Getting started · Public
How ONE is organised
The subdomains, tenant types, and product areas you will meet when you sign in, administer an organisation, or connect an application.
Skyfallen ONE is an identity platform. People sign in with a ONE ID. Organisations run members, permissions, and branding from IAM. Connected applications use CAS, SAPP, and webhooks to work with trusted identity data.
The about site is the front door. Product work happens on the subdomains listed below.
Where you sign in
ONE splits the product across subdomains so each job has a clear home.
Enterprise tenants may also publish workforce sign-in and the portal on a custom hostname. Sign-in, password reset, passkey flows, and consent can run on that hostname when it is enabled. IAM and My stay on the platform subdomains above.
The about page lists these entry points with links.
| Address | What you do there |
|---|---|
auth.skyfallen.one |
Sign in, approve consent, reset a password, or register a passkey. |
my.skyfallen.one |
Update your profile, phone number, passkeys, and account security settings. |
iam.skyfallen.one |
Manage members, invites, permissions, branding, integrations, and subscriptions for your organisation. |
idms.skyfallen.one |
Call identity APIs from your server — CAS session exchange, SAPP reads, tenant signup, and webhooks. |
help.skyfallen.one |
Read this documentation. |
Tenant types
Most work in ONE happens inside a tenant — an organisation or personal space tied to your ONE ID.
Your account can belong to more than one tenant. Use tenant switching in the navigation before changing members, branding, or connections. Actions always apply to the tenant you have selected.
| Type | Best for |
|---|---|
| Personal | One person who needs a ONE ID without organisation administration. |
| Commercial | A small organisation that needs a managed tenant and a limited member count. |
| Enterprise | A workforce tenant with domain-based sign-in, branding, portals, and directory integrations. |
The four jobs ONE covers
Customer identity. People create a ONE ID, verify their email, and sign in to Skyfallen and partner services. They manage profile data and security from the account area.
Organisation administration. Tenant owners and administrators invite members, assign permissions, import CSV lists, and connect Google Workspace.
Workforce identity. Enterprise tenants brand their sign-in screen, run a workforce portal, and publish CAS and SAML apps alongside custom links for members.
Application integrations. Partner and internal systems use API keys to provision tenants, read account data through SAPP, sign users in through CAS, and receive signed change events through webhooks.
| If you are… | Start with |
|---|---|
| Creating your first account | Create your ONE account |
| Setting up a business tenant | Information required for commercial and enterprise tenants |
| Recovering access | Reset a forgotten password |
| Running an organisation | Run your organisation in IAM |
| Branding workforce sign-in | Brand your sign-in and portal |
| Building an integration | API overview |