This tutorial is coming soon.
X-Dome-Act-As, and calls Dome. The frontend never sees either secret.
Production usually should not mint identities with a shared HMAC secret. This tutorial will cover the two stronger verification methods:
Until this tutorial ships, use the HMAC sandbox path and the delegated-agent reference below.
Next steps
Until this tutorial ships, use the HMAC path and the delegated-agent reference:- Govern per end user for the HMAC sandbox path
- Delegated agents for OIDC providers, workspace policy, and methods
- Pass identity for delegated agents in application code
- Adopt an existing app to move a running app onto the governed path