Keycloak is the identity authority

Passwords, verification and recovery stay in Keycloak. ChainsFlow validates the Keycloak Bearer JWT instead of issuing a parallel identity.

The subject is the user ID

The Keycloak subject UUID is stored as users.id and referenced by user_portfolios. No identity mapping or application-session table is required.

Plans remain local

ChainsFlow owns Free and Pro quotas and Stripe subscription state because those are product rules, not identity-provider concerns.