⚠ DEV MODE — auth bypass ativo (FinID OIDC não configurado).
← Catálogo de produtos

FinIDfinid

Identidade + autenticação OAuth2/OIDC. IdP oficial Finaya — não usar Keycloak.

Category: authLayer: coreMaturity: adoptedFicha: enrichedSquad: finid-squad

Papel

Autenticação OpenID Connect / OAuth 2.0, MFA, OTP, validação de dispositivo, identidade federada. CRUD usuário/org/projeto. Emite JWT consumidos por FinWay/FinCore/FinPSTI/FinLabel/FinAI. Suporta device authorization grant (RFC 8628) e authorization code com PKCE.

Enterprise Architecture (5/27 capabilities enriquecidas)

✓ toda capability enriquecida com dono tem accountable declarado
✓ nenhuma entidade com dono ambíguo
OAuth 2.0 / OpenID Connectfinid.oauth2_oidc
A: IDENTITY_LEAD maturidade: ppl4 proc4 tech4 info3VS: VS-auth, VS-onboarding
Session:CRUToken:R
OIDC/OAuth2
Token Management (JWT)finid.token_management
A: IDENTITY_LEAD maturidade: ppl4 proc3 tech4 info4VS: VS-auth
Token:CRUD
JWKS Rotation (public keys)finid.jwks_rotation
A: SECURITY_LEAD maturidade: ppl3 proc2 tech4 info2VS: VS-auth
JwksKey:CRU
Password / PIN Managementfinid.password
A: SECURITY_LEAD maturidade: ppl4 proc3 tech3 info3VS: VS-auth
Credential:CRU
MFA TOTP (Google Authenticator-like)finid.mfa_totp
A: SECURITY_LEAD maturidade: ppl3 proc3 tech4 info3VS: VS-auth
MfaEnrollment:CRU

NÃO é

  • NÃO é Keycloak (decisão explícita Founder)
  • NÃO faz KYC/biometria (FinTrust faz)

Capabilities (27)

⚙️ Funcionais (16)

OAuth 2.0 / OpenID Connect
identity_auth

Authorization Code + PKCE + Refresh + Client Credentials grants. UserInfo endpoint + ID Token. Compatível OIDC.

finid.oauth2_oidc
Device Authorization Grant (RFC 8628)
identity_auth

Device code flow para CLI / IoT / TVs. Polling, device verification URL.

finid.device_flow
Token Management (JWT)
identity_auth

Emissão, validação, revogação de JWT. Claims custom Finaya (tenant_id, persona, scopes).

finid.token_management
JWKS Rotation (public keys)
identity_auth

Rotação automática de chaves públicas JWKS para validação de tokens.

finid.jwks_rotation
Password / PIN Management
identity_auth

Cadastro, troca, recuperação de senha. Validação de força, hashing bcrypt/argon2.

finid.password
MFA TOTP (Google Authenticator-like)
identity_auth

Multi-factor TOTP. Geração QR enrollment, validação 6 dígitos, backup codes.

finid.mfa_totp
OTP (SMS / Email)
identity_auth

One-time password via SMS ou email para confirmação de transação/login.

finid.otp
Push-based 2FA
identity_auth

Aprovação via push notification no app (alternative to TOTP/OTP).

finid.push_2fa
Device Validation / Fingerprint
identity_auth

Identificação e validação de dispositivos confiáveis (fingerprint, device binding).

finid.device_validation
Session Management
identity_auth

Gestão de sessões ativas, logout global, timeout, concurrent sessions limit.

finid.session
User Management (CRUD usuário)
admin

CRUD de usuários, persona (PF/PJ), claims, atributos custom.

finid.user_management
Organization / Tenant
admin

CRUD de organizações/tenants. Hierarquia org→projects→users.

finid.organization
Project / Application
admin

CRUD de projects (clients OAuth). Configuração de redirect_uris, scopes, secrets.

finid.project
Roles & Permissions (RBAC)
admin

Roles, permissions, scopes. RBAC granular por endpoint.

finid.permissions
Embedded Auth (iframe SDK)
integrations

Auth widget embed via iframe + JS SDK para integração nos apps clientes.

finid.embedded_auth
Federated / Social Login
identity_auth

Login via Google / Apple / Microsoft / GitHub federado (alternative ao login Finaya).

finid.federated_login

🔧 Não funcionais (11)

Multi-tenancy
architecture

Multi-tenant: tenant_id em todos endpoints, isolação Postgres schema/RLS.

finid.nf.multi_tenancy
Starter / SDK Lib
architecture

Lib starter para consumidores (Java/TS) integrarem FinID rapidamente.

finid.nf.starter
Cache (Redis)
performance

Cache distribuído Redis para JWKS, tokens validados, sessions.

finid.nf.cache
Observability
observability

Logs estruturados + métricas + traces OTel. Auditoria de eventos auth.

finid.nf.observability
Audit Log (eventos auth)
compliance

Audit log de login, logout, falhas auth, mudança de senha, criação de cliente OAuth.

finid.nf.audit
Security (HSM, secrets)
security

HSM para chaves de assinatura JWT. Secrets management. Encryption at rest.

finid.nf.security
Rate Limiting
reliability

Rate limit em endpoints auth (login, refresh, OTP) para prevenir brute force.

finid.nf.rate_limit
LGPD Compliance
compliance

Conformidade LGPD: direito ao esquecimento, portabilidade, consentimento.

