Live trust report · Signet

All systems hold the seal.

Signet is ready to authenticate users, issue tokens, and verify access. Every required service passed its latest check.

Checked JSON /health
Operational
Application Operational
Storage Operational
Signing Operational
Protocols Available

Live checks

Runtime

Read-only dependency checks shared with the machine health endpoint.

Web service

Public HTTP routes are accepting requests

Current request
Operational

Database

Persistent storage accepted a context-bounded connection check

Live probe
Operational

Identity cache

Provides identity lookups used by authenticated request paths

Live probe
Operational

Administration cache

Speeds up administrative status counts; failures do not block core flows

Live probe
Operational

Client cache

Accelerates OAuth client lookups with a database fallback

Live probe
Operational

Token signing engine

A non-persistent token was signed and verified in memory

In-memory self-test
Operational

Token cache

Accelerates online token verification with a database fallback

Live probe
Operational

Rate-limit store

Stores distributed rate-limit counters when Redis mode is active

Live probe
Operational

Protocol surface

OAuth & OpenID Connect

These routes and capabilities passed startup configuration validation.

OIDC discovery

Publishes OpenID Connect discovery metadata

Configuration
Available

OAuth metadata

Publishes OAuth authorization server metadata

Configuration
Available

Authorization Code + PKCE

Browser authorization with consent and PKCE protection

Configuration
Available

Device Authorization

Supports user authorization for CLIs and input-constrained devices

Configuration
Available

Client Credentials

Issues service identities without an interactive user

Configuration
Available

Token introspection

Lets authorized clients inspect the current state of a token

Configuration
Available

Token revocation

Lets clients invalidate access and refresh tokens

Configuration
Available

UserInfo

Returns OpenID Connect claims for an authorized subject

Configuration
Available

JWT signing capability

The configured JWT signing capability is initialized

Configuration
Available

JSON Web Key Set

Publishes asymmetric public signing keys when the algorithm supports it

Configuration
Available

Instance choices

Optional features

Disabled capabilities are an instance choice, not a service failure.

Refresh tokens

Allows clients to renew access without another full sign-in

Configuration
Enabled

Client ID Metadata Documents (CIMD)

Accepts URL-shaped client IDs backed by self-hosted metadata documents

Configuration
Not enabled

Audit logging

Records authentication, token, and administrative security events

Configuration
Enabled

Prometheus metrics

Exposes optional Prometheus operational metrics

Configuration
Not enabled

Login session tracking

Maintains server-side browser and device login sessions

Configuration
Enabled

Rate limiting

Protects sensitive endpoints from excessive requests

Configuration
Enabled

Refresh token rotation

Replaces refresh tokens after each successful use

Configuration
Not enabled

External OAuth login

At least one external identity provider is configured

Configuration
Configured