Product

Everything between your users and your applications

You connect each application to OneiD once. Sign-in pages, second factors, sessions, roles and the record of who signed in are then the same for all of them.

What you get

Features

The parts of OneiD that your users, your developers and your administrators work with.

Single sign-on

A user signs in once and reaches every connected application. Authorization code flow with PKCE for applications, client credentials for services, rotating refresh tokens.

Multi-factor authentication

Authenticator-app codes (TOTP) with enrolment by QR code. Make the second factor optional, or mandatory for everyone or for chosen users.

Admin console

One web console for applications, users, roles, scopes and sessions, with read-only and limited administrator roles.

Roles in every token

Assign roles in OneiD or map them from directory groups. Applications read them from the token; they do not need to query a directory.

Audit log

Sign-ins, failed attempts, password changes, client changes and key rotations are recorded with time and address.

Sessions and sign-out

Applications can sign the user out of OneiD. Administrators can revoke a user’s tokens at any time, and tokens are revoked when a password changes.

Managed signing keys

Signing keys are stored encrypted and survive restarts. A new key is published before it is used, so applications pick it up without interruption.

Hardened by default

Rate limits on sign-in and token requests, strict browser security headers, HTTPS only, and no secrets in logs.

Admin console

One console for applications, users and keys

Administrators work in a web console. Every action there is also available through the Admin API, under the same roles.

Applications

Register clients, their redirect addresses, scopes, allowed origins and token lifetimes. Generate, replace or disable a client secret.

Users

Create users, assign roles, unlock accounts, reset the second factor, require a password change or a second factor.

Roles and scopes

Define roles and the API scopes your services accept. Built-in administrator roles cannot be renamed or deleted.

Sessions

See who holds tokens for which application and revoke them.

Audit log

Search sign-ins, failures, administrator changes and key rotations. Auditors get a read-only role of their own.

Signing keys

Rotate the keys that sign tokens, with an activation time so that the new key is published first.

Administrators get only what they need

Built-in roles separate who manages applications, who manages users and who only reads. The management roles also come in read-only versions. The Admin API accepts tokens only from administrators whose token carries the admin scope.

Built-in administrator roles
RoleWhat it may do
AllFull administrator. The only role that manages other administrators and privileged scopes.
AllReadOnlySees everything, changes nothing.
AuthorizationServerManagerManages applications, scopes and keys.
UserManagerManages users and their roles.
AuditerReads the audit log.

Sign-in sources

Use the accounts that you already have

OneiD can keep the accounts itself or check them against a system that you already run. Your applications do not see the difference: they always talk to OneiD and always receive the same kind of token. One OneiD installation uses one of these sources.

Accounts that OneiD keeps

Users sign in with a user name and password that OneiD stores. Use this mode when you have no directory, or when you want OneiD to be the directory.

  • Password reset by a code sent to the user’s email address
  • Authenticator-app codes (TOTP) as a second factor, optional or mandatory
  • Account lockout after repeated wrong passwords
  • Administrators create users, assign roles and force a password change

Standards

Open standards, so any library works

OneiD speaks the protocols that sign-in libraries already know. It was tested with the OpenID Foundation’s conformance suite: the Config, Basic, Form Post and RP-Initiated Logout test plans for providers ran with no failed test. OneiD is not yet OpenID Certified.

OAuth 2.0

Authorization code, client credentials and refresh token grants (RFC 6749)

PKCE

Required for browser and mobile applications (RFC 7636)

OpenID Connect Core 1.0

ID tokens, userinfo, prompt and max_age, the claims parameter

OpenID Connect Discovery 1.0

Applications configure themselves from one address

RP-Initiated Logout 1.0

Sign-out that starts in the application

Form Post Response Mode

Authorization responses by HTTP POST

Token Introspection and Revocation

RFC 7662 and RFC 7009

JSON Web Tokens

Signed access tokens that an API can check without a call to OneiD

What OneiD does not do

Check this list before you plan an integration. OneiD does not offer:

  • SAML and WS-Federation
  • SCIM provisioning
  • Dynamic client registration
  • Implicit, hybrid, password and device flows
  • Front-channel and back-channel logout
  • Passkeys, SMS and push as second factors

The full list of supported and unsupported standards

Get OneiD

How to get OneiD

We can run OneiD for you, or you can run it in your own environment. Talk to us about the way that fits your organisation.

Hosted by OneiD

We run OneiD for you.

  • We install OneiD and its updates
  • We make the backups and monitor the service
  • You get your own OneiD address and your own data store

In your own environment

You run OneiD in your own cloud account or data centre.

  • OneiD runs as containers
  • OneiD keeps its data in a PostgreSQL database that you operate
  • We supply the software and support your team

Questions

Cannot find your answer? Ask us.

Is OneiD OpenID Certified?

Not yet. OneiD was tested with the OpenID Foundation’s conformance suite: the Config, Basic, Form Post and RP-Initiated Logout test plans for providers ran with no failed test. We will say “certified” only when the OpenID Foundation has certified it.

Can our users keep their Active Directory or Okta accounts?

Yes. OneiD can check passwords against LDAP or Active Directory, or send users to an OpenID Connect provider such as Okta. Groups become OneiD roles through a mapping you control. One OneiD installation uses one source of users.

A dedicated Microsoft Entra ID source is planned.

Does OneiD support SAML or SCIM?

No. OneiD speaks OpenID Connect and OAuth 2.0. If an application only supports SAML, or you need SCIM provisioning, talk to us before you choose OneiD.

Which second factors are available?

Authenticator-app codes (TOTP), optional or mandatory for everyone or for chosen users. SMS, passkeys and push notifications are not available.

Where does our data live?

Each customer has its own OneiD with its own database. When we host OneiD, you get your own OneiD address and data store. When you run it yourself, the data stays in your PostgreSQL database.

Can an AI coding agent connect our applications?

Yes. The documentation is published as Markdown and in llms.txt, and a connector specification lists exactly what an integration must do. Give your agent the specification and your client settings.

See OneiD sign you in

The demo application signs you in through OneiD and shows the tokens it receives. Talk to us about running OneiD for your organisation.