finid.nf.lgpd
DevOps / Infra Automation
release

Automation de infra (Terraform, K8s manifests, deploy scripts).

finid.nf.devops
Dependency Management
release

Bumps de dependências (Dependabot, deps automation).

finid.nf.deps
CI/CD Pipeline
release

Pipeline CI/CD (Jenkins / GitHub Actions), testes automatizados, deploy.

finid.nf.ci_cd

Dependências (1)

ProdutoTipoViaDescrição
finsourceaudits_toevent_async

Controles (5)

  • lgpd
  • antifraude
  • segregacao_acesso
  • audit_log
  • token_rotation

Gates obrigatórios (3)

  • jwt_validation_test
  • token_revocation_test
  • jwks_rotation_test

Timeline · 13 func · 9 não-func · ~22 meses · 5.2 FTE atual

Início
2024-07
Meses ativos
~22
Custo estimado
R$ 2.6M
FTE atual
5.2
Entregas
22
Método de estimação: inferred_from_deps_dates + ficha_vault — IdP Tier 0; squad confirma
Evidências: Ficha: status enriched 2026-04-28 + Spring Boot + OAuth2 + OpenAPI · Consumido por TODOS outros produtos (FinWay/FinCore/FinPSTI/FinLabel/FinAI/FinIB) · Decisão Founder: FinID é IdP oficial Finaya — NÃO usar Keycloak

Evolução do time

PeríodoComposiçãoFTE totalCusto/mês (BRL)
2024-07 → 2024-121× tech_lead2× senior1× qa@30%3.3R$ 90.400
2025-01 → 2025-121× tech_lead3× senior1× qa@50%1× sre@50%5.0R$ 131.500
2026-01 → atual1× tech_lead3× senior1× qa@50%1× sre@50%1× product_owner@20%5.2R$ 136.000

Entregas funcionais (13)

  1. 2024-07Kickoff FinID — IdP próprio Finaya (não Keycloak)
    Decisão estratégica: construir IdP próprio em vez de usar Keycloak. Razão: claims customizadas (persona, tenant_id), governança full-control, alinhamento com produtos Finaya.
    source: inferred
  2. 2024-09OAuth2 Authorization Code grant (RFC 6749)
    Fluxo OAuth2 padrão: authorize endpoint + token endpoint + JWKS. Confidential clients com client_secret.
    source: inferred
  3. 2024-10OIDC UserInfo + claims customizadas Finaya
    Endpoint `/oauth/userinfo` retorna claims OIDC + custom: `persona` (founder/dev_finaya/compliance/etc) + `tenant_id`.
    source: inferred
  4. 2024-12MFA TOTP + SMS
    Multi-factor auth: TOTP (apps tipo Google Authenticator) + SMS (fallback). Configurável por user.
    source: inferred
  5. 2025-02Refresh token + revogação
    Refresh token grant (RFC 6749 §6) + endpoint de revogação. Rotation de refresh_token opcional.
    source: inferred
  6. 2025-03Device fingerprint (validação dispositivo)
    Fingerprint baseado em User-Agent + IP + canvas + timezone. Detecta login de device novo → trigger MFA.
    source: inferred
  7. 2025-05CRUD usuário/org/projeto + admin API
    API admin para gestão de users, organizações, projetos. Persona-based access control.
    source: inferred
  8. 2025-06Cliente Torra + PicPay + Getnet em produção
    4 clientes em produção (Assaí, Torra, PicPay, Getnet). FinID virou dependência crítica de todos os outros produtos Finaya.
    source: inferred
  9. 2025-08Cliente Crefisa + PSTI integration
    Crefisa integrado: FinID emite tokens consumidos por FinPSTI. Auth Tier 0 + PSTI Tier 0 = setup crítico.
    source: inferred
  10. 2025-10Single Sign-On entre produtos Finaya
    SSO: user autentica no FinID e navega entre FinIB/FinLabel/FinAI sem re-login. Token compartilhado via cookie httponly.
    source: inferred
  11. 2025-12Cliente Corpx + OZ Câmbio: indirect Pix
    FinID autentica Corpx e OZ Câmbio (indirect Pix participants). Integração com FinCore + FinWay.
    source: inferred
  12. 2026-01Device authorization grant (RFC 8628)
    Suporte ao device-code flow para CLIs (`finaya-mcp-server login`). Prepara MCP servers + Claude Desktop integration.
    source: inferred
  13. 2026-03Onboarding self-service via OAuth Authorization Code
    User Finaya autentica via FinID OAuth e portal aprende mapping (sem touch no FinID admin API). Base para integração Slack ↔ FinID.
    source: inferred

Entregas não funcionais (9)

