1. Acceptance of Terms & Ecosystem Scope
By registering an account, authenticating, or accessing services provided by SSO Develop (operating under 555 ID / SSO Identity Provider), you agree to be bound by these Terms of Service and our Privacy Policy. These terms govern your identity across all authorized client applications, microservices, and connected developer ecosystem platforms. If you do not agree to these terms, you must not access or use the service.
2. Identity & Authentication Services
SSO Develop provides a centralized OpenID Connect (OIDC Core 1.0) and RFC 6749 OAuth 2.0 Identity Provider. Our platform enables users to securely sign in across downstream services using:
- Passkeys (FIDO2 / WebAuthn): Cryptographic hardware-bound authentication (Touch ID, Face ID, YubiKey) for phishing-resistant logins.
- Standard Credentials: Salted and hashed passwords encrypted at rest via bcrypt algorithms.
- Federated Social Logins: Secure identity federations with Google, Telegram, Facebook, and X (Twitter) with strict Content Security Policy (CSP) avatar sandboxing.
- Emergency Recovery Tokens: Cryptographically generated single-use recovery codes for self-service account restoration.
3. Account Security & User Responsibilities
You are solely responsible for safeguarding your login credentials, passkeys, and two-factor authentication recovery codes:
- You must never disclose passwords, active JWT session cookies (
sso_access_token,sso_refresh_token), or recovery codes to any third party. - We strongly recommend registering Passkeys and generating emergency recovery codes for all production and administrative access.
- You must maintain an accurate, verified email address to receive security challenge alerts and account recovery notifications.
- You agree not to engage in brute-force password guessing, automated scraping, token injection, or rate-limit circumvention. Accounts triggering repeated security violations are subject to automated 15-minute lockouts or permanent deactivation.
4. Client Applications, Scopes & Authorization
When signing into affiliated applications using SSO Develop, you authorize the minimal exchange of identity claims (such as sub, email, name, and picture) adhering strictly to standard OIDC scopes:
- Public Clients: SPAs, mobile applications, and static sites must enforce PKCE (Proof Key for Code Exchange) using SHA-256 (
code_challenge_method=S256). - Confidential Clients: Dedicated backend services must authenticate using registered client secrets. In compliance with security policies, public self-registration is strictly blocked on confidential clients.
- Session Isolation & Sharing: Services operate under strict session isolation by default. Multi-domain single sign-on is only permitted within explicitly configured session clusters (e.g.
SESSION_SHARING_CLUSTERS).
5. Developer Quotas, Fair-Use & Zero Subscription Fees
Developer registration and OpenID Connect identity integration across the platform operate under an open, fair-use model:
- Zero Cost Access: OpenID Connect client credentials, token generation, and discovery endpoints are 100% free of charge. No credit card, subscription fees, or payment processing is required for developer accounts.
- Standard Allocations: Developer accounts receive a standard allocation of 5 client applications, 10,000 monthly active users (MAU), and 120 req/min token endpoint rate limits.
- Fair-Use Protection & Grace Periods: If an application exceeds standard rate limits, token requests receive standard HTTP 429 status codes with
Retry-Afterheaders. If MAU approaches allocations, automated notifications provide a 14-day transition period rather than disrupting live user authentication. - Free Quota Increases: Verified developers requiring additional capacity for production services can request a quota extension at zero cost through the Help Center.
6. Termination, Soft-Delete & Data Erasure
You have full autonomy over your account and may terminate your relationship with SSO Develop at any time:
- Self-Service Account Deletion: You can initiate permanent deletion directly through the Danger Zone in your Account Dashboard.
- User Data Deletion Instructions: To disconnect third-party logins (such as Facebook) or submit manual deletion requests, follow our User Data Deletion Instructions.
- Soft-Delete Retention: In compliance with security audit mandates, deleted accounts and client records are soft-deleted for a 30-day retention window before permanent purge, during which active sessions and access tokens are immediately revoked.
7. Contact & Support Channels
For inquiries or technical disputes concerning these Terms of Service: