I think Logto will be good at “standalone identity service”, which means you can delegate all the sign-ins and user identity issues to Logto. (Just like SSO)
So you can have only one Logto installed, and add multiple “API resources” (for apps with a dedicated API service) and “applications” (for traditional web apps or your native/spa clients) in Logto. No matter they are remote or local, VPS or SaaS.
The logic is simple:
- for clients and traditional web apps, when it detects user is not signed in, use SDK to redirect to Logto
- for API services, add a middleware function to check if the request holds a valid token
If you’d like to connect a third party identity provider, “connectors” will be your friend.
These cases are covered in the docs.
Hope my reply helps. Feel free to join our discord channel or send us an email if you have any questions. :-)