SPIFFE Websitea case study
← Scytale — the whole project
Conversion UX & web design · HPE / Scytale

The SPIFFE
front door

A homepage that answered “what is this and why do I care” before the visitor left.

SPIFFE and SPIRE are the open-source Zero-Trust identity frameworks Scytale was built on — and the adoption research had found exactly where new visitors bounced. This is where that research cashed out first: a rebuild of the SPIFFE.io / SPIRE web experience, the literal front door of the whole project.

↓ 7% bounce rate↑ 12% conversionsA/B validated
spiffe.io — the redesign
SPIREspiffeDocumentationCommunityLearnDownloadGet SPIRE

Secure identity for every workload.

SPIFFE gives every workload a cryptographic identity. SPIRE is the runtime that issues and rotates it — across any platform, no shared secrets.

New to SPIFFE?
Understand the standard and why it matters.
What is SPIFFE? →
Ready to deploy?
Run SPIRE, the production identity runtime.
Get started with SPIRE →

What is SPIFFE?

SPIFFE, the Secure Production Identity Framework For Everyone, provides a secure identity in the form of a specially crafted X.509 certificate to every workload in a modern production environment. It removes the need for application-level authentication and complex network-level ACL configuration.

Learn More

Who Uses SPIFFE?

SPIFFE is currently used by a variety of projects that both issue and consume SPIFFE IDs.

Issuers
IIstio Citadel
KKuma
SThe SPIRE project
HHashiCorp Consul
Consumers
EThe Envoy proxy
GThe Ghostunnel proxy
PPinterest Knox

What is SPIRE?

SPIRE, the SPIFFE Runtime Environment, is an extensible system that implements the principles embodied in the SPIFFE standards. SPIRE manages platform and workload attestation, provides an API for controlling attestation policies, and coordinates certificate issuance and rotation.

Learn More

Who uses SPIRE?

What do we integrate with?

Learn the basics of SPIFFE and SPIRE in just 10 minutes.

☁ CLOUD NATIVE COMPUTING FOUNDATIONspiffeSPIFFE · SPIRE — CNCF Incubating
SPIRE Links
Get SPIRE
Documentation
Concepts
Try SPIRE
Community
Slack
GitHub
Contribute
Events
SPIFFE Links
What is SPIFFE?
SPIFFE ID
SVID
Specifications
Conversion UXWeb designInformation architectureA/B testingOpen-source communityHPE · Scytale
01Where this comes from

Built on a mapped journey, not a hunch.

This redesign didn’t start with a moodboard. It started with the adoption research — a nine-step journey that named exactly where and why people fell off. The front door was the first, highest-leverage place to act on it: the Onlooker phase, where passive interest either turned into evaluation or quietly evaporated.

The research that told us where to aim — the engine, the journey map, and the personas:

Read the Adoption Research
BEFOREThe old front door

The old site was documentation wearing a website’s clothes.

A new visitor couldn’t answer “what is this and why do I care” fast enough, so they left before the value ever landed. The page led with mechanism, not meaning.

And SPIRE — the runtime you actually deploy — was badly under-represented next to SPIFFE.
spiffe.io — the old front door
spiffeGet SPIREDocumentationM BlogtS
New! SPIFFE and SPIRE are now graduate projects of the Cloud Native Computing Foundation

Universal identity control plane for distributed systems

SPIFFE and SPIRE provide strongly attested, cryptographic identities to workloads across a wide variety of platforms.

Get startedDownload
Used By
amazonAnthem.armBloombergCISCODUKE ENERGYGoogleHashiCorp

Overview

SPIFFE and SPIRE provide a uniform identity control plane across modern and heterogeneous infrastructure. Since software is increasingly built from workloads that are dynamically scheduled across a fleet of machines, identity is the foundation of secure communication.

spiffe.io — the redesign
SPIREspiffeDocumentationCommunityLearnDownloadGet SPIRE

Secure identity for every workload.

SPIFFE gives every workload a cryptographic identity. SPIRE is the runtime that issues and rotates it — across any platform, no shared secrets.

New to SPIFFE?
Understand the standard and why it matters.
What is SPIFFE? →
Ready to deploy?
Run SPIRE, the production identity runtime.
Get started with SPIRE →

What is SPIFFE?

SPIFFE, the Secure Production Identity Framework For Everyone, provides a secure identity in the form of a specially crafted X.509 certificate to every workload in a modern production environment. It removes the need for application-level authentication and complex network-level ACL configuration.

Learn More

Who Uses SPIFFE?

SPIFFE is currently used by a variety of projects that both issue and consume SPIFFE IDs.

Issuers
IIstio Citadel
KKuma
SThe SPIRE project
HHashiCorp Consul
Consumers
EThe Envoy proxy
GThe Ghostunnel proxy
PPinterest Knox

What is SPIRE?

SPIRE, the SPIFFE Runtime Environment, is an extensible system that implements the principles embodied in the SPIFFE standards. SPIRE manages platform and workload attestation, provides an API for controlling attestation policies, and coordinates certificate issuance and rotation.

Learn More

Who uses SPIRE?

What do we integrate with?

Learn the basics of SPIFFE and SPIRE in just 10 minutes.

☁ CLOUD NATIVE COMPUTING FOUNDATIONspiffeSPIFFE · SPIRE — CNCF Incubating
SPIRE Links
Get SPIRE
Documentation
Concepts
Try SPIRE
Community
Slack
GitHub
Contribute
Events
SPIFFE Links
What is SPIFFE?
SPIFFE ID
SVID
Specifications
AFTERReshaping the front door

Built around what a new visitor needs.

Concrete objectives, with a bounce rate under 50% as the internal target:

01 A real hero section

One-liner + strong graphic + CTAs to Learn, Download, Join.

02 Audience-split navigation

SPIFFE · SPIRE · Docs · Download · Community · Learn.

03 SPIRE its own stage

Dedicated hero, use cases, end-user & integration logos.

04 Community as a front door

Clear paths to GitHub, Slack, Google Groups, events.

05 Docs restructured

In the spirit of Open Policy Agent — so evaluation didn’t stall.

Validated with A/B testingon bounce & time on page.

Results

Movement at both ends of the funnel.

Bounce rate
↓ 7%

Fewer people hit the front door and left without understanding what the frameworks could do.

Download & community conversions
↑ 12%

More of the people who stayed took the actions that actually begin adoption.

Why it worked

Because the changes weren’t cosmetic — every move traced back to a specific place the research had shown people falling off. The front door stopped being a wall of documentation and started being an answer to the visitor’s first question.

Where it landed

A front door that finally answered the first question.

This is the web-design half of the Scytale story — the public face of the open-source foundation the whole platform was built on. The research told us where to aim; the redesign moved the numbers; and the same frameworks became the engine inside the Scytale Enterprise product.