Identity infrastructure for B2B SaaS

Ship your product.
We'll ship the auth.

Tenant-aware login, OIDC, and RBAC for B2B SaaS teams — hosted, standards-based, and migratable off Cognito. Your users and data stay portable, so you're never locked in.

  • OIDC
  • OAuth 2.0
  • PKCE
  • Passkeys
  • TOTP

Built to pass your security review.

Platform

Auth built for tenants, not just users.

Organizations, environments, sessions, authorization checks, and audit evidence are first-class — because B2B auth is more than a login box.

01

Hosted login

Password, magic link, passkey, TOTP, recovery-code, and session-cookie flows for application sign-in — hosted and maintained so you don't have to.

02

OIDC sign-in

Environment-scoped issuers, discovery, JWKS, authorization code with PKCE, token exchange, userinfo, revoke, and logout endpoints.

03

Tenant-aware RBAC

Organizations, environments, memberships, roles, permissions, authorization checks, and session revocation as first-class product concepts.

04

Audit evidence

Security-sensitive actions and privileged admin changes leave durable, queryable event trails you can hand to your auditors.

Security & compliance

Built to pass your security review.

We run the infrastructure so your team doesn't — with the encryption, data controls, and audit evidence your customers' security questionnaires ask for. Hosted, but never locked in.

Migration

A practical path off Cognito.

Our first migration path targets SaaS teams already on Cognito user pools that want tenant-aware auth, clearer operator controls, and a product surface they can grow into — without a big-bang rewrite.

  1. 1
    Import users and clients

    Validate user exports, OAuth clients, membership mapping, and redirect URIs.

  2. 2
    Rehearse the cutover

    Test hosted login, OIDC discovery, token issuance, roles, and session behavior.

  3. 3
    Switch new sessions

    Move one organization environment at a time, with explicit operator control.

Not a slide deck

A running system, not a roadmap.

Live serverless deployment

Running on API Gateway, Lambda, and DynamoDB, fronted by Cloudflare, today.

OIDC verified end to end

Authorization code flow with PKCE, validated against real backing data.

Early access, open door

We're onboarding design partners and shaping the roadmap with them now.

Public signup

Create your Auth Yourself workspace.

Start with a hosted login, a production OIDC issuer, an owner account, and a workspace you control.

Create account