  1. 2024-08Stack Spring Boot + Spring Security + Postgres
    Setup baseline: Spring Boot 2.7 + Spring Security 5.x + Postgres como persistência. JWT com RS256.
    source: inferred
  2. 2024-11JWKS endpoint + rotation strategy
    `/.well-known/jwks.json` com rotation key automática. Cache 24h em consumers.
    source: inferred
  3. 2025-01Audit log estruturado + LGPD compliance
    Toda operação (login, MFA, token issue, revoke) gera audit log com IP, device, geo. Pré-requisito LGPD.
    source: inferred
  4. 2025-04Cliente Assaí: 95k usuários onboarded
    Primeiro cliente high-scale: Assaí RH (95k colaboradores). Stress test passou; tuning Postgres + cache JWT.
    source: inferred
  5. 2025-07HA: multi-AZ + Redis Sentinel para tokens
    High availability: deploy multi-AZ + Redis Sentinel para token cache. RPO < 1min; RTO < 5min.
    source: inferred
  6. 2025-09Performance: JWT cache + connection pool tuning
    Cache de JWT decode + connection pool Postgres ajustado. Login p99 < 200ms.
    source: inferred
  7. 2025-11Pen-test externo + remediation
    Pen-test contratado (empresa externa). Encontrados 3 findings médios; remediados em 30 dias.
    source: inferred
  8. 2026-02JWKS rotation automática + alerting
    Rotation de keys JWKS a cada 90 dias automaticamente. Alerts Prometheus se key próximo do vencimento.
    source: inferred
  9. 2026-04Ficha Vault enriched + ADR-008 amendment
    Ficha enriquecida 2026-04-28. ADR-008 amendment formaliza 7 layers safety deny-first.
    source: docs · evidence ✓

Squad owner de finid enriquece via PR em packages/ts/products-catalog/src/products/timelines/finid-timeline.ts

Capabilities — evolução técnica (17 capabilities · 1045 commits mapeados em 90.6%)

Método de mapeamento: priority: (1) repo único de capability; (2) conventional scope match; (3) longest keyword in message
Repos analisados: 9 repos → buildersid-auth, bb-auth-core, bb-auth-core-voltz, buildersid-2fa, buildersid-admin, +4
Unmapped: 98 commits (squad refina catalog em packages/ts/products-catalog/src/products/capability-catalogs/)

⚙️ Capabilities funcionais (12)

OAuth 2.0 / OpenID Connect🔥 Evoluindoidentity_auth
Authorization Code + PKCE + Refresh + Client Credentials grants. UserInfo endpoint + ID Token. Compatível OIDC.
335 commits
2021-082026-07
finid.oauth2_oidc · 44 meses de atividade · 11 feat · 14 fix · 0 refactor
MêsTotalfeatfixrefactorAmostras (até 5)
2026-077020
423d4fd fixgerar par de chaves RSA quando ausente no Redis (#192)
26a973c fixajuste de cves
7c4ae20 other3.0.0 (#194)
2026-069130
89c7da7 featadd SSO token exchange endpoint POST /v1/auth/sso-exchange (#185)
0a0e4f0 fixajuste de cves
c5a8443 fixvulnerabilidades
2026-0515000
7790acc otherupdate core commons
b42630a other3.0.0-rc-1 (#176)
c2b5655 otherMerge pull request #175 from buildersbank/develop
2026-0311230
acc3b3e featpublish Redis PubSub event on profile assignment and removal
845223c featadd features, menu sections and menu builder
5bf3939 fixresolve SonarQube code smells - unused import and containsEntry assertions
2026-024000
b150ab1 other1.8.0
fdb2df3 othermerge master
dcc5db6 other1.8.0-rc
2026-013000
1163020 other1.7.2
c784778 othermerge master
d60a671 other1.7.2-rc
2025-1211000
43de960 other1.7.1
058332a othermerge master
68711b8 other1.7.1-rc-2
2025-111000
c0a0423 otheradd optional userId to access token generated from client credentials
2025-101000
aaf28f0 otherAtualizando pullrequest.yaml
2025-0955150
b077945 featRelease Workflow
4c96f1f fixpom.xml
16feeb9 fixwrong commit
2025-0816100
4ca3d9c featupdate pom version
7205cd6 otherUpdate ci-cd.yaml
82f3157 otherUpdate Dockerfile
2025-061000
509ac59 otherCriando .github/CODEOWNERS

+ 32 meses anteriores omitidos.

User Management (CRUD usuário)🔥 Evoluindoadmin
CRUD de usuários, persona (PF/PJ), claims, atributos custom.
197 commits
2021-102026-07
finid.user_management · 36 meses de atividade · 15 feat · 4 fix · 0 refactor
MêsTotalfeatfixrefactorAmostras (até 5)
2026-074000
0025223 other3.0.0
3030366 otherMerge pull request #63 from buildersbank/develop
dc6cab6 otherMerge pull request #62 from buildersbank/merge-master
2026-0610120
d7d7cb1 featadd IdpConfig with trustedPortalSecret, collection IdpConfigs, REST + gRPC endpo…
c7ec3bf fixajuste de cves
3cb36fa fixcorrige CVEs criticos (netty 4.1.135.Final, spring-data-mongodb 4.5.12, tomcat 1…
2026-0515000
f091528 otherMerge pull request #165 from buildersbank/fix/multiconta-business-signature-user…
479dc7b otherupdate core commons
f0e5317 otherfix sonar
2026-0320220
e233b34 featadd account user registration, listing and login validation
2076374 featadd profiles and user account profile management
c8da69a fixfix validateUserActive bypass and add user profiles endpoint for login flow
2026-024000
9feedda other1.5.0
18368d6 othermerge master
b87b827 other1.5.0-rc
2025-129000
7701348 otherfix userId blank
c23cdd4 otheradd userName to client credential with userId
862fd64 otheradd clientid ips
2025-112100
538c4ef featremove app client cache (#38)
99130bd otheradd optional userId to AppClient
2025-101000
768148c otherAtualizando pullrequest.yaml
2025-091000
4edb217 otherAdicionando .github/workflows/pr-version-check.yaml via script
2025-083100
cd058c3 featfind user credentials
9d08c38 otherMerge pull request #41 from buildersbank/develop
a845c13 otherMerge pull request #37 from buildersbank/feat/user-credentials
2025-061000
a05c061 otherCriando .github/CODEOWNERS
2025-051000
0fd6000 otherUpdate ci-cd.yaml

+ 24 meses anteriores omitidos.

