Good morning·Tue, Sep 22·8:45 AM
ReaderBrands
Editorial
Digital Literacy

Understanding Cross-Brand Authentication

Single sign-on across independent brands is technically complex and raises real privacy questions. Here is how the Boston Made Passport system works and what it means for you.

August 11, 20266 min readDigital Literacy
Boston Made branded pattern representing the ecosystem identity and cross-brand connectivity

When you create an account on the Boston Made App, you are creating an identity within the Boston Made ecosystem. The Boston Made Passport is the system that lets you use that identity on participating partner sites without creating separate accounts on each one.

The technical mechanism is an authorization code flow. When you visit a participating partner site and choose to connect your Boston Made identity, the partner site redirects you to the App. You authenticate here, and the App issues a short-lived, single-use code. The partner site exchanges that code for your identity information — your name, email, and membership status — and creates a local session for you.

A few things are worth understanding about how this is designed. The code is single-use: once it is exchanged, it cannot be used again. It expires in sixty seconds. It is bound to the specific partner site that requested it — a code issued for one site cannot be used by a different site. These constraints are not incidental; they are the security model.

What information does the partner site receive? Your name, your email address, and whether you have an active Boston Made+ membership. It does not receive your password, your payment information, or any information about other sites you have connected to. Each connection is independent.

The participating sites are a defined list: bostonmade.org, bostonmade.io, bostonmade.net, pupwear.org, paxton.digital, and kingswellstrategicventures.com. Sites outside this list — including BOSSTOX, Beacon Federal Partners, and Lumo — are explicitly excluded from the Passport system. This is a deliberate boundary, not an oversight.

You can see which sites you have connected to from your account page. Connecting to a site is opt-in and happens only when you actively initiate it. The App does not automatically share your identity with partner sites when you visit them.

Cross-brand authentication is a convenience feature, not a requirement. You can use any participating brand's site without connecting your Boston Made identity. The Passport system exists for users who want a unified experience across the ecosystem.

The security model underlying cross-brand authentication is worth understanding at a basic level. When you use your Boston Made account to authenticate on a participating site, the hub issues a short-lived, single-use code that the participating site exchanges for your identity. This code expires quickly and cannot be reused, which means that even if it were intercepted in transit, it would be useless to an attacker by the time they tried to use it. This is a standard pattern in modern authentication systems, and it is significantly more secure than sharing passwords across sites.

Editorial note: This article is digital literacy content — analysis, perspective, or practical guidance. It is not reported news and does not contain fabricated events, interviews, statistics, or verified business achievements. For reported news and wires, visit the Boston Made Newsroom.

Related Digital Literacy