All case studies

Platform · Identity

One sign-in across a family of apps

One account that works across every Shravya app - web, phone-number and guest sign-in - including apps served as static files with no server of their own to read a session cookie.

  • 1account for every Shravya app
  • 3ways in: email, phone number or guest
  • 0passwords handled by any app except the sign-in portal

The problem

Most of the apps are static sites - fast and cheap to host, but with no server to read a secure, HttpOnly session cookie. The first attempt at single sign-on could never work for them, and failed in the worst way: a redirect loop.

Guests needed to be able to try things and later become real members without losing what they had done, and phone-number accounts had to be first-class, not an afterthought to email.

What we did

  • One sign-in portal owns the session. Static apps ask it for a short-lived token and exchange that for their own sign-in, so the secure cookie never has to be readable by page scripts.
  • Loop protection: if an app returns from the portal and still has no session, it stops and says so instead of bouncing forever.
  • Guests are real accounts with a short life; upgrading keeps their identity, and a nightly job deletes guest data that was never claimed.
  • Roles are enforced by the database security rules on the server, not by hiding buttons, and every rule change is tested - including deliberately breaking a rule to prove the tests notice.

The result

A member signs in once and moves between apps - World, Playhouse, the AI companion, vConnect, Finlytics - without signing in again.

Phone-only members can do everything email members can, including sending a project enquiry, which used to trap them in a loop.

Built with

Firebase AuthenticationNext.js on Cloud RunCustom tokensFirestore security rules

Figures checked against the live product on 21 September 2026.