Skip to content
OIDOT

The identity platform your product doesn't have to build.

Oidot is an authentication, SSO, and access-control platform: email/password and social login, TOTP MFA, permission-based RBAC, session management, and scoped API keys — built to be the identity layer other products rely on.

Platform

Everything an identity layer needs to do

One platform for authentication, access, and the machinery around them — so your product doesn't have to build it.

Authentication

Email/password signup and login, Argon2id password hashing, and enumeration-safe endpoints.

Single sign-on

Google, GitHub, and Microsoft login, plus Oidot as the OIDC provider for your other apps.

Multi-factor authentication

TOTP-based MFA, recovery codes, and step-up re-authentication for sensitive actions.

Role-based access control

Permission-based roles rather than hardcoded role names — fail-closed by design.

Session management

Users can see and revoke active sessions and devices, individually or all at once.

API keys

Scoped, rotatable machine credentials for programmatic access.

Built on

Argon2id
OAuth 2.1 / OIDC
TOTP MFA
Fail-closed RBAC
Audit logging
Rate limiting

Built for teams like these

Explore solutions →
01

Startups

Fast to integrate, with generous defaults out of the box.

02

SaaS platforms

Multi-app SSO via the OIDC provider, plus API keys for your customers.

03

Enterprise

MFA, audit logging, and fail-closed access control.

04

Developers

API-first, with scoped keys and an OpenAPI schema.

Ready to add identity to your product?

Start free, or talk to us about what you're building.