Terms and conditions

Terms and conditions

Production identity provider rules for Evantra Identity consumers, clients, and operators.

Operating terms

Built for trust, auditability, and responsible use.

These terms reflect the expectations of a production identity provider and should be reviewed before any application integrates with Evantra Identity.

Service usage

Evantra Identity is provided for authentication, consent, and session lifecycle management. Do not use it to bypass application authorization or legal compliance requirements.

Client obligations

Clients must register accurate ownership data, use exact redirect URIs, protect secrets, and follow approval requirements before production use.

Security expectations

Consumers must store tokens and sessions securely, respect httpOnly cookies, and build their own role or permission checks where needed.

Availability and changes

Identity services, scopes, and policies may evolve. We may change flows or controls to improve security, compliance, or reliability.

Acceptable use

  • • Do not impersonate another user or client.
  • • Do not share secrets, tokens, or sessions outside authorized services.
  • • Do not rely on identity for app-specific authorization decisions.
  • • Use suggestions and review channels to propose improvements responsibly.

Operator notes

Evantra workers and admins may use the admin review console to approve clients, review suggestions, and manage identity policy. Final workspace role decisions are enforced in the kernel-backed workspace layer.

Protected by Evantra Identity

Switch to Workspace