Identity at the edge, Handled.

Handled Cloud is a CDN native integration layer that ensures fast, secure and consistent identity across your domain.

Sign up (opens in new tab)

Secure frontend identity is complex

Identity in the browser is crucial in enabling your users to securely use your services. The browser is a hostile environment and many distinct decisions have to be made which have significant implications on security and user experience.

Handled Cloud handles identity once, at the edge, in one place, so your users get one consistent experience and your teams build features instead of identity plumbing.

How It Works

  1. 01

    Frontend is given a session cookie

    The browser is given a secure session cookie, which is managed by Handled Cloud working with your identity provider. Handled Cloud refreshes the session in the background as the user remains active, and clears it on logout. Your frontend never touches it.

  2. 02

    Handled Cloud implements the token handler pattern

    At the edge, Handled Cloud validates the session and forwards the JWT on to the origin if it's needed.

  3. 03

    Request arrives at origin with JWT

    Your API receives a standard Bearer token to validate or introspect with your IDP, no changes needed.

Identity behaviours for your front ends

Your front ends manage the session through one consistent set of endpoints, rather than each app integrating directly with your identity provider. Login, logout, refresh, and expiry are served on your domain; there is no OAuth client code in any frontend.

Enterprise requirements, handled.

A single Handled Cloud deployment handles identity for every origin in your configuration: micro-frontends, API gateways, backend services. Add a new app by adding a route.

Ready to handle identity at the edge?

Deploy into your Cloudflare account. Works with any OIDC-compliant identity provider.