Skip to main content

Enterprise identity. Zero compromise.

Connect your identity provider, automate user provisioning, and enforce phishing-resistant authentication — across every team and tenant in your Arbitex environment.

4 Identity Protocols

Works with every enterprise identity stack

Plug in your existing IdP — no custom integrations required.

SAML 2.0

Federate with any SAML-compliant identity provider. SP-initiated and IdP-initiated flows supported.

SCIM 2.0

Automate user and group provisioning from Okta, Azure AD, or any SCIM-compliant directory.

WebAuthn / FIDO2

Phishing-resistant hardware keys and passkeys. Replaces passwords where it matters most.

OIDC

OpenID Connect for token-based authentication. Full claims mapping and refresh token rotation.

Enterprise SSO

Federate with any SAML 2.0-compliant identity provider. Configure SP-initiated and IdP-initiated login flows, enforce session policies, and map IdP groups to Arbitex roles with no custom code.

Automated User Provisioning

SCIM 2.0 lifecycle management syncs users, groups, and role assignments from your directory in real time. Deprovisioning is immediate — when an employee leaves, access is revoked within seconds.

MFA and Passwordless

Enforce multi-factor authentication across all users with WebAuthn/FIDO2 hardware keys and passkeys. Phishing-resistant by design — eliminates credential theft as an attack vector.

Token and Session Governance

OIDC token validation with full claims inspection, JWT audience enforcement, and configurable refresh token rotation. Session policies enforce idle timeouts and maximum session durations per tenant.

Distributed Session Store

Sessions are backed by Redis — distributed across availability zones, with no sticky sessions required. Any gateway node can validate any session, eliminating single points of failure and enabling seamless horizontal scaling without session affinity routing.

OAuth Client Secret Rotation

Rotate OAuth client secrets with zero downtime. During rotation, both the old and new secrets remain valid for a configurable overlap window — services update their credentials without a hard cutover. The previous secret is automatically expired after the transition period.

How it works

01

Connect your identity provider

Point Arbitex at your existing SAML 2.0 IdP or OIDC provider — Okta, Azure AD, Google Workspace, Ping, or any compliant directory. Configuration takes minutes, not days. No SDK changes required in your application layer.

02

Provision users and groups automatically

Enable SCIM 2.0 to sync users and group memberships on a continuous basis. Role assignments in Arbitex reflect your directory in real time. When a user is deprovisioned in your IdP, their Arbitex sessions are terminated immediately.

03

Enforce authentication policies

Require MFA for all users or specific high-privilege roles. Choose between TOTP, hardware keys, or passkeys per policy tier. Monitor authentication events and policy enforcement in the audit log.

Related Resources

Machine-to-Machine

OAuth M2M for CI/CD and AI agents

Government

FedRAMP and FISMA compliance

Healthcare

HIPAA compliance and PHI detection

Compliance Frameworks

Pre-built policy packs for regulatory requirements

Read the identity provider guide

Identity-first access control for every AI workload.