About

One identity layer, agents included.

oauth.work handles who gets in and what they can do: single sign-on for your users, enterprise SSO and SCIM directory sync for your customers' IT teams, passkeys instead of passwords, RBAC and audit logs for their security reviewers, and scoped, revocable authorization for the AI agents acting on everyone's behalf.

We built it because agent access was being improvised — API keys shared between services, no consent step, no record of who did what. Meanwhile the teams selling to enterprises were paying per SSO connection for table stakes. Both were fixable, so we fixed them.

What we believe

  • Enterprise features shouldn't be a surcharge. SSO, directory sync, RBAC, audit logs, and agent auth are in the product, not behind a quote.
  • No per-connection tax, no lock-in. Standard OIDC on the wire, your configuration and data exportable through the management API — we'd rather earn the renewal.
  • Security is a property, not a posture. Tokens are bound to the client that requested them, replayed credentials revoke the session, and every privileged action is on the record.
  • You should be able to ship without talking to us. Free plan, real docs, no gated demo.

Where it runs

On Cloudflare's global network, so sign-ins happen close to your users wherever they are. The docs cover how it all fits together.