The Architecture
One foundation. Infinite possibilities.
Every product in the studio shares a single infrastructure layer. Solved once, shared across everything. This is how one studio operates 9 products.
One login across all products. OIDC-compliant SSO, JWT with JWKS validation, multi-tenant org management.
Stripe orchestration with automated provisioning.
Usage, revenue, and health across the portfolio.
Email, newsletters, notifications. One gateway.
Model Context Protocol connecting agents to operations.
Keys, domains, activations. Software stays secure.
Ingress, fan-out, replay. Events where they need to go.
Provider-agnostic files with tenant isolation.
Deep Dive
How each layer works.
Every product in the ecosystem authenticates through ALKEYON. A user signs up once and gets access to every service their organization subscribes to. No separate logins, no password fatigue.
Reseller handles the entire subscription lifecycle: checkout, payment processing, and workspace creation. When a customer pays, their environment is provisioned automatically - databases, DNS, secrets, everything.
A single analytics layer that spans every product. Track events, monitor active users, measure revenue - all from one dashboard. No separate analytics tools per product.
FF Mail provides transactional email with automatic retry and provider failover (Resend, SendGrid, SES). FF Newsletter handles subscriber management and campaign delivery. One infrastructure for all outbound communication.
FF MCP exposes 84+ tools across the entire platform via the Model Context Protocol. Connect Claude, ChatGPT, or any MCP-compatible assistant - your AI can manage billing, send emails, check analytics, and provision customers through conversation.
License manages software protection across every product: activation limits, domain locking, trial periods, and real-time validation. One licensing system shared by the entire portfolio.
Router receives webhooks from external services (Stripe, GitHub, etc.) and fans them out to multiple internal destinations. Automatic retries, payload logging, and one-click replay for debugging.
S3-compatible file storage with strict tenant isolation. Each organization gets its own storage namespace. Provider-agnostic - swap backends without changing application code.
This infrastructure is what we call FlowPrime -
and it's available to every builder who shares our standard.