Last updated 2026-09-01.
K is an identity service. It answers whether somebody is the person who was here before, and
signs the answer. This page covers the deployment at k.kbsoap.com. If you arrived
here from an app's sign-in screen, the policy you want is that app's own — K is what it is built
on, not who you have an account with.
One K deployment serves several tenants, and a tenant is a separate operator with its own signing key, its own applications and its own accounts. Nothing crosses between them. The tenant whose app you signed into is responsible for your account and is who to ask about it; K holds the records on that tenant's behalf. Zaparo's own tenant is Zaparo ID.
By design, not by policy: application data never enters. Scores, lists, rooms, messages and files stay with the application that holds them. K does not derive location from a network address, stores no advertising identifier, and has no password to store.
Default-deny. An application receives an account identifier and whether the account has ever signed in. Every other field is absent from its tokens until the person releases it to that application, and absent again within ten minutes of withdrawal.
An account deletion removes the account row and everything that hangs off it — sessions, device bindings, linked sign-in methods and the identifiers in them, provider-reported fields, consent and its history, and supersession statements naming the account on either side. No closed record is kept. Signing in afterwards with the same identifier produces a new account.
Accounts are kept until deleted. Sign-in flows expire in minutes and are discarded. Refresh token hashes are kept while the token could still be presented. Proof identifiers are kept only for the replay window.