IdentityComing soon · Security Platform

Tessarac is the IdP. Everything builds on it.

SAML 2.0 IdP + SP, OpenID Connect OP + RP, SCIM 2.0, MFA with WebAuthn / passkeys / hardware keys / TOTP, smart-card (CAC/PIV) sign-in, social federation with 25+ providers, JIT provisioning from Google Workspace and Microsoft Entra. The same primitives every customer-facing surface and every internal service uses.

Concentric authentication factors radiating from a central trust shield in deep midnight blue.

Workforce + Customer + Machine

One identity engine for every kind of identity.

Workforce SSO (employees, contractors, temp staff signing into your apps), customer identity (your customers signing into your product), and machine-to-machine (your services signing into each other) all use the same engine. Same audit log. Same RBAC model. Same compliance posture.

  • Workforce SSO — direct competitor to Okta Workforce, Microsoft Entra ID, JumpCloud, OneLogin
  • Customer identity (CIAM) — direct competitor to Okta Customer Identity Cloud (Auth0), Entra External ID
  • Machine-to-machine — OAuth client credentials, mTLS, hardware-bound workload identity
  • B2B multi-tenant — org switching, per-org SSO config, per-org branding, all built in
  • Per-tenant ECDSA P-384 trust anchor with HSM / cloud-KMS / BYOK options — one tenant's compromise can never reach another's keys

Every authentication factor your users want

The friction-free path on a phone is a passkey. The high-assurance path on a fed laptop is a smart card. Tessarac runs both, and the dozen options between them, on the same engine.

  • Multi-factor authentication challenge surface.

    Passkeys + WebAuthn

    Phishing-resistant, password-free sign-in. Built into iOS, Android, Windows, macOS — your users register the device they already have. Roaming hardware keys (YubiKey, Titan, Feitian) work the same way.

  • Single sign-on federation hub with token issuance flows.

    Smart card (CAC/PIV)

    Federal-grade hardware authentication. The Federal plan ships an embedded DoD/FCPCA trust bundle, OCSP+CRL revocation checking, and PIN-protected reader integration. Required for IL5 deployments.

  • Role-based access control surface with policy gates.

    Social federation

    25+ social providers — Google, Microsoft, Apple, GitHub, GitLab, Slack, LinkedIn, Facebook, X, Discord, Twitch, and more. Configure once; toggle per-tenant. Per-app social login is a setting, not a code change.

  • Append-only audit trail with hash-chained block visualization.

    Magic link + TOTP + SMS

    Passwordless sign-in via email link. TOTP for the security-conscious customer. SMS as a fallback (with opt-out at the tenant level — SMS is no longer recommended as a primary factor).

What we replace

The whole identity layer — workforce, customer, machine — under one bill.

Most teams pay Okta for workforce, Auth0 for customer, and a pile of homemade infrastructure for machine-to-machine. Tessarac collapses all three. One bill. One audit log. One implementation effort.

  • Direct migration paths from Okta (Workforce + Customer Identity Cloud), Microsoft Entra ID, Auth0, Keycloak, JumpCloud, and OneLogin
  • End-to-end agent envelope encryption — even our load balancers can't read the auth payload
  • Customer-visible per-tenant audit — your customers see their own logins, MFA challenges, and policy changes
  • Audit export to your own object-storage bucket / syslog endpoint — opt out of Tessarac retention entirely
  • Smart-card sign-in available on every paid plan; required by default on the Federal plan

One IdP. Workforce, customer, machine.

The thing every other product in your stack derives its trust from. One bill, one audit log, one tenant model.