Identity before portfolio access

The launch flow signs the user in through Keycloak. The verified Keycloak subject becomes the local user ID used for quotas and portfolio ownership.

No parallel application identity

Keycloak issues the access token and Spring Security validates its Bearer JWT. ChainsFlow does not create a second application token or persist a session table.

The identity remains authoritative

The Keycloak subject is stable across logins and devices. Local subscription and portfolio mappings are keyed directly by that verified identifier.

Free is intentionally bounded

The Free plan supports one exchange connection, automatic synchronization, queued manual refreshes and portfolio history.

Product state stays local

ChainsFlow keeps Free and Pro quotas, Stripe subscription state and portfolio mappings locally while Keycloak remains responsible for identity.