Auth & Organizations
OIDC single sign-on with Rauthy, orgs, roles and quotas
Identity: Rauthy
Authentication is delegated to Rauthy, a full-Rust OIDC identity provider: PKCE login, branded pages, JWKS-validated tokens. On first login, the platform provisions user, profile and a personal organization automatically (JIT provisioning).
Organizations
An organization is the tenant boundary: X-Org-Id on every request, membership-based
access, roles (owner, admin, viewer), member management by email, tiers and quotas.
Profile preferences (language, theme) are per user.
Global search
A cross-entity search (devices, POIs, tours, media, flows, dashboards) is wired into the top bar with grouped navigation to results.


