Skip to content

Starfly documentation

This content is for v1.0. Switch to the latest version for up-to-date documentation.

Starfly secures agents without replacing your IdP — turn platform credentials into scoped WIMSE JWTs, kill compromised access in milliseconds, and verify tool calls on one fabric.

Getting started

Running PEP and your first WIMSE JWT in 15 minutes — no cluster required.

Start the tutorial

Glossary

Trust domain vs audience, PEP, UTC, and every term the dashboard AI bar uses.

Read the glossary

Playground

Step through sandbox scenarios with screenshots — exchange, revocation, federation, MCP.

Open playground

API reference

RFC 8693 exchange, MCP verify, signals, federation — generated from OpenAPI.

Browse API

  1. Exchange stays fast — no new synchronous dependencies on the token exchange pipeline.
  2. Revocation stays fast — kill-switch propagation latency is not negotiable.

Async surfaces (dashboard, graph, UTC) observe the fabric — they never block exchange or revocation.