Docs/Start
Own the identity boundary.
Learn, integrate and operate RustyAuth—from one isolated realm to a cross-cloud Fleet control plane.Passkeys, revocable sessions, recovery, Fleet management and Analytics V1 are supported in 1.0.0. Keep exact image digests, browser/authenticator coverage, restore drills and deployment-specific security evidence. Native applications are post-1.0 previews.
Choose your path
Add passkeys to an app
Start the standalone stack, complete a ceremony, exchange the session for a JWT and verify it in your API.
Follow the path →Platform operatorDeploy one isolated realm
Understand the three-service topology, versioned configuration, secrets, backups and recovery gates.
Follow the path →Fleet operatorManage many realms
Run the separate Fleet control plane and pair organizations, projects and environments without sharing databases.
Follow the path →The product boundary
RustyAuth authenticates an identity, maintains revocable browser sessions and issues short-lived claims for downstream services. Your application still owns authorization, roles, entitlements and resource ownership.
Browse every guide
Getting started
Run the standalone or Fleet stack locally and verify it.
Open guide →StartIntegrate an application
Add passkeys, sessions and verified JWTs to a web application.
Open guide →UnderstandArchitecture
Service topology, trust boundaries and failure isolation.
Open guide →UnderstandIdentity data
Accounts, identifiers, passkeys, sessions and exposure rules.
Open guide →UnderstandFleet control plane
Organizations, projects, environments and isolated realms.
Open guide →UnderstandFleet Analytics
Cross-cloud rollups, hierarchy attribution, GreptimeDB and staged delivery.
Open guide →ReferenceHTTP and RPC API
Browser JSON, Connect, gRPC-Web and native gRPC boundaries.
Open guide →ReferenceFleet Analytics V1
Exact bucket, metric, histogram, privacy, coverage and archive semantics.
Open guide →ReferenceConfiguration
Versioned YAML, IaC ownership, secrets, webhooks and fail-closed startup policy.
Open guide →OperateDeployment
Three-service topologies for Docker, Railway and Fleet.
Open guide →OperateKubernetes and K3s
Integrated, Fleet and lightweight realm Helm charts for Kubernetes and Civo K3s.
Open guide →OperateSecurity
Security model, hardened defaults and continuous assurance.
Open guide →OperateBackups and recovery
Snapshot scope, binary envelopes, immutable S3 storage, alerting, key rotation and clean-room restore.
Open guide →ProjectStatus and roadmap
What 1.0.0 supports, what remains preview and what comes next.
Open guide →Source of truth
This site is the guided developer experience. The repository contains the normative protocol, security and operational references. Start at the GitHub documentation index when you need exhaustive contracts or release-specific detail.