MFA TOTP (Google Authenticator-like)🔥 Evoluindoidentity_auth
Multi-factor TOTP. Geração QR enrollment, validação 6 dígitos, backup codes.
114 commits
2021-102026-07
finid.mfa_totp · 29 meses de atividade · 8 feat · 4 fix · 0 refactor
MêsTotalfeatfixrefactorAmostras (até 5)
2026-074000
382151a other3.0.0
7e518ab otherMerge pull request #107 from buildersbank/develop
485feb7 otherMerge pull request #106 from buildersbank/merge-master
2026-0612040
28fcfa5 fixNPE ao injetar stub MessageTemplateServiceBlockingStub
08cdc8e fixcorrige CVEs criticos (netty 4.1.135.Final, spring-data-mongodb 4.5.12, tomcat 1…
0eb84b3 fixsuporte alfanumerico (IN RFB 2.229/2024)
2026-059000
44d792b otherfix sonar
f428fc6 otheradd tests
d525c63 otherMerge pull request #97 from buildersbank/fix/adjusting-dependency-grpc
2026-033100
ebd44bd featadd flag to disable sending code
6a379e0 otherfix image java version
50d2cce otherfix ci java version
2026-021000
719702a otherMerge pull request #91 from buildersbank/feat/setup-api-on-catalog-info
2025-122000
8d441f6 otherAtualizando pullrequest.yaml
09278e2 otherAdicionando permissão pull-requests: write ao workflow
2025-101000
a74e524 otherAtualizando pullrequest.yaml
2025-091000
42cce87 otherAdicionando .github/workflows/pr-version-check.yaml via script
2025-081000
a503884 otherMerge pull request #88 from buildersbank/develop
2025-061000
92e88da otherCriando .github/CODEOWNERS
2025-051000
101e108 otherUpdate ci-cd.yaml
2025-031000
76fabf2 otherUpdate Dockerfile

+ 17 meses anteriores omitidos.

Token Management (JWT)○ Estávelidentity_auth
Emissão, validação, revogação de JWT. Claims custom Finaya (tenant_id, persona, scopes).
56 commits
2021-112026-06
finid.token_management · 19 meses de atividade · 3 feat · 1 fix · 0 refactor
MêsTotalfeatfixrefactorAmostras (até 5)
2026-062000
7fdbe6e otherfix generate access token sso (#188)
0abeda2 othersave sso token in redis (#187)
2026-031000
ccde383 othervalidate token attributes test
2026-021100
698e63a featadd user revoke token endpoint
2025-125200
0fb06c7 featadding scopes list to user token generation request
b483027 otherfix token generation with userId
2a4df9a otherMerge pull request #104 from buildersbank/feature/add-scopes-to-user-token-gener…
2025-092010
781f8a1 fixintegration user token
22cd321 othertest token
2025-044000
880077d otherMerge pull request #77 from buildersbank/feature/exchange-id-for-access-token
b3f9589 otherCriação de um método que recebe o userId e gera um access-token para a funcional…
ce97f10 otherMerge pull request #31 from buildersbank/feature/exchange-id-for-access-token
2024-092000
b3f6bb9 otheradd config to remove previous access token
64f7a7f otherchange token scopes rules for client id token
2024-042000
9d47186 otheradd expires in token response
cdb8828 otheradd expiresIn attribute in token response (#29)
2024-032000
e56eba6 otherfix seconds to add ttl token
7207bda othermin ttl token 120 sec
2024-011000
df8bc52 otherfix jwt expires time
2023-052000
f90d28d otherMerge pull request #65 from platformbuilders/feature/limit-tokens-per-client
530063b otherMerge pull request #30 from platformbuilders/feature/limit-tokens-per-client
2022-104000
8e2fa47 otherAdicionando log em JWTUtils
4524e55 otherTratando header issuer para token de ClientCredentials
cfcdefd otherMerge pull request #52 from platformbuilders/feature/jwt-client-id-header

+ 7 meses anteriores omitidos.

