Keycloak is the identity authority
Passwords, verification and recovery stay in Keycloak. ChainsFlow validates the Keycloak Bearer JWT instead of issuing a parallel identity.
The subject is the user ID
The Keycloak subject UUID is stored as users.id and referenced by user_portfolios. No identity mapping or application-session table is required.
Plans remain local
ChainsFlow owns Free and Pro quotas and Stripe subscription state because those are product rules, not identity-provider concerns.