exoDocs

The stack

05 · Identity

Exo Key on Convex Auth v2 — Exo is the only OAuth client and identity provider; Apps are relying parties.

Dimension
05 · Identity
Platform
Convex Auth · via Exo Key
Convex Auth
Exo Key: one sign-in for every property (Google, GitHub, or Apple) with explicit App and Page scopes. Core standard · authority: EXO
Status
Exo Key live on staging for registered Apps; Clerk retiring App by App.

What it is

One sign-in for every property, with explicit App and Page scopes instead of a separate account per property. Exo's Convex deployment mounts Convex Auth v2 (core plus Google and GitHub OAuth; Apple when added) and holds the only provider registrations. It issues app-scoped RS256 access tokens that Apps verify (ADR 0004).

The full contract is on the Exo Key service page.

Platform

Convex Auth v2, which is open source and native to the Convex database (roadmap: convex-auth). It runs as a pinned alpha (@convex-dev/auth 2.0.0-alpha.2 in package.json). Per the Convex team, v2 is stable enough to deploy now and reaches GA by Q4 (ADR 0003).

Boundary and replaceability

  • Apps never touch providers. Apps don't mount auth components, don't hold AUTH_* or provider secrets, and never register with Google, GitHub, or Apple. Onboarding an App is a reviewed code change to convex/lib/exoIdApps.ts.
  • Authentication and authorization are separate. Exo proves identity (sub, email, name). Authorization (roles, tenant grants) stays with the App in v1.
  • Upgrade containment. Convex Auth upgrades are contained to convex/auth.ts, convex/auth.config.ts, convex/convex.config.ts, and the client provider.
  • Portability. A person has one Exo user id across Apps, and Apps key their records on it. Identity exports omit credentials.
  • Consequence. Exo's Convex deployment is a hard dependency for sign-in across the portfolio. Its availability and key rotation are platform responsibilities.

Cost notes

  • The move off Clerk was partly economic: Clerk "charges per MAU and makes a proprietary vendor the default login surface" (ADR 0003). Clerk's actual spend: TBD.
  • Convex Auth has no license fee. Its marginal cost is Convex function and storage usage: TBD.

Status

  • Live on staging: authorize page https://staging.exo.now/id/authorize, and token, revoke, JWKS, and discovery endpoints on frugal-eel-930.convex.site/exo-id.
  • Registered Apps: observatory, construct, rampart, dropship, and universe (Exo Key guide).
  • In progress: per-App rollout and retirement of Clerk environment variables (convex-auth). Exo's Clerk-backed /sign-in stays until Construct leaves Clerk.
  • Pending: a version-bump pass before Convex Auth v2 GA (Q4).

Source: content/docs/stack/identity.mdx

On this page