Organization / Tenant✓ Maduroadmin
CRUD de organizações/tenants. Hierarquia org→projects→users.
49 commits
2021-102026-06
finid.organization · 13 meses de atividade · 6 feat · 2 fix · 0 refactor
MêsTotalfeatfixrefactorAmostras (até 5)
2026-061010
c00c4f4 fix[PSTI-582] bumping multitenancy dependency version to fix app broken
2026-033110
70ac452 featadd name, email, document, tenantId and assignedBy fields to AssignProfileReques…
31337b1 fixpropagate TenantContext in async event listener aligned to fin-bko pattern
d987fe7 othercreate method enrichTokenWithAccountProfile to set accountId and tenantId on Tok…
2025-124200
3dece9a featupgrade multitenancy version
f1f8fe7 featupdate multitenancy starter version
3635b68 otherMerge pull request #105 from buildersbank/feat/update-multitenancy-version
2024-105300
f0edd3e featadd find organization and app client
43df03e otherupdate multitenant lib
5a13894 otherMerge pull request #39 from buildersbank/feature/find-organizations
2024-071000
f64b6e4 otheradd reload organization client option
2024-011000
85adc4b otherupdate redis and multitenant
2023-124000
72b0f2b otherMerge pull request #71 from platformbuilders/feature/single-tenant
ad69f84 otherAdding single tenant config
b4f85d8 otherMerge pull request #74 from platformbuilders/feature/single-tenant
2023-034000
692181f otherRemoção do Postgres na recuperação de tenants por client_id
ddf3021 otherIncluindo server Grpc para busca de OrganizationClientId
873ba2e otherAjustando retorno de OrganizationClientId
2022-061000
174badc otherInclusão de message bundle para tenant id não informado
2022-054000
3bcd2a1 otherMerge pull request #35 from platformbuilders/feature/update-multitenancy-lib
e2a1d4e otherAtualizando versão do bb-multitenancy-starter
741bd98 otherMerge pull request #33 from platformbuilders/feature/update-multitenancy-lib
2022-0313000
8b9909e otherAtualizando versão do multitenancy-starter
260ee46 otherMerge pull request #20 from platformbuilders/feature/fix-tenant
3741104 otherMerge pull request #13 from platformbuilders/feature/multi-tenant
2022-027000
3e375a4 otherMerge pull request #11 from platformbuilders/feature/fallback-organization-clien…
5d193a9 otherAlteração na forma de salvar e recuperar caches de OrganizationClientId
1bbf8f8 otherRecuperando infos de clientId e organizationId do banco relacional

+ 1 meses anteriores omitidos.

Password / PIN Management○ Estávelidentity_auth
Cadastro, troca, recuperação de senha. Validação de força, hashing bcrypt/argon2.
20 commits
2021-112026-07
finid.password · 10 meses de atividade · 9 feat · 1 fix · 0 refactor
MêsTotalfeatfixrefactorAmostras (até 5)
2026-071100
b4d2184 feat[sso] reconcile SSO/password identity by email and hard-remove UAP (#193)
2026-061000
8ba3e15 otherMerge pull request #180 from buildersbank/fix/snyk-hardcoded-password-fp
2026-032100
24b021d featadd temporary password generation and status-based flow for account users
b193425 otheradd phone and include password message
2026-021000
4beca9f otherMerge pull request #41 from buildersbank/feature/PJ-614-otp-pin-validation
2025-017700
f3c965c featlibs dependency mapping
2024-082010
dbf127d fixvalid user password
607e37b otherMerge pull request #73 from buildersbank/fix/user-password-validation
2022-051000
92f2d10 otherIncluindo validação de password quando informado
2022-032000
c47bd8f otherCorreção para passagem correta de clientId na validação de PIN
24fa11b otherInserindo log para verificação de erro na autorizacao do PIN
2022-012000
d643a14 otherAdição de endpoint /authenticate para troca de senha de users
1e3b705 otherRetornando o valor do PIN para ser usado na autenticação
2021-111000
3155004 othercriar estrutura para autenticar por assinatura PIN e PASSWORD
Roles & Permissions (RBAC)✓ Maduroadmin
Roles, permissions, scopes. RBAC granular por endpoint.
14 commits
2022-022026-03
finid.permissions · 4 meses de atividade · 2 feat · 0 fix · 0 refactor
MêsTotalfeatfixrefactorAmostras (até 5)
2026-034100
29cf6d1 featadd permissions CRUD - full vertical slice
