Phase 0 ยท Complete

Identity stays server-side.

SvelteKit owns the OAuth session, Redis stores encrypted tokens, and Go validates the provider access token. The browser receives only an opaque application cookie.

Foundation status

Complete

01

Go API

Available

Typed response: ok

02

Application identity

Your app session starts only after you choose Sign in.

Sign in

03

Request trace

Correlate the same-origin SvelteKit proxy with the canonical Go operation.

req_ae4d05b7144d75918694b054209aa082