accounts and commerce
shared identity, billing, and marketplace payouts across products.
one account service signs people in across hraness products with email codes instead of passwords. the hard parts sit where the pieces meet: keeping payment state idempotent, provider calls signed, and product data separate from identity.
this category covers the machinery behind paid software: central identity, webhooks that grant nothing until verified, double-entry credits, and marketplace payouts.
lessons
- one identity, many products: shared identity, per-app entitlementstart here · product-local sessions stay product-local
- idempotent checkout and signed webhooks, fail-closed · the success page is not the source of truth
- a credits ledger agents can spend against: double-entry for computesubscriber · holds, captures, and one transaction per mutation
- marketplace payout boundaries: what the platform owns and what it never touches · the line between asker and askee
projects
- suite-accounts · the sign-in and authorization package hraness products share.
- account.hraness.com · the deployed identity, subscription, and entitlement service.
- support · the free, community, and pro plans; paid plans bill through the same account service.
by hraness · drafted with ai assistance