Where your organization signs in.
KinAuth is an identity provider: single sign-on to the applications you already run, second factors your organization can require of everyone, and a directory of your users and groups.
It is secure by design. The database itself keeps organizations apart, passkeys make sign-in resistant to phishing, every change is recorded, and the server is built on Go’s own libraries and nothing else. How KinAuth is built
- Sign-on
- OpenID Connect, SAML 2.0
- Second factors
- Passkeys, approval on a phone, authenticator codes, recovery codes
- Address
- your-organization.kinauth.com
What your organization’s people sign in to through KinAuth.
One sign-in for the applications you already run
KinAuth signs people in to applications that speak OpenID Connect or SAML 2.0, and has ready-made settings for Grafana, Harbor and Redash. People sign in once, at your organization’s address, and open their applications from one page.
- OpenID Connect
- The authorization code flow, with PKCE required by default. Signed ID tokens, refresh tokens that are spent by their use, and sign-out when the application asks for it.
- SAML 2.0
- A separate identity provider for each application, with its own signing key. Signed responses, sent to the address you registered and to no other.
- Access by group
- You give each application to groups, or to everyone. A person who leaves a group no longer gets its applications: access is checked again at every sign-on.
A second factor that cannot be approved by reflex
When you sign in, the page shows a two-digit number. KinAuth’s app on your phone shows three, and is never told which one is right: you pick the one on your screen. A request somebody else caused has no number in front of you to match, and a wrong pick is a denial.
The key that approves is created on the phone and never leaves it. The server keeps only its public half, so nothing in the database can approve a sign-in.
Open KinAuth on your phone and choose this number:
Waiting for your phone…
Someone is signing in to Acme as you
203.0.113.24 · Chrome · now
Choose the number on the sign-in page
This was not me
- Passkeys
- A key that your device or a security key holds, and that works only at your organization’s own address, so it cannot be given to a fake page. Use one after your password, or alone in its place when it verifies you with a fingerprint, a face or a PIN.
- Authenticator codes
- Six-digit codes from any authenticator app (TOTP), which work without a network.
- Recovery codes
- Ten codes, each good once, for the day a phone is lost. A session opened with one gets you back in, and can neither add nor remove a factor.
- Required by the organization
- An administrator can require a second factor of everyone, with a set number of days for each person to add one. After that, a password alone opens nothing.
Your people, their groups, and a record of every change
The directory holds your organization’s users and the groups they belong to. Groups are what gives access: put a person in one, and they have its applications at their next sign-in.
Every sign-in and every change is written to the audit log with who did it, when, and from which address, in the same step as the change itself. The log is append-only: the database itself refuses an update or a delete.
Sign-ins and changes in your organization. Entries cannot be edited or deleted.
Secure by design
An identity provider is the one system whose compromise is the compromise of everything behind it. KinAuth is built so that its guarantees do not rest on anybody remembering to be careful.
- Organizations kept apart by the database
- Each organization has its own address, and PostgreSQL’s row level security lets a query see only the rows of the organization it was opened for.
- Sign-in that resists phishing
- A passkey answers only to your organization’s address, and an approval on a phone needs the number that is on your screen.
- Every change on record
- The audit entry is written together with the change: both happen or neither does.
- No third-party code in the server
- The server is built on Go’s standard library and the Go team’s own cryptography module. What else it needs, it has written itself.
Your organization, at its own address
Every organization on KinAuth signs in at an address of its own, your-organization.kinauth.com, with its own users, its own applications and its own audit log.
Questions about KinAuth? Write to us: legal@kinauth.com