Enterprise Software
Product Handoff Tokens: How Suite Navigation Works Without Shared Sessions
Short-lived, single-use handoff tokens let Suite Home open CRM, finance, and receptionist portals without a second login — and why that differs from enterprise SSO.
Product Handoff Tokens: How Suite Navigation Works Without Shared Sessions
Suite navigation sounds simple: click CRM in the launcher, land in CRM. In practice, each product runs its own NestJS API, Next.js portal, and session store. Sharing cookies across subdomains does not scale when products deploy independently.
Handoff tokens solve this: the gateway issues a short-lived, single-use token; the target product portal exchanges it for a local session. Users experience one click; architects keep clean product boundaries.
Guide: Suite gateway buyer's guide · Product: Suite Platform
The flow in four steps
- User is authenticated in Suite Home (gateway session)
- User clicks an entitled product — e.g. CRM
- Platform mints a handoff token bound to user, tenant, and target product
- CRM portal validates the token once, creates a CRM session, invalidates the token
Seconds from click to working CRM UI — without storing CRM sessions in the gateway.
Handoff vs SSO (practical distinction)
| Handoff | Enterprise SSO | |
|---|---|---|
| Purpose | Open a specific product from suite launcher | Federate identity across unrelated apps |
| Token life | Short, single-use | Protocol-dependent (often longer) |
| Session owner | Each product portal | IdP + app session |
| Best for | Modular suite under one operator | Corp-wide app catalog |
You can add SAML/OIDC later. Handoff ships value for suite UX without waiting on IdP projects.
Security properties that matter
- Single-use — replay fails after redemption
- Short TTL — minutes, not days
- Product-scoped — token for CRM cannot open finance portal
- Tenant-scoped — entitlements checked before minting
Service links: how products find each other
Handoff needs the gateway to know each product's portal URL. Service link registry stores:
- API base URL and API key for federation metrics
- Portal URL for handoff redirects
- Product tenant ID mapping
- Link mode: native / read / sync
No more CRM_PORTAL_URL scattered across twelve env files.
Entitlements gate the launcher
Products not entitled for a tenant never appear in Suite Home. Handoff minting also checks SKU flags — you cannot hand off to finance if finance is not on the plan.
Honest limitations
- Handoff is not a substitute for product-to-product API auth — use service links and API keys for server-side calls
- Federation metrics require configured service links; without them, Suite Home shows gateway entities only
- Each product must implement token validation — shared TypeScript contracts help
Further reading
Contact Tekvers if you are wiring handoff into a new product SKU.