9ce266c otherfix new scopes on appclient dont need to be add on security service
e582940 otherMerge pull request #118 from buildersbank/feature/PJ-586-PBAC-permissions
2026-011100
3e006fa featadd challenge identifier on auth validation and add SettingsBank to retrieve def…
2022-055000
65c96d8 otherMerge pull request #39 from platformbuilders/feature/add-scopes-to-authenticatio…
5939a13 otherAdicionando mais uma condição no if de scopes para evitar NullPointer
948172e otherIncluindo scopes na autenticação simples para ser usado no backoffice
2022-024000
a49ca94 otherTrocando set de scopes por typeMapConverter
f27987f otherAlterando classes de validação de scopes
40cd7bf otherImplementacao de validação de scopes
Device Validation / Fingerprint✓ Maduroidentity_auth
Identificação e validação de dispositivos confiáveis (fingerprint, device binding).
13 commits
2022-012026-06
finid.device_validation · 6 meses de atividade · 1 feat · 4 fix · 0 refactor
MêsTotalfeatfixrefactorAmostras (até 5)
2026-064020
bab0dab fixfindById com filtro _class explicito (regressao Spring 3) (#183)
034d133 fixrevert bb-redis-starter 3.3.3-SNAPSHOT -> 3.3.2-SNAPSHOT (regressao device-login…
2cdd798 otherRevert "fix(device-login): findById com filtro _class explicito (regressao Sprin…
2025-094010
8c1ead5 fixreturn invalid device if device id not found
5656f91 otherfix device credential conflict validation
272a22a otherEnable multiple devices (#101)
2025-081000
838647c otherMerge pull request #36 from buildersbank/feature/dock-trusted-devices
2025-061100
32789a2 featFind device credentials
2024-082010
c10b0ea fixFixied find identity device credentials
f146642 otherMerge pull request #75 from buildersbank/fix/find-device-identity-credentials
2022-011000
fcd903a otherAjustando mensagem para device inválido
Project / Application○ Estáveladmin
CRUD de projects (clients OAuth). Configuração de redirect_uris, scopes, secrets.
12 commits
2021-102025-10
finid.project · 7 meses de atividade · 1 feat · 0 fix · 0 refactor
MêsTotalfeatfixrefactorAmostras (até 5)
2025-101000
c2d4c88 otherUpdate sonar-project.properties
2024-092100
c893155 featadd find project and application
c6f7882 otherMerge pull request #37 from buildersbank/feature/find-project-application
2023-031000
279dafb otherAjuste em application-env
2022-035000
828202d otherAdicionando payments nos escopos do application.yml
a9a15d8 otherAdicionando cep no jwt_bearer do application.yml
4dd4e3a otherCorreção para credentials do gcp no application.yml
2022-021000
00c2306 otherIncluindo variaveis de ambiente no application-env.yml
2021-121000
806ea85 otherAdição de propriedades em arquivos application-env.yml
2021-101000
bb37959 otheradd application
Embedded Auth (iframe SDK)🆕 Novointegrations
Auth widget embed via iframe + JS SDK para integração nos apps clientes.
6 commits
2026-062026-06
finid.embedded_auth · 1 meses de atividade · 0 feat · 3 fix · 0 refactor
MêsTotalfeatfixrefactorAmostras (até 5)
2026-066030
6e3dbe8 fixempacota AWS SDK auth/sts (runtime) via adapter-data
6c5b9d6 otherMerge pull request #178 from buildersbank/fix/aws-sdk-packaging
bbfbfbc otherMerge pull request #99 from buildersbank/fix/aws-sdk-packaging
OTP (SMS / Email)○ Estávelidentity_auth
One-time password via SMS ou email para confirmação de transação/login.
4 commits
2022-032026-02
finid.otp · 3 meses de atividade · 0 feat · 0 fix · 0 refactor
MêsTotalfeatfixrefactorAmostras (até 5)
2026-021000
2eb24fd otherotp validation in ibk channel
2024-111000
88490a7 otherreturning code to mobile otp api
2022-032000
d133db6 otherAlteração de log do metodo verifyOtpCode
c1946a5 otherMudança nos logs de envio de OTP
JWKS Rotation (public keys)💤 Dormenteidentity_auth
Rotação automática de chaves públicas JWKS para validação de tokens.
1 commits
2022-042022-04
finid.jwks_rotation · 1 meses de atividade · 0 feat · 0 fix · 0 refactor
MêsTotalfeatfixrefactorAmostras (até 5)
2022-041000
e83e9ee otherEndpoint para retornar a public key cadastrada

