Point a lens at any web page.
Map its identity migration surface.
Moving off hand-rolled, DIY authentication onto a managed identity provider? This reads every login link, session cookie, and identity request on a running page — and tells you, per surface, what it does today and what it becomes once it's managed. A run is a survey: a live-annotated overlay plus map editions you can hand to the team.
It reports; it does not sell. Runs on your own Ollama — nothing leaves your network.
- 1 Sign-in link redirects to /login form → hosted login page
- 2 session cookie httpOnly · rolling session → provider session + refresh
- 3 /api/me reads x-profile-id header → ID token claims
Capture, classify, serve.
Capture
A headless browser loads the page and records only what touches identity — identity-bearing requests, cookies with their flags, interactive elements. Header values are never stored; they are live credentials.
Classify
A local model maps each surface onto the migration vocabulary: what it reads today, what a managed identity provider must provide instead. It runs on your own Ollama endpoint — nothing about the target leaves your network.
Serve
The page returns with a numbered overlay pinning every surface in place, plus three downloadable map editions — Markdown, PDF, and HTML.
The surface bar
Every survey reduces to one reading: how much of the page's identity surface is already wired, how much is still to migrate, and how much is still unknown. Amber marks only the work — everything settled stays quiet.
Take the map with you.
Every survey exports the same map three ways — a Markdown brief for the ticket, a PDF for the review, an interactive HTML overlay for the walkthrough.
Run your first survey.
Sign in with your unfuck.cloud account, point the lens at a URL, and read the map.
Sign in with unfuck.cloud