The stack
05 · Identity
Exo Key on Convex Auth v2 — Exo is the only OAuth client and identity provider; Apps are relying parties.
- Dimension
- 05 · Identity
- Platform
- Convex Auth · via Exo Key
- Convex Auth
- Exo Key: one sign-in for every property (Google, GitHub, or Apple) with explicit App and Page scopes. Core standard · authority: EXO
- Status
- Exo Key live on staging for registered Apps; Clerk retiring App by App.
What it is
One sign-in for every property, with explicit App and Page scopes instead of a separate account per property. Exo's Convex deployment mounts Convex Auth v2 (core plus Google and GitHub OAuth; Apple when added) and holds the only provider registrations. It issues app-scoped RS256 access tokens that Apps verify (ADR 0004).
The full contract is on the Exo Key service page.
Platform
Convex Auth v2, which is open source and native to the Convex database
(roadmap: convex-auth). It runs as a pinned alpha
(@convex-dev/auth 2.0.0-alpha.2 in package.json). Per the Convex team, v2 is stable enough
to deploy now and reaches GA by Q4
(ADR 0003).
Boundary and replaceability
- Apps never touch providers. Apps don't mount auth components, don't hold
AUTH_*or provider secrets, and never register with Google, GitHub, or Apple. Onboarding an App is a reviewed code change toconvex/lib/exoIdApps.ts. - Authentication and authorization are separate. Exo proves identity (
sub,email,name). Authorization (roles, tenant grants) stays with the App in v1. - Upgrade containment. Convex Auth upgrades are contained to
convex/auth.ts,convex/auth.config.ts,convex/convex.config.ts, and the client provider. - Portability. A person has one Exo user id across Apps, and Apps key their records on it. Identity exports omit credentials.
- Consequence. Exo's Convex deployment is a hard dependency for sign-in across the portfolio. Its availability and key rotation are platform responsibilities.
Cost notes
- The move off Clerk was partly economic: Clerk "charges per MAU and makes a proprietary vendor the default login surface" (ADR 0003). Clerk's actual spend: TBD.
- Convex Auth has no license fee. Its marginal cost is Convex function and storage usage: TBD.
Status
- Live on staging: authorize page
https://staging.exo.now/id/authorize, and token, revoke, JWKS, and discovery endpoints onfrugal-eel-930.convex.site/exo-id. - Registered Apps:
observatory,construct,rampart,dropship, anduniverse(Exo Key guide). - In progress: per-App rollout and retirement of Clerk environment variables
(convex-auth). Exo's Clerk-backed
/sign-instays until Construct leaves Clerk. - Pending: a version-bump pass before Convex Auth v2 GA (Q4).
Source: content/docs/stack/identity.mdx
04 · App state & storage
Convex is the live backend for every app: data, functions, real-time state, and files. Object storage only when a workload justifies it.
06 · Design system
Every Exo app uses shadcn/ui components with the Structured Liquidity theme; websites and pages are built and published in Construct.