Authorization Code + PKCE
Authentication is delegated to Keycloak without collecting credentials in Budgetly.
BUDGETLY · M1
Budgetly is building a household planning system that connects income, obligations, funding, goals, and actual activity without turning shared finances into a spreadsheet puzzle.
Authentication is delegated to Keycloak without collecting credentials in Budgetly.
Access and refresh tokens remain encrypted behind the BFF/API boundary.
Membership checks and PostgreSQL RLS independently enforce tenant boundaries.
Desktop and compact navigation now sit behind the authenticated household context.