What you can control
Every one of these is a setting an administrator changes, not a project.
However your people already sign in
Choose which methods your organization allows, and turn the rest off.
- Email and password, with a password policy you set
- Social accounts, enabled individually — Google, GitHub, Microsoft
- Your corporate sign-in over SAML or OpenID Connect
- Your directory over LDAP, including Active Directory
- Require corporate sign-in and disable the alternatives entirely
- Different organizations can be configured differently
A second factor for sign-in
Add a second step for everyone, or for the people whose access warrants it.
- Authenticator apps with a one-time code
- Backup codes for recovery
- Enforce it across the whole organization rather than person by person
Accounts that follow your directory
People arrive and leave in your directory, and their access here follows automatically.
- Directory synchronization, so joiners and leavers are handled where you already handle them
- A synchronization credential you rotate yourself
- Connect an existing corporate directory
- Claim your email domains so the right people land in the right organization
Password rules your policy requires
Set the password standard your security policy asks for, and apply it across the organization.
- Password length, complexity and reuse rules you define
- Applied organization-wide rather than person by person
- Sessions you can end centrally
Short sessions, revocable immediately
Access is short-lived by default, and a session you end stops working rather than expiring in its own time.
- Short-lived access, refreshed quietly in the background
- End one session or all of a person’s sessions
- Revocation fails closed — if it cannot be checked, access is refused rather than allowed
- Sign-in, sign-out, password reset and permission changes all land in the audit trail
Your sign-in page, on your domain
The whole sign-in experience carries your brand, including the page itself.
- Your logo, favicon and colors
- Your own domain, with certificates handled for you
- Your users never see a third-party login screen
Built on the standards you already require
Nothing proprietary in the way of your existing identity infrastructure.
- OpenID Connect
- Authorization code flow with proof key exchange
- OAuth 2.0
- Signed, verifiable tokens with published verification keys
- SAML 2.0
- For corporate sign-in that speaks SAML
- LDAP
- For sign-in against Active Directory or another LDAP directory
- SCIM 2.0
- For directory synchronization of people and groups
Bring it to your security review
If your reviewers have a checklist, send it over — we would rather answer it before you commit than after.