Platform · Identity
One sign-in across a family of apps
One account that works across every Shravya app - web, phone-number and guest sign-in - including apps served as static files with no server of their own to read a session cookie.
- 1account for every Shravya app
- 3ways in: email, phone number or guest
- 0passwords handled by any app except the sign-in portal
The problem
Most of the apps are static sites - fast and cheap to host, but with no server to read a secure, HttpOnly session cookie. The first attempt at single sign-on could never work for them, and failed in the worst way: a redirect loop.
Guests needed to be able to try things and later become real members without losing what they had done, and phone-number accounts had to be first-class, not an afterthought to email.
What we did
- One sign-in portal owns the session. Static apps ask it for a short-lived token and exchange that for their own sign-in, so the secure cookie never has to be readable by page scripts.
- Loop protection: if an app returns from the portal and still has no session, it stops and says so instead of bouncing forever.
- Guests are real accounts with a short life; upgrading keeps their identity, and a nightly job deletes guest data that was never claimed.
- Roles are enforced by the database security rules on the server, not by hiding buttons, and every rule change is tested - including deliberately breaking a rule to prove the tests notice.
The result
A member signs in once and moves between apps - World, Playhouse, the AI companion, vConnect, Finlytics - without signing in again.
Phone-only members can do everything email members can, including sending a project enquiry, which used to trap them in a loop.
Built with
Firebase AuthenticationNext.js on Cloud RunCustom tokensFirestore security rulesFigures checked against the live product on 21 September 2026.