In progress GHub Creator and maintainer Open core 2026 - present

GPlatform SSO / GPlatform Single Sign-On

One account for every GPlatform product, and one control that ends every session.

The identity layer for the GPlatform products and the G Open registries: one person above every product account, organisations and teams, access to each product granted from one screen, four ways to sign in, an OpenID Connect provider for applications, and one lockdown that ends every session in every product.

What it is

GPlatform SSO is the identity layer Gelhaus Solutions runs for its products, at sso.gplatform.org. It holds the person, the organisations and teams they belong to, the sessions they have open in every product at once, and which products each of them may reach, in which role. Somebody who has signed in to one product is let into the next without a second account being made for them.

One person above every product

Every account hangs off one identity. Each product knows you by an identifier of its own, different in every product, and that identifier belongs to your account in that product rather than to you. So merging two of your accounts, or moving a product's sign-in onto GPlatform SSO, never changes what a product has already written down about you.

An account made inside one product signs in to that product and nowhere else. It becomes a full account only if you accept the offer to join it to another, and that offer only ever arrives by email, to an address both accounts have confirmed.

Four ways in

A password and an authenticator code in one step, with ten recovery codes, each working once, for the day the authenticator is not at hand. A passkey, bound to sso.gplatform.org, which is both factors at once. A one-time code by email, for an account without a password. And sign-in providers: Apple, Bitbucket, Discord, Facebook, GitHub, GitLab, Google, LinkedIn, Microsoft, Spotify, Twitch and X, and any OpenID Connect issuer configured for a product.

A provider sign-in resolves only through a link you made, never through an email address. A provider that hands out addresses it has not checked can be linked to your account from your settings, and is then a way in; it is never a way into somebody else's account.

One control that ends everything

When something is wrong, one control ends every session the account holds, in every product. It asks how far to go: end every session; also require a new password and revoke every personal token; also suspend the account; or also drop every linked provider.

Each product checks a session again at least every 60 seconds and is told directly as well, so the lockdown holds in each of them within that minute whether or not the notice reaches it. A token issued over OpenID Connect lives five minutes at most, and every token names the sign-in it came from, so ending the sign-in ends the token.

Organisations, teams and access

An owner or admin grants a person, a team or the whole organisation a product and a role inside it, from one screen, and it takes effect without anybody opening that product's own administration. GPlatform SSO stores the role and tells the product; what the role permits stays the product's decision.

Organisations can require a second factor, shorten how long a sign-in lasts and set how often people prove themselves again. Rules only ever tighten. Enterprises group organisations and prove their domains with a file or a DNS record, and organisations and enterprises run service accounts for their machines, with tokens that always expire.

For applications

Our own products, and software we run, can speak a session protocol through a client library. Every application can sign people in through a conformant OpenID Connect provider: authorization code with PKCE, short-lived EdDSA tokens, a pairwise subject per application, and signing keys that never leave HashiCorp Vault.

Every application is enrolled at one of three tiers: our own product, software we run, or somebody else's software. Only our own products may create accounts. Somebody else's software is never told which other products a person uses, and learns who somebody is only after they agree on a consent screen.

Privacy by default

No trackers, no analytics, no advertising. A session records a country, never a city, read from a database on our own server rather than from a lookup service, and raw IP addresses are kept for 90 days, then only as a keyed hash. Our support can act as you only with your consent, given for a reason you are shown and lasting at most seven days, and you are told afterwards every time.