Hosted login
Password, magic link, passkey, TOTP, recovery-code, and session-cookie flows for application sign-in — hosted and maintained so you don't have to.
Identity infrastructure for B2B SaaS
Tenant-aware login, OIDC, and RBAC for B2B SaaS teams — hosted, standards-based, and migratable off Cognito. Your users and data stay portable, so you're never locked in.
Built to pass your security review.
Platform
Organizations, environments, sessions, authorization checks, and audit evidence are first-class — because B2B auth is more than a login box.
Password, magic link, passkey, TOTP, recovery-code, and session-cookie flows for application sign-in — hosted and maintained so you don't have to.
Environment-scoped issuers, discovery, JWKS, authorization code with PKCE, token exchange, userinfo, revoke, and logout endpoints.
Organizations, environments, memberships, roles, permissions, authorization checks, and session revocation as first-class product concepts.
Security-sensitive actions and privileged admin changes leave durable, queryable event trails you can hand to your auditors.
Security & compliance
We run the infrastructure so your team doesn't — with the encryption, data controls, and audit evidence your customers' security questionnaires ask for. Hosted, but never locked in.
TLS on every connection and encrypted storage for user, session, and secret data.
Durable, queryable event trails that support your SOC 2 and ISO 27001 controls.
EU-aware data handling, with a data-processing agreement available for production.
Pull users, OAuth clients, memberships, and roles on demand, over open standards.
Runs on AWS, pinned to a single account and region you choose.
Organizations and environments keep one customer's data separate from another's.
Migration
Our first migration path targets SaaS teams already on Cognito user pools that want tenant-aware auth, clearer operator controls, and a product surface they can grow into — without a big-bang rewrite.
Validate user exports, OAuth clients, membership mapping, and redirect URIs.
Test hosted login, OIDC discovery, token issuance, roles, and session behavior.
Move one organization environment at a time, with explicit operator control.
Not a slide deck
Running on API Gateway, Lambda, and DynamoDB, fronted by Cloudflare, today.
Authorization code flow with PKCE, validated against real backing data.
We're onboarding design partners and shaping the roadmap with them now.
Public signup
Start with a hosted login, a production OIDC issuer, an owner account, and a workspace you control.