Authenticate against your local Keycloak realm. Your access token carries the
tenant claim — the sole source of tenant identity the kernel trusts (I1).
realm aseos-tenants · public PKCE client aseos-portal
Session
verified
AI Operations
Providers
Routing
Usage
Cache
Context
Events
Audit
Reliability
LOCAL_STATUS
Flow result
Tenant administration
every mutation is a capability-gated kernel syscall