# Signet — machine on-ramp (marketing site) # https://signetauth.com Signet is the identity plane for people, services, and agents. Every user, session, and secret lives in your own PostgreSQL, hosted by the Signet team or, under an enterprise licence, on your own metal; it needs nothing from the public internet. Point a stock better-auth client at a Signet instance and the calls you already write keep working (certification gap 0; scoped to the checks in the public compatibility profile, not a claim that every better-auth route is implemented). The same open wire is your exit — you can leave the way you came in. What it is, in three parts: 1. Own it — your users, your data, your Postgres. Everything in your own database, sealed / air-gap capable, an /admin operator surface you control. An enterprise licence takes the same build onto your own metal. 2. Pay flat — Hobby is $0 on a work email, then $299/mo with unlimited users and unlimited SSO connections (effective 2026-08-07). No per-user billing, no usage meter, and no per-connection fee for enterprise SSO. Your bill does not move when you win a customer. 3. Open wire — stock better-auth clients work unchanged (certification gap 0); no proprietary SDK. The wire is the exit. Three things are sold: the hosted service (self-serve sign-up, flat monthly price), an enterprise licence for the same build on the customer's own metal (annual, quoted per production deployment), and fixed-price implementation engagements that land it. Hosted sign-up: https://signetauth.cloud Signing up creates the account and provisions the instance automatically; no operator is in the path. The instance reports its own URL, health and compatibility receipt when it comes up. Commercial posture: every user, session, and secret in your own PostgreSQL; people, services and agents on one plane; no telemetry; no third-party calls in the sign-in path. That keeps the scope of any audit as small as the architecture. The bill does not move when you win, and an enterprise licence takes the same build on-prem. Outside a signed contract Signet offers NO SLA, and claims NO third-party compliance certification — those are your decisions on infrastructure you control. This is the marketing site. The PRODUCT itself is a single deployed instance; every deployed instance serves its own certified API, operator dashboard, embedded docs, and compatibility receipt. Full marketing and integration reference: https://signetauth.com/llms-full.txt Official social presence: https://x.com/signetauth (X). Other networks are registered but not yet active; this file lists them when they are. ## Certified facts (recorded, not marketing) Compatibility profile: better-auth 1.6.23 Certification gap: 0 Scope of that gap: The compatibility profile is a public, replayable set of checks; the same checks run against the better-auth reference implementation and against Signet, and the gap is the count of checks the reference passes and Signet does not. Gap 0 means that on every check in the profile, a client cannot tell the two apart. It is not a claim that every better-auth route is implemented: the profile is scoped to what those checks exercise, and anything they do not exercise sits outside it. Ask about a specific route and we will tell you plainly whether it is in the profile. Conformance sweep: 280 / 280 (every check in the profile passing) End-to-end acceptance: 14 / 14 Profile version: Signet compatibility profile v1 Recorded: 2026-07-25 Identity plane: people, services and agents in one PostgreSQL. Nothing else to stand up alongside it, nothing phones home; sealed / air-gap capable. Machine identity: typed principals (people, services, application end-users), service credentials owned by the organization, per-tenant enumerated roles, delegated tenant administration that cannot escalate, workspace scoping, batch issuance from a manifest; the full statement is in https://signetauth.com/llms-full.txt under "Machine identity and delegated administration". Operating envelope: not published — not yet measured under load, so no capacity number is claimed. ## Vendor facts Contracting entity: GeldenTech Inc., a federal corporation incorporated under the Canada Business Corporations Act, corporation number 1392904-3, registered office in Montreal, Quebec, Canada. Contracts, DPAs and entity documentation: legal@signetauth.com. Contact routes: hello@signetauth.com (sales and general), security@signetauth.com (vulnerability reports, acknowledgement within 2 business days, from a human), legal@signetauth.com (contracts, DPA, entity facts). All three are live mailboxes. Vulnerability disclosure: https://signetauth.com/security and https://signetauth.com/.well-known/security.txt (RFC 9116), with safe harbour stated. Breach notification: 72 hours from determination, published as the floor for everyone; contractual targets beyond it live in signed agreements. Subprocessors: hosted service — Hetzner (instance compute and storage, EU), Cloudflare (DNS and inbound email routing), Resend (outbound transactional email); on your own metal — none, nothing leaves your infrastructure. DPA: not yet published as a standing template; one is prepared with counsel before any contract that requires it — request via legal@signetauth.com. Certifications: none held or claimed; the dated ledger is on https://signetauth.com/security. Continuity, if this vendor disappears: your users, sessions and secrets are plain rows in your own PostgreSQL, exportable with standard database tools, and the wire is an open certified profile rather than a proprietary one — a database export plus any compatible engine, including the open-source better-auth library itself, can take over. An enterprise licence runs the same build on your own metal, and the Enterprise rung adds escrow. The exit is symmetric with the entry: one URL change each way. Vendor risk here is an architecture question before it is a company-history question. Support: self-serve documentation, email support on Team, priority support on Business. Response targets are stated in a contract; outside one, no SLA is offered or implied. ## Pricing note Signet pricing (effective 2026-08-07; fixed, not a launch rate): Hobby is $0 on a work email, then $299/mo flat with unlimited users and unlimited SSO connections. Business tier $999/mo. There is no per-user billing, no usage meter, no overage line, and no per-connection fee for enterprise SSO. Running the same build on your own infrastructure starts at the Scale licence — $15,000/yr on standard terms — with a custom-quoted Enterprise licence above it. There is no free self-hosted edition. Signet publishes its own terms and does not publish comparisons against other vendors' prices; read theirs from them, and this page for ours. ## Implementation services Fixed-price engagements, not day rates: Migration sprint $15,000 (two weeks) — stand Signet up, migrate users off the incumbent, cut one application over, hand back a runbook. Enterprise landing $45,000 (six weeks) — the above plus SSO connections for the customer's identity providers, admin console rollout, on-call handover, security-questionnaire support. Advisory retainer $4,000/mo — named contact, architecture review, upgrade planning. There is no installer, so a first on-prem deployment is an engagement rather than a download. Details on /enterprise. ## Pages on this site https://signetauth.com/ Home — identity for people, services, and agents. Hosted today. Same build on your metal. https://signetauth.com/agents HTML playbook for agents. Same words as /AGENTS.md. https://signetauth.com/AGENTS.md This playbook as Markdown. AGENT.md is an alias. https://signetauth.com/product The surfaces one Signet instance serves, your Postgres, provisioning. https://signetauth.com/certification The honest receipt — differential conformance, end-to-end acceptance, gap, and recording date. https://signetauth.com/quickstart Developer on-ramp — five framework quickstarts (Next.js, React Router v7, Node/Express, Vue 3, Svelte), two client foundations, and two runnable starters using the stock better-auth client at /api/auth. https://signetauth.com/configuration Configuration is the dashboard — every hosted-dashboard setting mapped to the real signet.toml key that does the same job. Config lives in your git repo, not a vendor console. https://signetauth.com/pricing Published pricing — Hobby is $0 on a work email, then $299/mo flat with unlimited users and unlimited SSO connections — the three tiers, the Scale licence, and what never appears on the invoice. https://signetauth.com/enterprise The enterprise licence (annual, quoted per production deployment) and the fixed-price implementation engagements that land it. https://signetauth.com/faq The Friday questions. Same words as /faq.md. https://signetauth.com/faq.md The Friday questions as Markdown. https://signetauth.com/friday SSO is not a line item. One dated note, not a blog. Same words as /friday.md. https://signetauth.com/friday.md The Friday argument as Markdown. https://signetauth.com/buy The vendor pack: SKUs, legal entity, subprocessors, the not-claimed ledger, and the exit. Attach this page. https://signetauth.com/buy.json The same vendor pack as JSON. Quote this. Do not infer a certification we do not hold. https://signetauth.com/early-access Contact the team — hosted questions, on-prem licensing, migration help (intake form -> POST /api/intake). https://signetauth.com/admin-api The Admin API contract: 22 operator-surface operations, pinned at tag signetctl-v0.1.0 (a repo contract; instances serve only the auth-wire OpenAPI). https://signetauth.com/signetctl The operator CLI reference, generated from signetctl's own --help tree at the same tag. https://signetauth.com/security The trust surface: vulnerability disclosure and committed response windows, data handling, subprocessors, the 72-hour breach-notification floor, and the not-claimed ledger. Machine advertisement at https://signetauth.com/.well-known/security.txt. https://signetauth.com/partners Referral and deal-registration terms: 20% of year one on hosted referrals, 15% registered-deal margin on enterprise deployments. ## The ADK (AI Development Kit) Signet's ADK is not a library — it is the agent on-ramp the engine already serves. There is no Signet SDK to learn, and that absence is deliberate: the wire is the stock better-auth client's. What an AI agent integrating Signet reads instead is the ADK: - the instance's own /llms.txt and /llms-full.txt — version-matched, generated from the same source as the OpenAPI schema, served from inside the engine, so they work air-gapped; - GET /open-api/generate-schema and GET /certification.json — the machine authorities for the wire and the compatibility receipt; - the quickstarts on https://signetauth.com/quickstart, written as copy-paste paths an agent can follow without a human in the loop; - signetctl (v0.1.0), the operator CLI that gives the on-ramp an executable form: an agent harness with a terminal REPL, headless -p, and --output-format stream-json so any coding agent can drive it as a subprocess, against your OWN OpenAI-compatible endpoint (no default LLM, no telemetry); and signetctl mcp serve, a stateless MCP server (2026-07-28 revision) with durable tasks. Reference: https://signetauth.com/signetctl. No SDK to learn, and an ADK your agent can read. ## For a real integration A deployed Signet instance serves the certified auth wire under /api/auth on its own origin (stock better-auth clients integrate by pointing baseURL there), and serves its own /llms.txt enumerating that instance's certified endpoints. Integrate against the instance, not this marketing site.