Every feature you need to ship auth — from a weekend project to a Fortune 500 deployment.
Email/password, social login, magic links, enterprise SSO. One API handles all of it. Your users pick how they want to authenticate.
SAML, OIDC, LDAP — configured in your dashboard, not in code. Domain-based routing automatically sends users to the right identity provider.
Full SP metadata generation. IdP-initiated and SP-initiated flows. Signature verification.
Auto-discovery via .well-known. Code exchange with PKCE. UserInfo endpoint.
Bind authentication against Active Directory or OpenLDAP. TLS support.
Annotate your routes. The SDK discovers permissions automatically and registers them with AuthFI. Assign permissions to roles in the dashboard. JWTs include everything.
Colors, fonts, layout, logo, custom domain, custom CSS. Your users never know AuthFI exists.
Primary, background, text — full palette control.
Inter, Roboto, Poppins, DM Sans, or system.
Centered, split panel, or left-aligned.
auth.yourapp.com with auto SSL.
Everything you need to integrate, extend, and automate.
Node.js, Python, Go, Java, PHP, C#, Ruby. JWT validation + permission checks built in.
HMAC-signed events for login, signup, password reset, MFA enrollment. Full delivery log.
Full REST API with API key auth. CRUD users, roles, apps, connections, everything.
Standard .well-known/openid-configuration + JWKS endpoints for every tenant.
Automated user provisioning from Okta, Azure AD, or any SCIM-compatible IdP.
Isolated dev, staging, production — each with their own keys, users, and config.
Deploy one agent. It discovers your services automatically, hooks into the Linux kernel via eBPF, and validates JWTs on every request. Admin panels, APIs, dashboards — all protected without touching a single line of application code.
OIDC federation to AWS, GCP, and Azure. AuthFI issues short-lived tokens trusted by cloud IAM. Your users and services access cloud resources with their AuthFI identity — no API keys in environment variables. Ever.
AuthFI core handles auth for any SaaS app. Industry modules add compliance-specific scopes, token claims, and discovery endpoints — activated per tenant, no code changes.
SMART on FHIR v2.2 scope engine. Patient/encounter launch context. fhirUser claim injection. .well-known/smart-configuration. HIPAA-ready audit retention.
PSD2 Strong Customer Authentication. Transaction signing scopes. KYC verification hooks. PCI-DSS audit controls. Risk-based step-up authentication.
LTI integration for LMS platforms. FERPA-compliant access controls. Student/guardian consent model. SIS directory sync. Grade-level scoping.
Modules activate per tenant via the management API. Your SaaS serves healthcare, fintech, and education customers — from one deployment.
Cloud Run for compute. Cloud SQL for data. Cloudflare for edge. Scales down to $0 when idle, scales up to handle millions of auth requests.
Auto-scaling containers. Pay only for requests. Scale to zero.
Managed PostgreSQL with automatic backups and regional replicas.
Global CDN, DDoS protection, custom domain SSL provisioning.
India, US, EU, Australia. Data residency per tenant.