All Weke consoles Open your account

Token coverage

One ID, many audiences.

A session proves who you are; an audience token says which door you are opening. The split is the security model — capability is granted one console at a time, and never travels further than it was minted for.

A working day by token type Illustrative fixture data.
Session tokens issued
4,820
Audience grants
1,650
Refresh exchanges
980
01

Session tokens

  • Issued at sign-in, 15-minute life
  • RS256-signed; the issuer is wekelogin.com
  • Refreshed quietly so short life costs nothing
Who you are
02

Audience tokens

  • Exchanged from a session, per console
  • aud names exactly one app
  • A billing token opens billing — full stop
Which door
03

Service verification

  • Public keys at /.well-known/jwks.json
  • Every service verifies for itself
  • No shared secrets between consoles, ever
Proof, not trust

The estate

The doors this ID opens

Twelve surfaces across money, operations, and infrastructure — the full directory lives on the platform hub, and every entry answers to the same key.

The Weke console directory on wekedev.com