Skip to content
Balkan Tecnologia

Sign-in, permissions and API keys in your product

We handle who gets into your system and what each person can do: sign-in, access roles, two-factor authentication, single sign-on and API keys.

A mint-green thread running underneath a blank white slab the size of a phone.

Who it's for

For companies whose access control grew by patching and where nobody is sure who can do what.

What it solves

  • An employee leaves the company and their access keeps working.
  • Permissions are scattered across the code, in every screen and every route.
  • A corporate customer asks to sign in with their company account, and the system cannot do it.
  • API keys were sent by email and never changed again.

What we do

Sign-in and sessions
Password, social sign-in or email link, with session expiry and sign-out from every device.
Two-factor authentication
Authenticator app or passkey, required by role or for sensitive actions.
Roles and permissions
Roles and access rules defined in one place and checked on every API call.
Single sign-on (SSO)
Business customers sign in through their own identity provider, via SAML or OpenID Connect.
API keys
Issuing, scoping, rotating and revoking keys for whoever uses your APIs.
Access log
Who signed in, from where, and who changed permissions, keeping only the personal data needed, with the LGPD in mind.

What you get

  • An identity service in production, built in-house or on a chosen provider
  • A documented, reviewable matrix of roles and permissions
  • Automated access-denied tests for every role
  • A log of sign-ins and permission changes
  • A procedure for revoking access and rotating API keys

How we do it

  1. Access inventory

    Who uses the system, how they get in and what each role does today.

  2. Permission model

    Roles and rules defined with your team, before any code.

  3. Choosing the provider

    Ready-made provider or in-house service, comparing cost, control and where the data lives.

  4. Development

    Sign-in, two-factor, SSO and API keys, tested in the sandbox.

  5. User migration

    Existing accounts moved to the new sign-in, with a way back.

Technology examples

  • OpenID Connect
  • OAuth
  • SAML
  • WebAuthn
  • Keycloak
  • PostgreSQL

In Brazil, we handle

LGPD
Brazil's General Personal Data Protection Law (Law 13,709/2018).

Related services

FAQ

Is it worth writing sign-in from scratch?

Usually not. A ready-made identity provider, such as Keycloak or a managed service, takes less work to maintain. The choice depends on cost, control and where the data lives.

Can people sign in with a CPF or CNPJ?

Yes. Registration checks the format and check digits, and CNPJ fields already accept the alphanumeric format.

Will users have to change their passwords?

It depends on how passwords are stored today. If the format allows it, they migrate as they are; if not, each person sets a new one at their next sign-in.

What about the LGPD?

We keep sign-in data to the minimum needed, with an access log. Legal interpretation stays with your data protection officer or legal team; the technical design is covered under privacy by design.