One sign-in for every ProductCraft product
Platform auth is now its own first-class service. A single ProductCraft account signs you in to Heimdall, Envoi, and every product to come.
Until now, your ProductCraft identity lived inside Heimdall. That made sense when Heimdall was the only product, but it conflated two different concerns: managing your team's access to ProductCraft, and managing your customers' access to your apps.
We've split them. Platform auth is now its own service at api.auth.productcraft.co, with its own database, signing keys, and sign-in surface at auth.productcraft.co. Every ProductCraft product — Heimdall, Envoi, future Tack, future Rally — uses the same platform identity, with workspace-scoped roles and per-service activation.
What's the same. Heimdall's Consumer API for your end-users is unchanged. Per-app sign-in, per-app JWKS, hdk_live_* API keys, m2m credentials — all still there, all still cryptographically isolated per app. Your end-users see no difference.