Smart Capture EngineFramework 0.1

Identity and access

Authentication

IAM
Platform Core IAM is the identity authority

SCE validates signed bearer tokens and workspace claims. It does not store passwords, issue access tokens, or implement a parallel login system.

Authentication flow

active
01User or serviceRequests Platform Core token
→
02Platform Core IAMIssues workspace-scoped JWT
→
03SCE APIVerifies JWKS, issuer, audience
→
04Tenant boundaryScopes every database query

Current session

Bearer token
Subjectusr_maya_cruz
Emailmaya@combridgecorp.com
Workspacetnt_combridge_core
Audiencesmart-capture-engine
Token expiry43 minutes

Granted scopes

9 permissions
sce:captures:readsce:captures:writesce:templates:readsce:templates:writesce:research:readsce:research:writesce:admin:readsce:tenants:readsce:tenants:write