Back to referencesIT & technology

Centralized Authorization and Application Platform

Single sign-on, unified user and rights management for all Atrea internal and customer applications. We built a central platform on top of Zitadel featuring custom login, multi-brand support, fine-grained permissions, and notifications.

Client
Atrea s.r.o
Year
2026
Technologies
TypeScriptNode.jsExpressPostgreSQLTypeORMZitadelOpenID ConnectNext.jsVue.jsWeb PushDocker

The Challenge

Atrea operates numerous web applications for employees, business partners, and customers. Until now, each of them handled login, users, and permissions in its own way. This resulted in multiple accounts per person, fragmented rights management, and access logic that had to be programmed from scratch every time.

The goal was to create a single shared platform that any new or existing application can use, offering unified sign-on, central rights management, and shared services such as notifications or user feedback.

The Solution

Single Sign-On (SSO)

We chose the open-source IAM platform Zitadel as the identity provider. However, we built our own login screens (Next.js over Session API v2), ensuring that registration, password reset, and multi-factor authentication (MFA) look and behave precisely according to Atrea's needs. Employees log in with their corporate Microsoft account, while external users use email and password.

Multiple Brands on a Single Platform

A single installation serves multiple brands and organizations. Each brand has its own login visual style, custom domain, email templates, and outgoing SMTP server. The brand is determined centrally based on the application and callback, ensuring users never end up in the wrong environment.

Permissions in One Place

Applications no longer calculate anything themselves; all permission logic lives in a central service:

  • roles within each application and automatic role assignment based on email domain,
  • binary and graded permissions (disabled / view / edit) in a tree structure,
  • permissions for specific records (e.g., sharing a single project with a colleague),
  • application administrators and super administrators with an audit log of all changes.

Roles and permissions are embedded directly into the access token (JWT) upon login. This allows the frontend to know what the user should see without making extra queries. Backend services of other applications verify permissions with a single API call.

Shared Services for All Applications

  • Notifications via email and Web Push, with templates for each message type, bulk sending, and user subscription settings.
  • Multilingual support with a central language registry, fallback languages, and automated template translation.
  • Feedback and support directly from applications, including attachments and status change notifications.
  • User profiles and preferences shared across applications.

Administration

For administrators, we built an admin panel in Vue 3. It contains users, roles and permissions, applications and their OIDC clients, brands, email settings, notification templates, support, and audit logs. The platform also includes developer documentation (VitePress) with a version tailored for AI assistants, allowing developers to connect new applications quickly and uniformly.

The Result

  • One account for all Atrea applications and corporate SSO via Microsoft.
  • New applications integrate in a few days instead of weeks of developing custom login and rights management.
  • Access management in one place, including instant user blocking across the entire platform.
  • Ready for multiple brands and markets thanks to multi-brand and multilingual support.
  • The platform already serves production Atrea applications, with others being migrated gradually.
View project

Have a similar project in mind?

Start a conversationBack to references