Documented candidate
Better Auth is selected for the pilot because of its Next.js/MySQL integration and passkey support; it is not approved for real members.

Milestone 8 · prototype validated
KIIRAAY now tests invitation, session, grant, expiry, and revocation transitions using wholly fictional roles.
Provisional technical decision
Keycloak remains the fallback for a future separate identity service. The pilot selects Better Auth while preserving every legal, human, and technical barrier.
Better Auth is selected for the pilot because of its Next.js/MySQL integration and passkey support; it is not approved for real members.
The pilot accepts only seven published fictional roles and five fixed scopes; no name, contact, or identifier enters the system.
Invitation, rotation, expiry, and revocation produce testable states without creating a cookie or token.
Password-only, Senator, an incompatible scope, and every extra field are denied server-side.
The production feature flag stays off; sign-in, account, session, and member-map routes do not exist.
Residency, accountable owners, recovery, keys, independent testing, and legal approval remain blocking.
MySQL pilot · fixed identities only
Choose a fictional role, scope, and assurance level to test invitation, rotation, expiry, and revocation.
These states are a control model. No operational account, secret, cookie, token, session, or grant exists.
Milestone boundary
Account, session, and grant describe only the future system’s expected state transitions.
No sign-in, registration, recovery, or passkey route is published.
No password, TOTP secret, private key, token, cookie, or invitation code is received or produced.
No member, public office, real territory, or durable authorization is created.
Political maps, layers, data, exports, and communications remain absent.