All platforms¶
Every platform's role, layer and source repository in one place. Before going deeper, this page answers what exists for what purpose.
By layer¶
-
Layer 1 — Identity / PKI
eID Mongolia — the national eID platform. Threshold ECDSA, dual certificates, CA · OCSP · TSA, iOS/Android/desktop SDKs.
-
Layer 2 — Identity / SSO
Gerege SSO — OIDC provider and eID proxy. DAN Gateway · G-Sign · Gerege Verify.
-
Layer 3 — Platform foundation
Gerege Nexus — modular monolith, app store, 8 modules.
Gerege Template Platform — the foundation for building services. Gerege Platform — extended, an IdP itself.
-
Layer 4 — Vertical products
Developer Portal · Gerege App · Gerege POS · Gerege Wallet · Gerege Kiosk · Ring · Khurdan (government line).
-
Layer 0 — Data exchange
X-Road Mongolia — instance
MN, central server and security servers.
At a glance¶
| Platform | Role | Layer | Repo | Status |
|---|---|---|---|---|
| eID Mongolia | Identity, signing, PKI | 1 | eid-platform-mn |
Production |
| Gerege SSO | OIDC provider, eID proxy | 2 | sso-gerege-mn |
Production |
| DAN Gateway | DAN identity gateway | 2 | sso-gerege-mn |
Production |
| G-Sign | Signing gateway | 2 | sso-gerege-mn |
Production |
| Gerege Verify | Company / state registry lookups | 2 | sso-gerege-mn |
Production |
| Gerege Nexus | Modular platform, app store | 3 | open-gerege-nexus |
Production |
| Gerege Template | Foundation for building services | 3 | template-gerege-mn |
Production |
| Gerege Platform | Extended platform, IdP | 3 | gerege-platform-mn |
Production |
| Developer Portal | API catalogue, app-registration gateway | 4 | developer-gerege-mn |
Production |
| Gerege POS | Point-of-sale identity and signing | 4 | gerege-pos-mn |
Production |
| Gerege Wallet | Citizen digital wallet | 4 | wallet-gerege-mn |
Partial |
| Gerege Kiosk | Self-service terminal platform | 4 | gerege-kiosk-mn |
Production |
| X-Road Mongolia | Data exchange | 0 | xroad-mn |
Partial |
| Government line | SSO · Template · Ring · Khurdan | 2–4 | *-dgov-mn |
Production |
Repository access
Several of the repositories above are private. If you need access, contact the Gerege Systems platform team.
Boundary rules¶
Three rules keep responsibilities from overlapping between platforms:
1. Credentials live only in SSO. OAuth clients and client secrets are created only in SSO and stored only there. Even the Developer Portal does NOT create clients and never sees a secret — it explains what to prepare and deep-links into the SSO console.
2. Never call eID directly. Layer 3–4 applications do not reach eID. Permitted eID services are relayed through SSO's eID proxy.
3. One responsibility = one platform. When two platforms start doing the same job, one is merged into the other. Historical examples: the separate eID repositories became a single monorepo, and first-party OIDC code replaced Ory Hydra.
Which one do I need?¶
| If you… | Start here |
|---|---|
| Are building an app that must sign citizens in | Gerege SSO |
| Need legally binding signatures on PDFs | G-Sign · eID Mongolia |
| Need to verify organisation details | Gerege Verify |
| Are standing up a whole new service | Gerege Template Platform |
| Want an organisation's operations unified on one platform, as modules | Gerege Nexus |
| Want to browse the available APIs | Developer Portal |
| Need to identify a customer at the counter and have them sign | Gerege POS |
| Need to exchange data between organisations | X-Road Mongolia |
| Want eID sign-in inside your mobile app | eID Mongolia — SDKs |
| Need to deliver services to citizens through self-service terminals | Gerege Kiosk |