Skip to main content

ROC 2.0 Documentation

Unified authentication, authorization, and user management platform powering ResMed enterprise applications.

GraphQL + REST
Dual API Surface
SAML 2.0
Okta SSO
RBAC
Role-Based Access
No Local Setup
Hosted Platform

How ROC Works

Application
ROC Login
Session
GraphQL me
Access Decision

Your app redirects to ROC for login. After authentication, ROC sets a session. Your app calls the GraphQL me query to get user identity and roles, then makes an access decision.

Choose Your Path

🖥️

For Frontend / App Teams

Redirect-based login, session handling, route protection, and React / Next.js integration guides.

Frontend Guide
⚙️

For Backend / Service Teams

API-key auth, service account setup, GraphQL queries, and service-to-service integration patterns.

Integration Guide

⏱ 30–60 Minute Onboarding

Standard integrations can be onboarded in 30–60 minutes. Follow the Quick Start to connect via frontend redirect-based auth or backend API keys.

Start Onboarding

Common Tasks

🚀Onboard a frontend app🔧Onboard a backend service📡Test the me query🔑Configure environment variables🔐View authentication flow📖Open API reference

Start Here

🚀

Getting Started

Platform overview, quick start, auth flow, and environment configuration.

🖥️

Frontend Integration

Redirect-based auth, session handling, route protection, and Next.js examples.

⚙️

Integration Guide

Full-service and backend API integration, environment variables, service accounts.

📡

API Reference

GraphQL queries, authentication headers, and the live Playground.

🔑

Access Models

Invite-based and approval-based access flows for user onboarding.

🛡️

Security

MFA, token lifecycle, rate limiting, audit logging, and troubleshooting.

🏗️

Platform

Architecture, SLOs and observability, and cost model.

Production SLOs and observability metrics available in Platform → SLOs & Observability.