
Synx Pass
Identity, authentication, and ownership.
- People, services, machinesRecognized on the domain
- AuthenticationWho is connected
- Ownership controlAccess follows the owner
- Access that can moveWhen ownership moves

Identity and authentication for Morph Space

Identity, authentication, and ownership.
Synx Pass is the identity and authentication system for the Morph Space ecosystem. It authenticates the people and agents who use Real Time Web services, and it is the identity layer used by Morph Space and the Synx tools.
The network architecture does not require one authentication technology. Synx Pass is Synx's implementation, currently based on Keycloak. It establishes who is connected. Synx DNS and Synx BIOS use that identity when applying ownership and access rules.
Machines and AI agents can take part through Ghosts, under an accountable human or organizational identity. Synx Pass verifies who you are. The Ghost determines which data belongs to you or is available to you.
Synx Pass is the identity and authentication system for Morph Space. The network architecture does not require one security technology. Synx Pass is Synx's implementation, currently based on Keycloak.
Synx Pass is the identity and authentication system used within the Morph Space ecosystem. It authenticates users who want to access Real Time Web services and provides the identity layer used by Morph Space and the Synx tools.
The Real Time Web is based on Morphic Architecture Design (MAD), described at RealTimeWeb.org. MAD defines the underlying network architecture but deliberately does not mandate a specific authentication or security technology. Instead, the architecture is designed to be tokenized and adaptable to different identity and authentication systems. Implementations may therefore use different technologies, including decentralized identity systems, blockchain-based solutions, or proprietary authentication protocols.
Synx Pass is the authentication implementation provided by Synx for Morph Space. It is currently based on Keycloak and provides identity, authentication and token management for users, agents and the Ghosts representing resources within the Morph Space ecosystem. In simple terms, MAD defines how the network can work. Synx Pass provides a trusted identity layer for our implementation of it.
Synx Pass registers and authenticates users and authorized agents, then associates that identity with domains, services, and Ghosts. Synx Pass establishes identity. Synx DNS and Synx BIOS use it for ownership and access.
Synx Pass is used to register and authenticate users and authorized agents participating in Morph Space. Once authenticated, the user's identity can be associated with domains, services and Ghosts within the Real Time Web. Morph Space uses this identity to determine who is interacting with a domain or resource, while the Synx tools determine what that authenticated identity is permitted to do.
Token-based authentication is used to maintain secure sessions. Tokens can be refreshed dynamically as clients and Ghosts interact with services, allowing authentication to remain active during long-running real-time connections. This separation is important. Synx Pass establishes identity. Synx DNS and Synx BIOS use that identity when applying ownership and access rules.
Synx Pass verifies who you are. Ownership and data access are decided by the Ghost, through Synx DNS and Synx BIOS. A channel can stay connected while data is withheld until the authenticated user has access.
Synx Pass authenticates the user, but it does not itself determine ownership of the underlying data. Data ownership and access are managed through the Ghost and the control mechanisms provided by Synx DNS and Synx BIOS. A Ghost represents an endpoint or network resource within the Real Time Web. At the data layer, ownership of that Ghost determines which authenticated user is entitled to receive data from the associated source.
This creates an important distinction between connection and data access. A network channel may technically exist while the authenticated user does not own, or has not been granted access to, the relevant Ghost. In that situation, the channel can remain established, but data from that source is not delivered to the user. When ownership or permission changes, access to the data channel can change accordingly without requiring the underlying data source to be migrated or duplicated. The principle is: Synx Pass verifies who you are. The Ghost determines which data belongs to you or is available to you.
Yes. Agents and machines can use authenticated services through Ghosts, under an accountable human or organizational identity. An autonomous agent cannot create an identity on its own under the current Synx policy.
Yes, AI agents and machines can participate in authenticated Real Time Web services, but within the current Morph Space model they operate under an accountable human or organizational identity. At runtime, machines and AI agents interact with the network through their associated Ghosts. A Ghost can be owned or controlled by an authenticated user, allowing an AI agent, robot, device or software process to operate within permissions associated with that identity.
Under the current Synx policy, an autonomous agent cannot independently create an identity without being associated with a responsible human or organization. This is primarily a governance and accountability decision rather than a fundamental technical limitation. Our objective is to allow machines to operate autonomously while maintaining a clear chain of ownership and responsibility. Machines can act autonomously. Their authority still comes from an accountable owner.
Sign-in can look familiar. After authentication, identity, resource ownership, data access, and service access stay separate, so one of those rights can change without the others.
From the user's perspective, Synx Pass can look very similar to a traditional authentication system. You register, identify yourself and authenticate using familiar mechanisms. The important difference appears after authentication. In a conventional application, authentication, application permissions, data access and service control are often managed together by the same application or backend. The Real Time Web separates these concerns across different control layers. This means that several different rights can coexist independently.
Identity: Synx Pass establishes who the participant is. Resource ownership: the Ghost identifies ownership or control of a network resource. Data access: determines whether data from a particular source can reach the authenticated endpoint. Service access: the service provider can determine whether a participant may use a particular service or intelligent transformation. This separation creates an important property. A user may have legitimate access to a data source while access to a particular service that transforms that data is withdrawn. Conversely, a service connection may exist while the user does not have permission to receive data from a particular source.
For example, a service provider may operate intelligence that transforms raw sensor data into a prediction. The user may control access to the underlying sensor data, while the service provider retains control over access to the transformation or intelligence they provide. The service provider can therefore terminate access to the service without changing ownership of the user's underlying data source. This creates a separation between who you are, what you own, what data you may receive, what service you may use, and who controls the intelligence applied to that data. That separation is one of the fundamental design principles behind the Real Time Web.