House Desk and Pub integrate through narrow contracts rather than a shared database or shared authorization service.
| Producer | Consumer | Contract |
|---|---|---|
| Authentik | Cloudflare Access | OIDC identity, profile, and verified email claims |
| Cloudflare Access | House Desk and Pub | Product-specific signed Access JWTs with unchanged audiences |
| House Desk | Pub | Least-data published event projection for Pub displays |
| House Desk | Calendar clients | Token-gated ICS feed |
| House Desk and Pub | Transactional providers | Bounded email or operational delivery requests |
Each consumer authenticates the producer, validates a versioned response shape where applicable, and stores only what it needs. A shared identity provider does not create a shared application database.
For product-specific details, see House Desk integrations and Pub’s House Desk event source.