Milestone 8 · prototype validated

Test the access lifecycle without processing an identity.

KIIRAAY now tests invitation, session, grant, expiry, and revocation transitions using wholly fictional roles.

2providers assessed
7fictional roles
4simulated lifecycles
0operational access

Provisional technical decision

A simpler integration does not lower the requirements.

Keycloak remains the fallback for a future separate identity service. The pilot selects Better Auth while preserving every legal, human, and technical barrier.

01

Documented candidate

Better Auth is selected for the pilot because of its Next.js/MySQL integration and passkey support; it is not approved for real members.

02

Fixed identities

The pilot accepts only seven published fictional roles and five fixed scopes; no name, contact, or identifier enters the system.

03

Verifiable lifecycle

Invitation, rotation, expiry, and revocation produce testable states without creating a cookie or token.

04

Structural denials

Password-only, Senator, an incompatible scope, and every extra field are denied server-side.

05

Production closed

The production feature flag stays off; sign-in, account, session, and member-map routes do not exist.

06

Approval first

Residency, accountable owners, recovery, keys, independent testing, and legal approval remain blocking.

MySQL pilot · fixed identities only

Simulate the full lifecycle without opening one account.

Choose a fictional role, scope, and assurance level to test invitation, rotation, expiry, and revocation.

Better Auth · in review24 h0 secrets0 real access

These states are a control model. No operational account, secret, cookie, token, session, or grant exists.

Lifecycle event
Synthetic role
Synthetic scope
Fictional assurance

Milestone boundary

An “active” simulated state grants no access.

Account, session, and grant describe only the future system’s expected state transitions.

No authentication

No sign-in, registration, recovery, or passkey route is published.

No secret

No password, TOTP secret, private key, token, cookie, or invitation code is received or produced.

No assignment

No member, public office, real territory, or durable authorization is created.

No map

Political maps, layers, data, exports, and communications remain absent.