Where your organization signs in.

KinAuth is an identity provider: single sign-on to the applications you already run, second factors your organization can require of everyone, and a directory of your users and groups.

It is secure by design. The database itself keeps organizations apart, passkeys make sign-in resistant to phishing, every change is recorded, and the server is built on Go’s own libraries and nothing else. How KinAuth is built

Sign-on
OpenID Connect, SAML 2.0
Second factors
Passkeys, approval on a phone, authenticator codes, recovery codes
Address
your-organization.kinauth.com
The administrator’s panel of an organization called Acme, at its own address.

One sign-in for the applications you already run

KinAuth signs people in to applications that speak OpenID Connect or SAML 2.0, and has ready-made settings for Grafana, Harbor and Redash. People sign in once, at your organization’s address, and open their applications from one page.

OpenID Connect
The authorization code flow, with PKCE required by default. Signed ID tokens, refresh tokens that are spent by their use, and sign-out when the application asks for it.
SAML 2.0
A separate identity provider for each application, with its own signing key. Signed responses, sent to the address you registered and to no other.
Access by group
You give each application to groups, or to everyone. A person who leaves a group no longer gets its applications: access is checked again at every sign-on.

A second factor that cannot be approved by reflex

When you sign in, the page shows a two-digit number. KinAuth’s app on your phone shows three, and is never told which one is right: you pick the one on your screen. A request somebody else caused has no number in front of you to match, and a wrong pick is a denial.

The key that approves is created on the phone and never leaves it. The server keeps only its public half, so nothing in the database can approve a sign-in.

The sign-in page and the phone, during an approval.
Passkeys
A key that your device or a security key holds, and that works only at your organization’s own address, so it cannot be given to a fake page. Use one after your password, or alone in its place when it verifies you with a fingerprint, a face or a PIN.
Authenticator codes
Six-digit codes from any authenticator app (TOTP), which work without a network.
Recovery codes
Ten codes, each good once, for the day a phone is lost. A session opened with one gets you back in, and can neither add nor remove a factor.
Required by the organization
An administrator can require a second factor of everyone, with a set number of days for each person to add one. After that, a password alone opens nothing.

Your people, their groups, and a record of every change

The directory holds your organization’s users and the groups they belong to. Groups are what gives access: put a person in one, and they have its applications at their next sign-in.

Every sign-in and every change is written to the audit log with who did it, when, and from which address, in the same step as the change itself. The log is append-only: the database itself refuses an update or a delete.

The audit log after a sign-in with a phone. The entry in red is an approval refused because the wrong number was chosen.

Secure by design

An identity provider is the one system whose compromise is the compromise of everything behind it. KinAuth is built so that its guarantees do not rest on anybody remembering to be careful.

How KinAuth is built

Organizations kept apart by the database
Each organization has its own address, and PostgreSQL’s row level security lets a query see only the rows of the organization it was opened for.
Sign-in that resists phishing
A passkey answers only to your organization’s address, and an approval on a phone needs the number that is on your screen.
Every change on record
The audit entry is written together with the change: both happen or neither does.
No third-party code in the server
The server is built on Go’s standard library and the Go team’s own cryptography module. What else it needs, it has written itself.

Your organization, at its own address

Every organization on KinAuth signs in at an address of its own, your-organization.kinauth.com, with its own users, its own applications and its own audit log.

Questions about KinAuth? Write to us: legal@kinauth.com