Identity

One answer to who someone is.

Who someone is, and what they may have, is answered once. Every product resolves against that same answer, so there is one place to add a person and one place to remove them.

Configuration›Identity ServicesEXAMPLE
ServiceStatus
SAML 2.0On
SCIMOn
Directory ServicesOff
Verified Domainharborpine.example
What you get

Sign-in and provisioning, built in.

Nothing to bolt on from another vendor.

SAML 2.0 and OIDC

Single sign-on from Entra ID, Okta or any SAML 2.0 provider, with SP metadata you can export.

SCIM provisioning

People and groups arrive from your directory, and someone removed there loses access here.

Google and Microsoft

People can sign in with the account they already have.

Two-factor

A code from an authenticator app (TOTP) as a second factor.

Verified domains

A custom identity provider is tied to a domain you have verified.

Self-serve sign-up

Create an organisation yourself, with no call and no procurement cycle.

Join rules

Decide who may join with your domain.

Anyone signing up with a matching email domain can join, or wait for an administrator to approve them. Once SAML is on, your identity provider decides instead.

  • Approval queue in Access Requests
  • SAML replaces join rules when enabled
  • Directory Services reads groups; it never writes
Dashboard›Access RequestsEXAMPLE
PersonDomainWaiting
Noah Kimharborpine.example2 h
Ava Brooksharborpine.example1 d
Directory groups

Name a group anywhere a person can go.

Connect Microsoft Entra, PingOne or Active Directory to read groups and membership, so a group can be an approver, an owner or the audience of a rule.

Configuration›Identity ServicesEXAMPLE
SP Entity ID
unique to your organisation
ACS URL
unique to your organisation
Signing
Default · rotated by Fowlguard
Pricing

Sign-in with Google or Microsoft on every plan. SAML 2.0, SCIM and Directory Services from the Small plan, $5 per user per month.

Compare plans
Questions

Asked often.

Which identity providers work?

Any SAML 2.0 provider, including Entra ID and Okta, plus Google and Microsoft sign-in.

What happens when someone leaves?

With SCIM, removing them in your directory removes their access here, with nobody doing it by hand.

Do you support passkeys?

Not yet. Today the second factor is a code from an authenticator app.