🔧 Capabilities não funcionais (5)

Dependency Management🔥 Evoluindorelease
Bumps de dependências (Dependabot, deps automation).
94 commits
2025-032026-07
finid.nf.deps · 11 meses de atividade · 0 feat · 0 fix · 0 refactor
MêsTotalfeatfixrefactorAmostras (até 5)
2026-076000
fc856ac choreatualizar versão para 3.0.0 no pom.xml
154051d choreatualizar versão para 3.0.0-rc-2 no pom.xml
7023a71 choreatualizar versão para 3.0.0-rc-1 no pom.xml
2026-0612000
31f8e8c chorebump bb-core-commons para 3.0.4-SNAPSHOT
18a20c6 chorekeep Codewall documentation/config only (#154)
0db6064 docscodewall.md neutro (so contexto CNPJ)
2026-0511000
7d8461b choremerge release into develop
ba01665 choreatualizar versão para 3.0.0-rc-1 no pom.xml
293c57d choreatualizar versão para 3.0.0-rc no pom.xml
2026-035000
144081a docsupdate Postman collection with account user registration and password change flo…
adf555c chorefix sonarqube issues in GenerateTokenAudienceUseCase
9f30792 choresonarqube fixes on legacy files and docs
2026-027000
159f8b7 choreatualizar versão para 1.8.0 no pom.xml
8bc1d1c choreatualizar versão para 1.8.0-rc no pom.xml
6cafb14 choreresolver conflitos mantendo versões locais dos pom.xml
2026-015000
d3ff538 choreatualizar versão para 1.7.2 no pom.xml
ae1bb39 choreatualizar versão para 1.7.2-rc no pom.xml
b2cdcad choreresolver conflitos mantendo versões locais dos pom.xml
2025-1214000
c805eb0 choresetup api definition and springdoc
9fab7fc choreatualizar versão para 1.7.1 no pom.xml
5ef54bc choreatualizar versão para 1.7.1-rc-2 no pom.xml
2025-1016000
8c67668 choreAtualizando pullrequest.yaml
cbe6f6d choreatualizar versão para 1.0.5 no pom.xml
07cf010 choreatualizar versão para 1.0.5-rc no pom.xml
2025-0913000
2538659 choreatualizar versão para 1.6.0 no pom.xml
bb8c28e choreatualizar versão para 1.6.0-rc no pom.xml
9d30ce7 choreatualizar versão para 1.5.7-rc-10 no pom.xml
2025-073000
68b9d1c choreadds corpx
2025-032000
cb075c7 choreupdate Java version to 17 and Spring Boot to 2.7.18 (#76)
0aca06c choreupdate Java version to 17 and Spring Boot to 2.7.18 (#40)
CI/CD Pipeline✓ Madurorelease
Pipeline CI/CD (Jenkins / GitHub Actions), testes automatizados, deploy.
26 commits
2025-092026-06
finid.nf.ci_cd · 6 meses de atividade · 0 feat · 0 fix · 0 refactor
MêsTotalfeatfixrefactorAmostras (até 5)
2026-064000
32de953 choreadiciona .mvn/extensions.xml (artifact-registry wagon)
158285e choreadicionar documentação de contexto (CLAUDE.md, ADR) (#3)
3493a29 testancora fim de regex DOCUMENT + regressao trailing chars (review Codewall)
2026-032000
8a6883d testadd coverage for findAllByUserId and findByAccountId in UserAccountProfileDataAd…
0075090 testimprove coverage for SonarQube - PasswordGenerator, AuthenticateUseCase, Paginat…
2026-021000
0ccde43 choreupdate version to 2.3.0-SNAPSHOT and refactor GitHub workflows to inherit secret…
2026-0112000
0f87f48 chorereplace secrets with inherit
2025-104000
6f02239 choreAdicionando pullrequest.yaml
2025-093000
f068adc choreadd empty line for better readability in ci-cd.yaml
4091719 chorestreamline Git push process in version check workflow
19d58cc choreenhance version check workflow to update pom.xml and create GitHub releases
Multi-tenancy○ Estávelarchitecture
Multi-tenant: tenant_id em todos endpoints, isolação Postgres schema/RLS.
3 commits
2026-042026-04
finid.nf.multi_tenancy · 1 meses de atividade · 0 feat · 0 fix · 0 refactor
MêsTotalfeatfixrefactorAmostras (até 5)
2026-043000
8a80faf chore[PSTI-515] bumping multitenancy dependency version to fix property broken
b687f80 chore[PSTI-515] bumping multitenancy dependency version to fix vulnerability
Starter / SDK Lib🆕 Novoarchitecture
Lib starter para consumidores (Java/TS) integrarem FinID rapidamente.
2 commits
2026-062026-06
finid.nf.starter · 1 meses de atividade · 0 feat · 0 fix · 0 refactor
MêsTotalfeatfixrefactorAmostras (até 5)
2026-062000
3c4a1e6 chorebump bb-redis-starter para 3.3.3-SNAPSHOT
Observability○ Estávelobservability
Logs estruturados + métricas + traces OTel. Auditoria de eventos auth.
1 commits
2026-032026-03
finid.nf.observability · 1 meses de atividade · 0 feat · 0 fix · 1 refactor
MêsTotalfeatfixrefactorAmostras (até 5)
2026-031001
60c1746 refactorreplace NotificationAdapter with Feign + gRPC pattern aligned to fin-bko-authori…

Release Notes (técnicas, derivadas de commits — 426 commits)

Fonte: commits reais dos repos: buildersid-auth
Período: 2021-102026-02 · 41 meses · 23 func + 41 não-func
Critério: conventional_commits: feat/fix → functional; perf/refactor/chore/docs/test/build/ci/style → non_functional; outros ignorados
2026-020 func·4 não-func·8 commits totais

Funcional (0)

    Não funcional (4)

    • 159f8b7choreatualizar versão para 1.8.0 no pom.xml
    • 8bc1d1cchoreatualizar versão para 1.8.0-rc no pom.xml
    • 6cafb14choreresolver conflitos mantendo versões locais dos pom.xml
    • 995fff6choresort challenge by userid
    2026-011 func·8 não-func·12 commits totais

    Funcional (1)

    • 3e006fafeatadd challenge identifier on auth validation and add SettingsBank to retrieve default scopes^\

    Não funcional (8)

    • 0f87f48chore(ci)replace secrets with inherit
    • d3ff538choreatualizar versão para 1.7.2 no pom.xml
    • ae1bb39choreatualizar versão para 1.7.2-rc no pom.xml
    • b2cdcadchoreresolver conflitos mantendo versões locais dos pom.xml
    • cc1fbfbchoreadd duplicate device validation
    • + 3 similares (amostra dedup top 10)
    2025-122 func·9 não-func·27 commits totais

    Funcional (2)

    • 3dece9afeatupgrade multitenancy version
    • 0fb06c7featadding scopes list to user token generation request

    Não funcional (9)

    • c805eb0choresetup api definition and springdoc
    • 9fab7fcchoreatualizar versão para 1.7.1 no pom.xml
    • 5ef54bcchoreatualizar versão para 1.7.1-rc-2 no pom.xml
    • aafe245choreresolver conflitos mantendo versões locais dos pom.xml
    • 6b5076fchoreatualizar versão para 1.7.1-rc no pom.xml
    • 5914f38choreatualizar versão para 1.7.0 no pom.xml
    • f8a0e92choreatualizar versão para 1.7.0-rc no pom.xml
    • + 2 similares (amostra dedup top 10)
    2025-110 func·0 não-func·1 commits totais

    Funcional (0)

      Não funcional (0)

        2025-100 func·2 não-func·3 commits totais

        Funcional (0)

          Não funcional (2)

