Sign-in and access

Sign-in your security team will approve

Your people sign in the way your organization already works — and they never leave your branding to do it.

Email and password, the social accounts they already have, or your own corporate sign-in. Whichever it is, the login page is yours: your domain, your logo, your colors, with no third-party screen in the middle.

What you can control

Every one of these is a setting an administrator changes, not a project.

  • However your people already sign in

    Choose which methods your organization allows, and turn the rest off.

    • Email and password, with a password policy you set
    • Social accounts, enabled individually — Google, GitHub, Microsoft
    • Your corporate sign-in over SAML or OpenID Connect
    • Your directory over LDAP, including Active Directory
    • Require corporate sign-in and disable the alternatives entirely
    • Different organizations can be configured differently
  • A second factor for sign-in

    Add a second step for everyone, or for the people whose access warrants it.

    • Authenticator apps with a one-time code
    • Backup codes for recovery
    • Enforce it across the whole organization rather than person by person
  • Accounts that follow your directory

    People arrive and leave in your directory, and their access here follows automatically.

    • Directory synchronization, so joiners and leavers are handled where you already handle them
    • A synchronization credential you rotate yourself
    • Connect an existing corporate directory
    • Claim your email domains so the right people land in the right organization
  • Password rules your policy requires

    Set the password standard your security policy asks for, and apply it across the organization.

    • Password length, complexity and reuse rules you define
    • Applied organization-wide rather than person by person
    • Sessions you can end centrally
  • Short sessions, revocable immediately

    Access is short-lived by default, and a session you end stops working rather than expiring in its own time.

    • Short-lived access, refreshed quietly in the background
    • End one session or all of a person’s sessions
    • Revocation fails closed — if it cannot be checked, access is refused rather than allowed
    • Sign-in, sign-out, password reset and permission changes all land in the audit trail
  • Your sign-in page, on your domain

    The whole sign-in experience carries your brand, including the page itself.

    • Your logo, favicon and colors
    • Your own domain, with certificates handled for you
    • Your users never see a third-party login screen

Built on the standards you already require

Nothing proprietary in the way of your existing identity infrastructure.

OpenID Connect
Authorization code flow with proof key exchange
OAuth 2.0
Signed, verifiable tokens with published verification keys
SAML 2.0
For corporate sign-in that speaks SAML
LDAP
For sign-in against Active Directory or another LDAP directory
SCIM 2.0
For directory synchronization of people and groups

Review the wider security and deployment boundary →

Bring it to your security review

If your reviewers have a checklist, send it over — we would rather answer it before you commit than after.