Skip to content

Overview

Kubernetes-native NHI identity broker and shared signals aggregator.

Starfly validates source credentials, evaluates OPA policy, and mints WIMSE-compliant JWTs via RFC 8693 token exchange.

When mTLS is enabled, protected endpoints run on port 8694. Public endpoints (health, JWKS, metrics) always run on port 8693.

Information