One shared story
Environments, JWKS, and sessions stay aligned — so your app and your MCP server speak the same identity language.
Clerk-class authentication for WeldSuite — and for every product that needs users, orgs, machines, agents, and MCP-ready OAuth in one place.
01 — Work without the loose ends
Users are more than passwords. Machines need more than a shared secret. WeldAuth connects people, orgs, services, and AI agents on one foundation.
Environments, JWKS, and sessions stay aligned — so your app and your MCP server speak the same identity language.
Hosted auth, dashboard, and APIs share branding and domains. Ship like Clerk — without leaving the WeldSuite family.
Start with sign-in. Add orgs, API keys, M2M, agents, and dynamic OAuth when your product is ready.
Powerful on their own
Thoughtfully built auth surfaces. One shared data plane. A clearer way to ship.
Password, magic link, OAuth, SAML. MFA, roles, and org memberships with Clerk-compatible permission checks.
User- and org-owned ak_ keys, plus machine secrets and scoped M2M tokens for service-to-service calls.
First-class agents with session-like JWTs, and dynamic client registration so MCP clients can connect securely.
Credential families
Distinct prefixes. Clear ownership. No guessing which secret belongs where.
pk_ / sk_Talk to WeldAuth. Select an environment.
ak_Long-lived secrets owned by a person or team.
msk_ / mt_Service actors minting scoped opaque tokens.
agsec_ → JWTAgent secrets mint short-lived sessions.
Your data. Handled properly.
Soft multi-tenant by design, environment isolation, and JWKS-verified tokens — ready for EU-first workloads.
Dev, staging, and production as separate data planes — Clerk-like.
User, agent, and OAuth access tokens verify the same way.
Dedicated auth domains and application callbacks, Auth0-style.
API on Cloudflare Workers. Postgres on Neon. Web on Vercel.
Good to know
No. WeldSuite is the first customer, but WeldAuth is a general multi-tenant auth platform — other products can sign up and run their own instances.
WeldAuth aims for Clerk-class product surfaces (users, orgs, environments, machine auth, satellites/auth host) without claiming wire compatibility. You get a familiar model with room to extend for agents and MCP.
Yes. Enable dynamic client registration, publish authorization-server metadata, and let MCP clients register via RFC 7591 — then authorize with PKCE.
Production targets Neon Postgres with soft multi-tenancy. Hosted auth and dashboard deploy on Vercel; the API runs on Cloudflare Workers.
Create an application, grab your keys, and ship sign-in that looks like it belongs next to WeldMail and WeldCRM.