Operational · 17+ apps live

Identity, access and billing
for modern SaaS.

One sign-in. One billing system. Full control across every product. Melyx powers authentication, access and payments for 17+ live apps — so we (and you) can ship real products instead of plumbing.

Sign in with Melyx See how it works
17+
Live apps
2
Regions (EU · Tokyo)
SSO
One identity
Stripe
PCI-handled billing
Powering production apps including
auth.melyx.id cart.melyx.id aigatecloud.com getirishcompany.com dublin24h.com convertlyx.app idea2viral.com idea2post.app news.melyx.id melyx.dev

One backbone. Four jobs.

Architecture

Identity, access, billing and workspaces — connected as one system, not duct-taped vendors.

Identity (Auth Hub) SSO across every Melyx app. Email, magic link, Google & GitHub. Caddy forward_auth protects internal apps with zero per-app code.
Access Control Per-app roles, granular grant / revoke, and a single admin surface that sees who has what across products.
Billing System Stripe-handled cards (we never see the PAN), webhook-driven account provisioning, subscription lifecycle, invoices.
Workspace Management Multi-tenant workspaces, team membership, and per-workspace API keys — the same primitive every Melyx app uses.

Built on standards that don't bend

Trust

No magic. Boring, well-understood building blocks.

OAuth2 + JWTStandard session model. JWTs short-lived, refreshed via HTTP-only cookies.
Stripe-handled cardsPCI-DSS compliance lives with Stripe. Melyx never stores card numbers.
HTTPS everywhereTLS via Cloudflare + Let's Encrypt. HSTS preload on every domain.
Abuse protectionRate limiting, suspicious-login detection, email verification, Cloudflare WAF in front.

Authentication that just works

/auth

One login across every Melyx app. Try it on auth.melyx.id.

Google · GitHub · EmailThe login methods users actually expect — nothing exotic.
Magic linkFor users who don't want a password. Single-use, expiring, signed.
Session & token securityHTTP-only, SameSite, rotate on privilege change. Revocable from the user dashboard.

Manage who can access what

/access

Per-app roles, central admin, full audit log. Same system across every product we ship.

Grant / revoke instantlyOne click cascades across every app a user touches.
Role-based permissionsAdmin / member / viewer per workspace. Customizable per app.
Multi-app controlOne dashboard, every product. Built so we (the operators) trust it first.

Secure billing, zero card-data headaches

/billing

Payments processed via Stripe. Card numbers never touch Melyx servers.

PCI-compliant flowStripe Elements / Checkout in the browser. We see tokens, not PANs.
Subscription lifecycleCreate, upgrade, downgrade, cancel — all webhook-driven. No manual reconciliation.
Webhook automationAccount provisioning, role grants and email notices fire off the same event stream.

Security is not optional

Read more →
Email verificationRequired for every account. Bounces and abuse traps blocked.
Rate limitingPer-IP and per-account. Tunable per endpoint.
Suspicious-login detectionNew IP, new device, impossible travel — all flagged.
Responsible disclosureEmail [email protected] — we respond within 48h.

Built by operators, for operators

Team
M
Mervin · Founder
Builds and runs Melyx from Dublin, Ireland. Has shipped, supported and broken every line of this stack at least once.

Build real products — not infrastructure

Try Melyx auth in 30 seconds. No credit card.

Sign in with Melyx Talk to us