Identity

One Identity Across Connected Apps: Understanding Bhauu Identity

One person can use one Bhauu Identity across registered apps without merging their permissions or product data.

One Bhauu Identity can connect a person to several applications. That shared identity is the starting point, not permission for apps to read each other's data.

The roles in the ecosystem

  • Bhauu is the parent brand.
  • Bhauu Identity is the canonical user identity.
  • Bhauu Auth hosts authentication and application authorization.
  • Bhauu Account is where the person manages that same identity; it is not a second identity database.
  • Connected Apps are separately registered applications that may receive allowed identity information through their own grants.

Shared identity does not mean shared app data

A person might use the same Bhauu Identity with a work tool and a community app. Each application has its own registration, requested scopes, authorization relationship, and application-owned data. Neither application inherits the other's grant or database merely because the person is the same.

Likewise, removing one app's access does not delete the canonical identity or automatically delete content that app stores. An app with a local session must participate in revocation through validation, renewal failure, events where supported, or a bounded session lifetime. Shared sign-in infrastructure should not be mistaken for universal instant logout.

What developers should design

Use Bhauu Auth's documented Authorization Code and PKCE flow to obtain allowed identity claims. Create and protect your own application session, and decide what product data your app stores. For access changes, handle Bhauu-side revocation and your local logout separately.

Takeaway

One canonical user simplifies identity across connected apps, while consent, access, and app-owned data remain separate. Read Sessions and continuity for the boundary, or visit the developer overview to begin an integration.