Solutions · B2B SaaS

The auth checklist
that unblocks the deal.

Enterprise SSO, directory sync, RBAC, and audit logs — shipping today, and priced so that winning a bigger customer doesn't cost you more per customer.

Every enterprise deal stalls on the same security questionnaire.

SAML is the line item that holds up the contract.

Your buyer's security team will not sign without single sign-on against their own identity provider. Building SAML yourself means learning XML signature verification well enough to get it right, and getting it wrong is a breach rather than a bug.

  • SAML 2.0 and OIDC federation, so a customer connects the IdP they already run.
  • Assertions verified signature by signature, with single-use assertion IDs so a captured one cannot be replayed.
  • IdP-initiated logins resolve back to the right connection rather than guessing.
  • Connect Okta, Microsoft Entra ID, Google Workspace, Ping Identity, JumpCloud, or any conforming IdP.

Their IT admin configures it. Not your support queue.

Every SSO connection you set up by hand is a support ticket, a shared screenshot of a metadata URL, and a certificate that expires in a year with nobody watching. The Admin Portal hands that work to the person who actually owns the identity provider.

  • A hosted portal your customer's IT admin signs into to configure SSO and SCIM themselves.
  • Domain verification over DNS, so a connection is claimed by someone who controls the domain.
  • They rotate their own SAML signing certificate before it expires.
  • SCIM 2.0 directory sync: new hires appear, leavers are deprovisioned, groups stay in step.

The evidence a security review asks for.

Procurement will ask who did what and when, whether you can prove it, and whether the answer lands in the system their security team already watches. That is a logging problem long before it is a feature problem.

  • Every privileged action in a tenant-scoped audit log you can query and export.
  • Stream to Datadog, Splunk HEC, or any HTTPS collector in that destination's native format.
  • RBAC with roles and permissions carried in the token, enforced across the API and the management plane.
  • Signed, retried webhooks — or pull the same stream behind a cursor.
console.oauth.work · activity
The activity screen showing the audit trail, with each event's actor and timestamp.

Winning a bigger customer shouldn't cost more per customer.

Per-connection pricing taxes exactly the deals you worked hardest to win: the tenth enterprise customer costs the same to serve as the first, but the bill says otherwise. That is a pricing model, not a cost.

  • Every tenant, every SSO connection, and every agent is in the price.
  • Your data and your tenant configuration export through the management API.
  • Standard OIDC end to end, so there is nothing bespoke to adopt and nothing to unpick if you leave.
What you get

In the product today.

Enterprise SSO
SAML 2.0 · OIDC federation

Connect a customer's identity provider and their whole company signs in, verified assertion by assertion.

Directory Sync
SCIM 2.0 · users + groups

Deprovisioning ends live sessions on the next request, not whenever the token happens to expire.

Admin Portal
self-serve setup for IT admins

Your customer's IT team configures SSO and SCIM, verifies their domain, and rotates their own certificate.

RBAC & organizations
roles · permissions · memberships

Tokens carry the organization and the roles with them. Define permissions once, enforce them everywhere.

Audit logs & streaming
queryable API · Datadog · Splunk · HTTPS

A tenant-scoped record of every privileged action, queryable and streamable to the SIEM they already run.

Multi-tenancy
one isolated issuer per customer

Each customer is a self-contained issuer with its own keys, so one tenant's configuration can never reach another's.

Ship the checklist.
Win the deal.

Set up a tenant on the free plan in minutes, or read the docs first. No sales call and no demo gate — and a real person on the other end when a procurement review needs one.