Enterprise Software

Product Handoff Tokens: How Suite Navigation Works Without Shared Sessions

Short-lived, single-use handoff tokens let Suite Home open CRM, finance, and receptionist portals without a second login — and why that differs from enterprise SSO.

By Osama Qaseem · September 3, 2026

  • Suite Platform
  • Auth
  • Architecture
  • Multi-tenant

Product Handoff Tokens: How Suite Navigation Works Without Shared Sessions

Suite navigation sounds simple: click CRM in the launcher, land in CRM. In practice, each product runs its own NestJS API, Next.js portal, and session store. Sharing cookies across subdomains does not scale when products deploy independently.

Handoff tokens solve this: the gateway issues a short-lived, single-use token; the target product portal exchanges it for a local session. Users experience one click; architects keep clean product boundaries.

Guide: Suite gateway buyer's guide · Product: Suite Platform


The flow in four steps

  1. User is authenticated in Suite Home (gateway session)
  2. User clicks an entitled product — e.g. CRM
  3. Platform mints a handoff token bound to user, tenant, and target product
  4. CRM portal validates the token once, creates a CRM session, invalidates the token

Seconds from click to working CRM UI — without storing CRM sessions in the gateway.


Handoff vs SSO (practical distinction)

HandoffEnterprise SSO
PurposeOpen a specific product from suite launcherFederate identity across unrelated apps
Token lifeShort, single-useProtocol-dependent (often longer)
Session ownerEach product portalIdP + app session
Best forModular suite under one operatorCorp-wide app catalog

You can add SAML/OIDC later. Handoff ships value for suite UX without waiting on IdP projects.


Security properties that matter

  • Single-use — replay fails after redemption
  • Short TTL — minutes, not days
  • Product-scoped — token for CRM cannot open finance portal
  • Tenant-scoped — entitlements checked before minting

Service links: how products find each other

Handoff needs the gateway to know each product's portal URL. Service link registry stores:

  • API base URL and API key for federation metrics
  • Portal URL for handoff redirects
  • Product tenant ID mapping
  • Link mode: native / read / sync

No more CRM_PORTAL_URL scattered across twelve env files.


Entitlements gate the launcher

Products not entitled for a tenant never appear in Suite Home. Handoff minting also checks SKU flags — you cannot hand off to finance if finance is not on the plan.


Honest limitations

  • Handoff is not a substitute for product-to-product API auth — use service links and API keys for server-side calls
  • Federation metrics require configured service links; without them, Suite Home shows gateway entities only
  • Each product must implement token validation — shared TypeScript contracts help

Further reading

Contact Tekvers if you are wiring handoff into a new product SKU.