Identity

Who your end users are, and who can act for them

End users, the buyer organizations they belong to, your own team and the credentials your systems use, held on the same customer record as subscriptions, usage and entitlements.

An illustrated customer record for Acme Inc. Its members, subscription, usage and entitlements are held on the same record.
Acme Inc.org_acmeIllustrative

What it covers

Built so far

  • Sign-up and sign-in for your end users

    Email and password with email verification, magic links, Google or GitHub. Signing up creates the account, the buyer organization and the membership together.

  • Buyer organizations

    The service supports creating an organization, inviting, accepting and removing members, and switching between organizations.

  • Your team and machine credentials

    Invite teammates with one of four roles, Owner, Admin, Member or Viewer, scoped to all apps or a single app. Create, narrow, rotate and revoke machine credentials.

  • Separate sign-in for operators and end users

    Your team and your end users sign in through separate identity pools. The console does not accept end-user credentials, and the portal does not accept operator credentials.