Documentation
Running SanctiKey.
These are the operator guides: what the console does, what each permission tier can actually do, and how to wire your identity provider to it. They describe the product as deployed, not as planned.
Anything you can count is generated from the code that enforces it. The permission tables in Users and permissions are built from the same scope definitions your session is authorized against, so they cannot quietly go stale the next time a capability is added.
Available now
Getting started
What signup actually does, the two logins you receive and why they are separate, multi-factor enrollment, and the path to your first signature.
Portal and console
The two surfaces and the two logins: what the billing portal holds, what the console holds, why money authority and key authority stay apart, and how buying a key from inside the console works.
Users and permissions
The four permission tiers and the exact scopes each one carries, how partitions differ from permissions, and what happens when a user holds more than one tier.
Account recovery
Resetting a forgotten billing portal password, what to do when your authenticator is gone, and which of the two paths your account takes.
Federation
Connecting SAML or OIDC single sign-on, and the step people miss: a federated user arrives with no permissions until an administrator assigns a tier.
Keys
Key types and usage, partitions, the difference between placement, relocation and failover, and the deletion lifecycle.
Certificate authority
Hierarchy, CSR signing, issuance, revocation, the public CRL and OCSP endpoints, and the enrollment boundary we do not cross.
Audit
What every operation records, how the trail stays intact, streaming it into your own systems, and what is deliberately kept out of it.
Escrow and Keyout
What conveys and what does not, in the same words as the legal terms.
Limits
Key counts, bundled operations, the prepaid ceiling and what happens when you reach it, and the regional add-ons.