Identity before portfolio access
The launch flow signs the user in through Keycloak. The verified Keycloak subject becomes the local user ID used for quotas and portfolio ownership.
No parallel application identity
Keycloak issues the access token and Spring Security validates its Bearer JWT. ChainsFlow does not create a second application token or persist a session table.
The identity remains authoritative
The Keycloak subject is stable across logins and devices. Local subscription and portfolio mappings are keyed directly by that verified identifier.
Free is intentionally bounded
The Free plan supports one exchange connection, automatic synchronization, queued manual refreshes and portfolio history.
Product state stays local
ChainsFlow keeps Free and Pro quotas, Stripe subscription state and portfolio mappings locally while Keycloak remains responsible for identity.