Skip to main content

Getting started · Public

How ONE is organised

The subdomains, tenant types, and product areas you will meet when you sign in, administer an organisation, or connect an application.

Skyfallen ONE is an identity platform. People sign in with a ONE ID. Organisations run members, permissions, and branding from IAM. Connected applications use CAS, SAPP, and webhooks to work with trusted identity data.

The about site is the front door. Product work happens on the subdomains listed below.

Where you sign in

ONE splits the product across subdomains so each job has a clear home.

Enterprise tenants may also publish workforce sign-in and the portal on a custom hostname. Sign-in, password reset, passkey flows, and consent can run on that hostname when it is enabled. IAM and My stay on the platform subdomains above.

The about page lists these entry points with links.

Address What you do there
auth.skyfallen.one Sign in, approve consent, reset a password, or register a passkey.
my.skyfallen.one Update your profile, phone number, passkeys, and account security settings.
iam.skyfallen.one Manage members, invites, permissions, branding, integrations, and subscriptions for your organisation.
idms.skyfallen.one Call identity APIs from your server — CAS session exchange, SAPP reads, tenant signup, and webhooks.
help.skyfallen.one Read this documentation.

Tenant types

Most work in ONE happens inside a tenant — an organisation or personal space tied to your ONE ID.

Your account can belong to more than one tenant. Use tenant switching in the navigation before changing members, branding, or connections. Actions always apply to the tenant you have selected.

Type Best for
Personal One person who needs a ONE ID without organisation administration.
Commercial A small organisation that needs a managed tenant and a limited member count.
Enterprise A workforce tenant with domain-based sign-in, branding, portals, and directory integrations.

The four jobs ONE covers

Customer identity. People create a ONE ID, verify their email, and sign in to Skyfallen and partner services. They manage profile data and security from the account area.

Organisation administration. Tenant owners and administrators invite members, assign permissions, import CSV lists, and connect Google Workspace.

Workforce identity. Enterprise tenants brand their sign-in screen, run a workforce portal, and publish CAS and SAML apps alongside custom links for members.

Application integrations. Partner and internal systems use API keys to provision tenants, read account data through SAPP, sign users in through CAS, and receive signed change events through webhooks.

If you are… Start with
Creating your first account Create your ONE account
Setting up a business tenant Information required for commercial and enterprise tenants
Recovering access Reset a forgotten password
Running an organisation Run your organisation in IAM
Branding workforce sign-in Brand your sign-in and portal
Building an integration API overview
English