Identity
One answer to who someone is.
Who someone is, and what they may have, is answered once. Every product resolves against that same answer, so there is one place to add a person and one place to remove them.
| Service | Status |
|---|---|
| SAML 2.0 | On |
| SCIM | On |
| Directory Services | Off |
| Verified Domain | harborpine.example |
Sign-in and provisioning, built in.
Nothing to bolt on from another vendor.
SAML 2.0 and OIDC
Single sign-on from Entra ID, Okta or any SAML 2.0 provider, with SP metadata you can export.
SCIM provisioning
People and groups arrive from your directory, and someone removed there loses access here.
Google and Microsoft
People can sign in with the account they already have.
Two-factor
A code from an authenticator app (TOTP) as a second factor.
Verified domains
A custom identity provider is tied to a domain you have verified.
Self-serve sign-up
Create an organisation yourself, with no call and no procurement cycle.
Decide who may join with your domain.
Anyone signing up with a matching email domain can join, or wait for an administrator to approve them. Once SAML is on, your identity provider decides instead.
- Approval queue in Access Requests
- SAML replaces join rules when enabled
- Directory Services reads groups; it never writes
| Person | Domain | Waiting |
|---|---|---|
| Noah Kim | harborpine.example | 2 h |
| Ava Brooks | harborpine.example | 1 d |
Name a group anywhere a person can go.
Connect Microsoft Entra, PingOne or Active Directory to read groups and membership, so a group can be an approver, an owner or the audience of a rule.
- SP Entity ID
- unique to your organisation
- ACS URL
- unique to your organisation
- Signing
- Default · rotated by Fowlguard
Sign-in with Google or Microsoft on every plan. SAML 2.0, SCIM and Directory Services from the Small plan, $5 per user per month.
Asked often.
Which identity providers work?
Any SAML 2.0 provider, including Entra ID and Okta, plus Google and Microsoft sign-in.
What happens when someone leaves?
With SCIM, removing them in your directory removes their access here, with nobody doing it by hand.
Do you support passkeys?
Not yet. Today the second factor is a code from an authenticator app.