Centralized Authorization and Application Platform
Single sign-on, unified user and rights management for all Atrea internal and customer applications. We built a central platform on top of Zitadel featuring custom login, multi-brand support, fine-grained permissions, and notifications.
- Client
- Atrea s.r.o
- Year
- 2026
- Technologies
TypeScript Node.js Express PostgreSQL TypeORM Zitadel OpenID Connect Next.js Vue.js Web Push Docker
The Challenge
Atrea operates numerous web applications for employees, business partners, and customers. Until now, each of them handled login, users, and permissions in its own way. This resulted in multiple accounts per person, fragmented rights management, and access logic that had to be programmed from scratch every time.
The goal was to create a single shared platform that any new or existing application can use, offering unified sign-on, central rights management, and shared services such as notifications or user feedback.
The Solution
Single Sign-On (SSO)
We chose the open-source IAM platform Zitadel as the identity provider. However, we built our own login screens (Next.js over Session API v2), ensuring that registration, password reset, and multi-factor authentication (MFA) look and behave precisely according to Atrea's needs. Employees log in with their corporate Microsoft account, while external users use email and password.
Multiple Brands on a Single Platform
A single installation serves multiple brands and organizations. Each brand has its own login visual style, custom domain, email templates, and outgoing SMTP server. The brand is determined centrally based on the application and callback, ensuring users never end up in the wrong environment.
Permissions in One Place
Applications no longer calculate anything themselves; all permission logic lives in a central service:
- roles within each application and automatic role assignment based on email domain,
- binary and graded permissions (disabled / view / edit) in a tree structure,
- permissions for specific records (e.g., sharing a single project with a colleague),
- application administrators and super administrators with an audit log of all changes.
Roles and permissions are embedded directly into the access token (JWT) upon login. This allows the frontend to know what the user should see without making extra queries. Backend services of other applications verify permissions with a single API call.
Shared Services for All Applications
- Notifications via email and Web Push, with templates for each message type, bulk sending, and user subscription settings.
- Multilingual support with a central language registry, fallback languages, and automated template translation.
- Feedback and support directly from applications, including attachments and status change notifications.
- User profiles and preferences shared across applications.
Administration
For administrators, we built an admin panel in Vue 3. It contains users, roles and permissions, applications and their OIDC clients, brands, email settings, notification templates, support, and audit logs. The platform also includes developer documentation (VitePress) with a version tailored for AI assistants, allowing developers to connect new applications quickly and uniformly.
The Result
- One account for all Atrea applications and corporate SSO via Microsoft.
- New applications integrate in a few days instead of weeks of developing custom login and rights management.
- Access management in one place, including instant user blocking across the entire platform.
- Ready for multiple brands and markets thanks to multi-brand and multilingual support.
- The platform already serves production Atrea applications, with others being migrated gradually.
