SSO & Federation

One login for every app and every provider.

HelixIAM is a full OpenID Connect provider and a SAML 2.0 IdP and SP — plus brokers for social, enterprise, and legacy directories. Bring identities in, send them everywhere.

Standards-based SSO

Issue tokens as a certified-grade OIDC provider and assert SAML for the apps that need it. HelixIAM speaks both natively — including advanced OIDC (PAR, token exchange, CIBA).

  • OpenID Connect provider
  • SAML 2.0 IdP & Service Provider
  • PAR, DPoP, CIBA, token exchange
  • Front-, back-channel & SAML SLO

Broker any identity

Let people sign in with Google, Microsoft, GitHub, any OIDC/SAML provider, or your corporate directory. Attributes and roles map cleanly on the way in.

  • Social & generic OIDC brokers
  • SAML broker (inbound)
  • LDAP / Active Directory
  • JIT provisioning + account linking

Applications, not just clients

Model a real Service Provider once — it owns its OIDC client and SAML RP together, sharing subject claims and a login flow. WSO2/Okta-style, done right.

  • Unified Application model
  • Shared subject claim + flow
  • Per-client scopes, claims & mappers
  • Web-origins + real CORS enforcement

B2B organizations

Multi-tenant by design. Organizations, groups, and per-realm settings let you serve many customers from one deployment with hard isolation.

  • Realms with data partitioning
  • Organizations (B2B) + domains
  • Hierarchical groups & role mappings
  • Resource Indicators (RFC 8707)

See HelixIAM on your own stack.

A 30-minute demo: realms, agents, workload identity, and a live migration off Keycloak — mapped to your use case.

No credit card. Self-hostable. Engineered in Europe.