Keine Katze im Sack. Don't buy the cat in the sack. Pig in a poke, for the English. Either way - you open the bag before you hand anything over.

That is roughly the philosophy behind this entire website.

Old Forge isn't a brochure. It isn't a portfolio reel dressed up as a site. Every visible surface is a working thing, built the way I'd build it for you. The chat widget in the bottom-right corner isn't a gimmick - it's a live n8n workflow routing through Azure GPT‑4.1 with Redis-backed memory and an MCP tool layer, the same plumbing I'd stand up for your team's internal assistant. The sign-in button on the masthead runs full OIDC with PKCE against a self-hosted Keycloak at id.oldforge.tech. The letterpress typography was set, spaced and italicised by hand. None of it is decoration.

From today there is one more piece you can touch.

The first tile

Sign in, open your account page, and you'll see the Applications panel has stopped making promises. It has a tile in it: Fenrir. One click - new tab, no fresh login prompt, no "authenticate with provider" dance - and you're in the Fenrir dashboard. The Keycloak session you minted on oldforge.tech was the Keycloak session Fenrir needed. The browser follows a redirect, Fenrir trades a code for tokens against the same realm, and you land on the other side already signed in.

This is what nahtlos - seamless, done properly - is supposed to mean, rather than marketing shorthand for an animated gradient.

Fenrir isn't a demo

I want to be precise about this, because it matters.

Fenrir is a real product. It's an OWASP ZAP-based vulnerability scanning portal with OSINT collection, AI-enriched findings, multi-tenant isolation and a fourteen-day free trial that kicks in the first time you come through the door. It's the engine I use on my own security engagements. When you click that tile you aren't stepping into a sandbox of staged vulnerabilities against a dummy target - you're sitting in front of the same instance I'd use to run a scan for a client, with the same scanning queue, the same ZAP contexts, the same CVE lookup, the same reports.

That is deliberate. A showcase that keeps its sharpest tools behind a "contact sales" wall isn't a showcase - it's a billboard.

More doors coming

Fenrir is the first tile. It won't be the last.

Next through is Wegweiser, the artificially intelligent analysis platform I've been building for managed service providers - tenants, organisations, device health, the lot. That integration is designed and signed off: Soft federation rather than a forced migration, invite-only access via a realm role, and the same passthrough experience from this account page once an MSP is in. After Wegweiser, a small queue of other tools waits its turn. Each earns its tile one at a time.

The pattern is the same as today's. One identity at id.oldforge.tech. Each product is a Keycloak client in the same realm. Your /account page reads your realm roles from the access token and decides which doors to show you. Boring by design - the standard OIDC flow, nothing homemade, nothing proprietary, nothing you couldn't lift straight out of a Keycloak handbook.

If any of this sounds useful

If you're an existing client and you'd like the Fenrir tile to appear on your account, drop me a line.

If you're thinking of commissioning something similar - a federated identity layer, a small portfolio of apps sitting behind one front door, an AI-augmented admin surface stitched together from parts that don't normally talk to each other - I'd rather show you how it works here than quote you from a deck. Book a slot, or just poke around the site for ten minutes.

No cat, no sack. Just a workshop with the lights on.