Surfaces

Each surface carries one authority boundary

www.sigid.org you are here

Landing, documentation, pricing, and entry points. No credentials, no sessions.

identity.sigid.org Your account

Profile, sessions, passkeys, MFA, memberships, and data sharing controls.

dashboard.sigid.org Tenant operations

Applications, domains, branding, billing, audit, and operator workflows.

auth.sigid.org OAuth flows

Authorize, consent, callbacks, passkey ceremonies, and token issuance. Rust-owned.

Platform

Enterprise identity, not a login widget

Hosted auth

Password, passkey, magic link, social login, enterprise SSO, TOTP, SMS, and SIWE on a hardened first-party origin you never have to build.

Agent identity

AI agents as first-class principals with challenge–response auth, canonical IDP-minted identity, and standard token issuance.

Passkeys and MFA

FIDO2 resident credentials with automatic syncing, TOTP enrollment, SMS fallback, and backup codes.

Consent and sharing

Users choose what each application can see. Scope upgrades require re-consent – silently widening access is not a feature.

Credential vault and egress

Store third-party OAuth tokens, API keys, and SSH keys once. Agents use them through the egress data plane – the secret is injected at the boundary, never enters agent context, and every use is audited. The egress is open source: run it in your own cloud and your workload traffic never reaches SigID.

Enterprise SSO

Per-tenant OIDC federation with dynamic credentials, domain-based routing, and social provider support.

Tenant operations

Applications, domains, branding, billing, audit, webhooks, and policy management in one control plane.