Sign-in, permissions and API keys in your product
We handle who gets into your system and what each person can do: sign-in, access roles, two-factor authentication, single sign-on and API keys.

Who it's for
For companies whose access control grew by patching and where nobody is sure who can do what.
What it solves
- An employee leaves the company and their access keeps working.
- Permissions are scattered across the code, in every screen and every route.
- A corporate customer asks to sign in with their company account, and the system cannot do it.
- API keys were sent by email and never changed again.
What we do
- Sign-in and sessions
- Password, social sign-in or email link, with session expiry and sign-out from every device.
- Two-factor authentication
- Authenticator app or passkey, required by role or for sensitive actions.
- Roles and permissions
- Roles and access rules defined in one place and checked on every API call.
- Single sign-on (SSO)
- Business customers sign in through their own identity provider, via SAML or OpenID Connect.
- API keys
- Issuing, scoping, rotating and revoking keys for whoever uses your APIs.
- Access log
- Who signed in, from where, and who changed permissions, keeping only the personal data needed, with the LGPD in mind.
What you get
- An identity service in production, built in-house or on a chosen provider
- A documented, reviewable matrix of roles and permissions
- Automated access-denied tests for every role
- A log of sign-ins and permission changes
- A procedure for revoking access and rotating API keys
How we do it
Access inventory
Who uses the system, how they get in and what each role does today.
Permission model
Roles and rules defined with your team, before any code.
Choosing the provider
Ready-made provider or in-house service, comparing cost, control and where the data lives.
Development
Sign-in, two-factor, SSO and API keys, tested in the sandbox.
User migration
Existing accounts moved to the new sign-in, with a way back.
Technology examples
- OpenID Connect
- OAuth
- SAML
- WebAuthn
- Keycloak
- PostgreSQL
In Brazil, we handle
- LGPD
- Brazil's General Personal Data Protection Law (Law 13,709/2018).
Related services
FAQ
Is it worth writing sign-in from scratch?
Usually not. A ready-made identity provider, such as Keycloak or a managed service, takes less work to maintain. The choice depends on cost, control and where the data lives.
Can people sign in with a CPF or CNPJ?
Yes. Registration checks the format and check digits, and CNPJ fields already accept the alphanumeric format.
Will users have to change their passwords?
It depends on how passwords are stored today. If the format allows it, they migrate as they are; if not, each person sets a new one at their next sign-in.
What about the LGPD?
We keep sign-in data to the minimum needed, with an access log. Legal interpretation stays with your data protection officer or legal team; the technical design is covered under privacy by design.
Write to Balkan
Talk to us about your project