SSO — SAML & OIDC
Log your team in through your identity provider (Okta, Entra, Google, any OIDC/SAML IdP). An SSO sign-in provisions users straight into your organization.
Open Connector Enterprise adds the features security and IT teams require — SSO, SCIM directory sync, and long-term audit retention & export — unlocked by an offline license key on your self-hosted instance. The core broker stays open source (AGPL-3.0), and credentials never leave your environment.
Log your team in through your identity provider (Okta, Entra, Google, any OIDC/SAML IdP). An SSO sign-in provisions users straight into your organization.
Provision and deprovision users automatically from your directory over SCIM 2.0 — joiners and leavers stay in sync without manual seat management.
Keep the tamper-evident audit trail for as long as compliance requires and export it to your SIEM. The base trail is free in core; the EE layer adds retention + export.
Every enterprise feature runs on your self-hosted instance, unlocked by an offline license key — no phone-home, air-gap friendly. Credentials never leave your environment.
Self-host the open-source core for free, then unlock SSO, SCIM, and audit retention with a license key. No data leaves your environment.