# Authentication and authorization

Zild uses access tokens, JWT claims, tenant context, roles, groups, and effective permissions to apply consistent access control across apps and services.

Source: https://zild.ai/en-US/docs/platform/authentication-authorization

Zild uses access tokens, JWT claims, tenant context, roles, groups, and effective permissions to apply consistent access control across apps and services.

## Identity flow

- The user authenticates directly or through the identity provider configured for the tenant.
- Zild issues or accepts an access token that represents the authenticated identity and organizational context.
- Services validate the token and read the user, tenant, roles, groups, and required authorization claims.
- The requested action runs only when the effective permissions allow it, and relevant events are recorded for audit.

## Token context

JWT supports distributed validation without a centralized server session. Tokens carry the minimum context needed by each service. Applications must not infer access from the interface alone; the backend validates tenant and permission scope on every protected operation.

## Single sign-on

Tenants can federate authentication with Microsoft Entra or Google Workspace. After the external provider validates the identity, Zild normalizes the session into its internal tenant, role, group, and permission model.
