Worca, without the server.
We run Worca for you. Each instance gets its own host under worca.run, your team signs in once, and you decide who gets in and when it upgrades. Everything runs in the EU.
What you get
Your own Worca,
on its own host.
Each instance is a full Worca with its own key service and storage, reached at a random hostname under worca.run. Instances never share a network or a tunnel, and they live on a different domain from the sign-in.
Sign in once,
open every instance.
Everyone signs in at app.worca.dev, and every instance checks with it before letting anyone in. There are no passwords anywhere.
Ways to sign in
- ⚿Your rules for your orgChoose which sign-in methods members may use, and require an email domain: "only @acme.com, only through our SSO".
- ⛨Stricter per instanceAn instance can only narrow the org's rules, for example "this one requires SSO".
- ✓SSO on a domain you proveConnect your identity provider for an email domain your org has verified with a DNS record.
Access through teams,
nothing else.
Tenant admins invite people by email, put them in teams, and assign teams to instances. Someone gets into an instance only if one of their teams is assigned to it.
From an invite to an open instance
- A tenant admin invites you by emailYou sign up or sign in, and join the org.
- You're put in one or more teamsA person can be in several teams, and several orgs.
- Teams are assigned to instancesOne or more teams per instance.
- You open the instanceIt checks your sign-in and your teams before every request reaches Worca.
- ⊘Removing someone takes effect at onceTake a person out of a team or the org and every change they try is refused at once; reading stops within a minute.
- ▤An audit log you can readEvery operation, ours and yours, is recorded. Tenant admins see their org's log, kept for 30 days.
- ⚇Our staff can't get inNo platform role opens a tenant's instance. We see whether it's running, its Worca version and pipeline counts, not your work.
Encrypted with your key,
kept in the EU.
Tenant data in the control plane is encrypted in the application, with one key per org and one per user. Delete an org or an account and its key goes with it, so its data can't be read again, backups included.
Open by invite code,
for now.
Hosted Worca opens gradually. Signing up starts with an invite code; next comes a waitlist that anyone can join, where a valid code skips the wait.
- Get an invite codeCodes come from us while registration is invite-only.
- Sign up at app.worca.devVerify your email, enter the code, and your account is active.
- Create your org and an instanceThen invite your team and assign them to it.
Already invited to an org? Sign in with the email address the invite went to.
Rather run it on your own servers? Worca is open source under MIT, and runs on any container host behind your own sign-in.