Secure your APIs with a robust, feature-rich Identity solution.
- π Overview
- π Features
- π Protocols
- π Documentation
- π₯ Community
- π Contributing
- π License
Gravitee.io AM aims to be a bridge between applications and identity providers to authenticate, authorize and getting information about user accounts.
- Access security: Control and secure enterprise data with industry standard protocols such as OpenID Connect and OAuth 2.0 and JWT.
- Single sign-on (SSO): Centralized and strong authentication for your customers using out-of-the-box or custom identity providers.
- Multi-factor authentication (MFA): Enforce security and convenience by adding extra authentication factors.
- Passwordless: Secure your apps and APIs with industry best-practice security using biometrics, tokens and further passwordless auth mechanisms.
- Identity providers marketplace: Connect your application with your user resources such as LDAP, Database, Webservices, Azure AD, Social, ... .
- Analytics dashboard: The out-of-the-box dashboards give you a 360-degree view of your applications and users. You can also use all metrics with external tools like Grafana or Kibana.
- Plugins system: Specialize platform behavior to exactly fit your needs.
- OpenID Provider: Basic OP, Implicit OP, Hybrid OP, Config OP, Dynamic OP
- FAPI OpenID Provider: all profiles
Gravitee.io AM also supports the following protocols to help our customers to connect with 3rd party tools:
- SAML 2.0: Security Assertion Markup Language 2.0
- SCIM 2.0: System for Cross-domain Identity Management 2.0
- CAS protocol: Central Authentication Service
- Kerberos: Computer-network authentication protocol
- JWT: JSON Web Tokens
You can find Gravitee.io Access Management's documentation on the dedicated website.
Got questions, suggestions or feedback? Why not join us on the Gravitee.io Community Forum.
We welcome contributions! Please read the dedicated CONTRIBUTING guide for more info.
Gravitee.io API Management is licensed under the Apache License, Version 2.0.