Skip to main content

SecureAuth Connect documentation

SecureAuth Connect handles authentication, fine-grained authorization, API security, risk-based access, and lifecycle management for every identity population: consumers, business customers, partners, workforces, machine identities, and AI agents. It runs on open standards with policy-driven access controls.

At a glance

CapabilitiesAuthentication · Authorization · API security · Risk analysis · User and application management
Identity populationsConsumers · Business customers · Partners · Workforces · Machine identities · AI agents
ProtocolsOIDC · SAML · OAuth 2.1 · FAPI-certified
DeploymentPublic SaaS · Private SaaS · Private cloud · Kubernetes self-hosted
ComplianceSOC 2 Type 2 · ISO 27001

Where do you want to go?

What do you want to do?

Authentication methods

SecureAuth Connect supports the following authentication methods. Select one to see configuration steps.

MethodWhat it isTypical useConfigure
Email OTPOne-time code sent to emailStep-up, fallback, first-factorView
Magic linkOne-click email loginLow-friction B2CView
PasskeysDevice-bound cryptographic login, no passwordConsumer appsView
Push notificationApprove or deny on a mobile deviceB2B, high-security B2CView
QR codeScan a QR code with a mobile device to sign inShared workstations, kiosksView
SMS OTPOne-time code sent via text messageStep-up, fallbackView
Social loginSign in with Apple, Facebook, GitHub, Google, LinkedIn, Microsoft, or XConsumer appsView
SSOSign in using your company's identity providerB2BView
SymbolMatch a symbol on screen and mobile deviceHigh-security, anti-phishingView
TOTPTime-based codes from a mobile appB2B, high-security B2CView
Voice OTPOne-time code read aloud by phone callStep-up, fallback, accessibilityView
PasswordTraditional username and passwordLegacy or fallback onlyView

How users get to the right provider

When you connect multiple identity providers, SecureAuth Connect can automatically route users to the correct one based on their email domain or organization membership. This is called IdP Routing, and it eliminates the need for users to manually choose a provider at sign-in.