OSS-first docs
These docs teach the open system first: contracts, generated surfaces, runtimes, governance, and incremental adoption. Studio shows up as the operating layer on top, not as the source of truth.
Feature Hubs
Auth User Hub
Ship user-owned identity, authentication, recovery, MFA, passkeys, sessions, consent, and personal security.
Personal scope
User routes never inherit administrative authority.
Fresh security
Sensitive security routes resolve a fresh session.
Copy-ready example
import { installAuthUserHub } from "@lssm-tech/module.auth-os/hub";
const hub = await installAuthUserHub({
context,
ports: yourProviderNeutralPorts,
evaluatePolicy: (policyId, operationRef) =>
policyEngine.evaluate({ policyId, operationRef, context }),
fulfillPolicyObligations: (request) => obligationRuntime.fulfill(request),
});
await hub.start();Production truth
Deterministic fixtures, adapters, and provider templates remain candidate. Qualified means the consumer has passed live provider, infrastructure, security, restore, failover, canary, rollback, and operator qualification in the exact environment.
Continue through the Hub ecosystem
Related package reference
Runnable all-nine reference app
Workflow Hub
Install definitions, DAGs, schedules, approvals, workers, retries, leases, cancellation, dead letters, and replay.
Auth Admin Hub
Manage organizations, roles, invitations, SSO, SCIM, domains, posture, and tenant audit.
Why ContractSpec
Keep educational and comparison content reachable without letting it define the primary OSS learning path.