News 24 April 2026 4 min read The workshop is live By Old Forge Technologies 101 reads Contents **Keine Katze im Sack.** Don't buy the cat in the sack. Pig in a poke, for the English. Either way - you open the bag before you hand anything over. That is roughly the philosophy behind this entire website. Old Forge isn't a brochure. It isn't a portfolio reel dressed up as a site. Every visible surface is a working thing, built the way I'd build it for you. The chat widget in the bottom-right corner isn't a gimmick - it's a live n8n workflow routing through Azure GPT‑4.1 with Redis-backed memory and an MCP tool layer, the same plumbing I'd stand up for your team's internal assistant. The sign-in button on the masthead runs full OIDC with PKCE against a self-hosted Keycloak at `id.oldforge.tech`. The letterpress typography was set, spaced and italicised by hand. None of it is decoration. From today there is one more piece you can touch. ## The first tile Sign in, open your account page, and you'll see the **Applications** panel has stopped making promises. It has a tile in it: **Fenrir**. One click - new tab, no fresh login prompt, no "authenticate with provider" dance - and you're in the Fenrir dashboard. The Keycloak session you minted on oldforge.tech was the Keycloak session Fenrir needed. The browser follows a redirect, Fenrir trades a code for tokens against the same realm, and you land on the other side already signed in. This is what *nahtlos* - seamless, done properly - is supposed to mean, rather than marketing shorthand for an animated gradient. ## Fenrir isn't a demo I want to be precise about this, because it matters. Fenrir is a real product. It's an OWASP ZAP-based vulnerability scanning portal with OSINT collection, AI-enriched findings, multi-tenant isolation and a fourteen-day free trial that kicks in the first time you come through the door. It's the engine I use on my own security engagements. When you click that tile you aren't stepping into a sandbox of staged vulnerabilities against a dummy target - you're sitting in front of the same instance I'd use to run a scan for a client, with the same scanning queue, the same ZAP contexts, the same CVE lookup, the same reports. That is deliberate. A showcase that keeps its sharpest tools behind a "contact sales" wall isn't a showcase - it's a billboard. ## More doors coming Fenrir is the first tile. It won't be the last. Next through is **Wegweiser**, the artificially intelligent analysis platform I've been building for managed service providers - tenants, organisations, device health, the lot. That integration is designed and signed off: Soft federation rather than a forced migration, invite-only access via a realm role, and the same passthrough experience from this account page once an MSP is in. After Wegweiser, a small queue of other tools waits its turn. Each earns its tile one at a time. The pattern is the same as today's. One identity at `id.oldforge.tech`. Each product is a Keycloak client in the same realm. Your `/account` page reads your realm roles from the access token and decides which doors to show you. Boring by design - the standard OIDC flow, nothing homemade, nothing proprietary, nothing you couldn't lift straight out of a Keycloak handbook. ## If any of this sounds useful If you're an existing client and you'd like the Fenrir tile to appear on your account, drop me a line. If you're thinking of commissioning something similar - a federated identity layer, a small portfolio of apps sitting behind one front door, an AI-augmented admin surface stitched together from parts that don't normally talk to each other - I'd rather show you how it works here than quote you from a deck. Book a slot, or just poke around the site for ten minutes. No cat, no sack. Just a workshop with the lights on.