          • 8c67668choreAtualizando pullrequest.yaml
          • 6f02239choreAdicionando pullrequest.yaml
          2025-098 func·16 não-func·77 commits totais

          Funcional (8)

          • 8c1ead5fixreturn invalid device if device id not found
          • 4c96f1ffixpom.xml
          • 16feeb9fixwrong commit
          • 781f8a1fixintegration user token
          • 9d67d6ffixwrong template name
          • 738ee72fixmissing version
          • c0c85bafixbranch names
          • b077945featRelease Workflow

          Não funcional (16)

          • 2538659choreatualizar versão para 1.6.0 no pom.xml
          • bb8c28echoreatualizar versão para 1.6.0-rc no pom.xml
          • 9d30ce7choreatualizar versão para 1.5.7-rc-10 no pom.xml
          • f068adcchoreadd empty line for better readability in ci-cd.yaml
          • 399bcb5choreupdate version to 1.5.7-rc-8 in pom.xml
          • 78068f8choreatualizar versão para 1.5.7-rc-8 no pom.xml
          • f4211fcchoreatualizar versão para 1.5.7-rc-7 no pom.xml
          • 1204f31choreupdate pom.xml version to 1.5.7-rc-4
          • 40c28e4choreupdate pom.xml to version 2.7.18 and change dependencies to use project properties
          • 6622ec2choreatualizar versão para 1.5.7-rc-4 no pom.xml
          • + 6 similares (amostra dedup top 10)
          2025-081 func·0 não-func·16 commits totais

          Funcional (1)

          • 4ca3d9cfeatupdate pom version

          Não funcional (0)

            2025-070 func·1 não-func·1 commits totais

            Funcional (0)

              Não funcional (1)

              • 68b9d1cchoreadds corpx
              2025-060 func·0 não-func·1 commits totais

              Funcional (0)

                Não funcional (0)

                  2025-050 func·0 não-func·1 commits totais

                  Funcional (0)

                    Não funcional (0)

                      2025-040 func·0 não-func·2 commits totais

                      Funcional (0)

                        Não funcional (0)

                          2025-030 func·1 não-func·4 commits totais

                          Funcional (0)

                            Não funcional (1)

                            • cb075c7choreupdate Java version to 17 and Spring Boot to 2.7.18 (#76)
                            2025-020 func·0 não-func·1 commits totais

                            Funcional (0)

                              Não funcional (0)

                                2025-015 func·0 não-func·5 commits totais

                                Funcional (5)

                                • f3c965cfeatlibs dependency mapping
                                • 3b9a2e6featsonar properties and jacoco/depedency-check rules
                                • 97720d9featcreated catalog-info.yaml
                                • + 2 similares (amostra dedup top 10)

                                Não funcional (0)

                                  2024-101 func·0 não-func·3 commits totais

                                  Funcional (1)

                                  • dac114ffeatremoved datadog and finaya gitops

                                  Não funcional (0)

                                    2024-090 func·0 não-func·3 commits totais

                                    Funcional (0)

                                      Não funcional (0)

                                        2024-082 func·0 não-func·4 commits totais

                                        Funcional (2)

                                        • c10b0eafixFixied find identity device credentials
                                        • dbf127dfixvalid user password

                                        Não funcional (0)

                                          2024-070 func·0 não-func·2 commits totais

                                          Funcional (0)

                                            Não funcional (0)

                                              2024-060 func·0 não-func·5 commits totais

                                              Funcional (0)

                                                Não funcional (0)

                                                  2024-050 func·0 não-func·2 commits totais

                                                  Funcional (0)

                                                    Não funcional (0)

                                                      2024-040 func·0 não-func·2 commits totais

                                                      Funcional (0)

                                                        Não funcional (0)

                                                          2024-030 func·0 não-func·3 commits totais

                                                          Funcional (0)

                                                            Não funcional (0)

                                                              2024-010 func·0 não-func·3 commits totais

                                                              Funcional (0)

                                                                Não funcional (0)

                                                                  2023-123 func·0 não-func·8 commits totais

                                                                  Funcional (3)

                                                                  • 4102987fix:ambulance: Update runs-on value in ci-cd.yaml
                                                                  • 8586cb4feat✨ Add S3 artifact upload to CI/CD workflow
                                                                  • + 1 similares (amostra dedup top 10)

                                                                  Não funcional (0)

                                                                    + 17 meses anteriores omitidos. Acesso ao histórico completo via release_notes.monthly[] ou API.

                                                                    Re-gerar via pnpm --filter @finaya/products-catalog exec tsx scripts/generate-release-notes.ts finid <repo> após `gh api repos/buildersbank/<repo>/commits ... > /tmp/commits/<repo>.txt`.

                                                                    Clientes atuais (9) · INSUMO

                                                                    ⚠️ Dados de cliente são insumos, não fazem parte do produto. Lista atualizada manualmente.

                                                                    assaitorrasaojoaopaguemenospicpaygetnetcrefisacorpxoz_cambio

                                                                    Stack técnica

                                                                    Linguagens
                                                                    Java 17
                                                                    Frameworks
                                                                    Spring BootSpring Security
                                                                    Persistência
                                                                    Postgres
                                                                    Deploy: —

                                                                    Sustentação

                                                                    FTE/ano: 0.3SRE Tier: tier_0On-call: 24x7

                                                                    Last review: 2026-04-28 · Edit: packages/ts/products-catalog/src/products/