One platform · every access point
One identity for
your whole stack.
App, cloud, server, network, and AI agents — authenticated by one platform. Passkeys-first, keyless everywhere, enforced down to the kernel with eBPF, and fully white-label. Plans gate by scale, not by feature.
Free for 5,000 users · No credit card · Live in 5 minutes
Identity
Identity.
Passwordless auth, enterprise SSO, and a directory that syncs both ways.
Authentication
Passkeys/WebAuthn first. Magic link, OTP, social, password, TOTP MFA. PKCE, token rotation, breached-password check.
Learn more →Enterprise SSO
SAML 2.0 (SP + IdP), OIDC, LDAP/AD bridge. Domain routing. JIT provisioning. Works with Okta, Entra ID, Google.
Learn more →Directory & RBAC
Users → Groups → Roles → Permissions. SCIM inbound + outbound. Real-time sync from Entra ID, Okta, Workspace.
Learn more →Access
Access.
One login for every cloud, server, and network — keyless, all the way to the kernel.
eBPF zero-code auth
Kernel enforcement at ~45μs. WireGuard mesh, service discovery, legacy-app protection. One DaemonSet, no code changes.
Learn more →Cloud access
One login federates to AWS, GCP, Azure, OCI. Group→role mapping, console SSO, temporary credentials. Zero stored keys.
Learn more →Server access (PAM)
Zero-key SSH with short-lived certs. MFA on every login, role-based sudo, JIT elevation, full audit trail.
Learn more →Agents
Agents.
AI agents are identities — scoped, revocable, and audited like any other.
Agent identity
AI agents as first-class identities via MCP. Per-agent registry, scoped delegation, instant revoke.
Learn more →MCP gateway
Model Context Protocol tool catalog. Per-call capability gating enforced by the kernel BPF agent.
Learn more →Human-in-the-loop
Destructive tool calls pause for approval. Decide in the portal or via a magic-link email.
Learn more →Detection
Detection.
Risk scoring and a tamper-evident decision log running across every layer.
ML signals
Per-tenant models. Isolation Forest for anomalies, k-means for behavior — runs in your own binary.
Learn more →Trust score
Weighted across factors, recomputed on every login. Adaptive MFA elevation when risk spikes.
Learn more →Decision tape
Merkle-chained transparency log. Every decision auditable and chain-verifiable offline by your auditor.
Learn more →Branding
Branding.
Fully white-label — your domain, your TLS, zero AuthFI fingerprints.
Custom domain
Your domain, your TLS, auto-managed certs. SAML metadata, OIDC discovery, JWKS — all served from your origin.
Learn more →Theme + templates
Logo, colors, fonts, custom CSS. Branded email + SMS templates. Per-org branding for B2B sub-tenants.
Learn more →Secured by you
No AuthFI branding on Pro+. The login feels like your product; the receipts read like your audit.
Learn more →Developers
Developers.
Three lines of code, seven languages, identity as code.
SDKs
Seven languages. One-line middleware. Permissions auto-sync from your code to the console on startup.
Learn more →Terraform provider (coming soon)
Identity as code. Manage users, roles, SSO, and policies in HCL. GitOps your entire auth layer.
Learn more →Webhooks + SIEM
Real-time event dispatch. CSV / JSON / OpenTelemetry export. Stream every decision into Splunk or Datadog.
Learn more →Platform
Platform.
One control plane, one audit trail, global by default.
Global infrastructure
4 data-residency regions + global edge via Cloudflare, zero-downtime deploys, automatic failover, up to 99.99% SLA.
Learn more →Control plane
One dashboard for every capability. One audit trail. One place to revoke access — everywhere.
Learn more →Built for compliance
Built for SOC 2 and HIPAA workflows. Unified, exportable audit timeline across app, cloud, server, and AI.
Learn more →One platform. Every access point.
Start free for 5,000 users — passkeys, SSO, and keyless access live in five minutes.