keystone · runs in your browser

The stack, wired

Sign in, pick a tenant, meter some usage, then ask the member about the bill. Identity gates it, tenancy isolates it, billing prices it to the exact minor unit and posts a balanced ledger, and the member reads the same state. The four kits over one executor. It is a faithful simulation; nothing here touches a database.

identity-kit
tenant-kit
billing-kit
ai-member
identity-kitsession active
Y
account id · usr_9f2a…
tenant-kitrow-level isolation
billing-kitmeter → price → post
acme · invoice
$0.00
0API call
0Storage GB
0Seat

No events yet: meter one to see the ledger post.

Scoped to acme. globex owes $0.00. A separate ledger you can’t see from here.

ai-membergrounded in the live state
0
kits composed into one app: identity, tenancy, billing, memory
0
tenants sharing one browser tab, isolated down to every posting
0×
ledger entries per charge: debit and credit, or it does not post
0
databases touched. A faithful simulation of the real kits, in your browser
What to try

Four moves, one per kit

01
identity-kit
Sign out, then try to meter

The fire button gates the moment the session drops. Identity is not a login form on the side. Every other kit refuses to move without a subject.

02
tenant-kit
Switch tenants mid-stream

Meter usage as Acme, flip to Globex, and watch the invoice, usage counters and ledger swap wholesale. Two tenants, one tab, zero bleed.

03
billing-kit
Fire an event, then replay it

Replay sends the same idempotency key again. The duplicate is caught, shown dashed in the ledger, and the total does not move: exact Money, balanced postings, no double charge.

04
ai-member
Ask the member about the bill

The member answers from the same tenant-scoped state the ledger shows: grounded in what actually posted, not a summary that can drift from the money.

This wiring ships as a real app

keystone is the same four kits composed into a CRM you can run today. Open-source core, managed Cloud, native mobile.