·6 min read
Single sign-on between two apps without an identity provider: the one-minute ticket
Two internal tools on different domains, no shared cookie, and no appetite for an identity provider for a handful of users. A signed ticket that lives sixty seconds and works once replaced the second login. The flow, the code, and the four responses we measured in production.