Per-tenant signing keys in a multi-tenant OIDC issuer
One binary, many tenants, and a different signing key for each. How WeldForge keeps token issuance isolated without running an issuer per customer.
I architect resilient systems where development, infrastructure, and quality assurance intersect — identity & access, zero-knowledge security, multi-tenant SaaS, and the audit discipline that keeps them all honest.
Heritage in judgement. Modern in method.
Field notes from building identity platforms and multi-tenant products — the decisions, the trade-offs, and the things I wish I'd known earlier.
One binary, many tenants, and a different signing key for each. How WeldForge keeps token issuance isolated without running an issuer per customer.
A short colophon. Who I am, what I'll write about here, and why the site you're reading runs on the same stack I ship to clients.
Architecture, identity, and delivery work runs through CW Vermaak Informatics. The product is WeldForge.