Platform
One identity layer. Six capabilities.
Sign-in, provisioning and audit for Indian organisations. Explore each one below.
Live flow, simulated
- HR marks a leaver inactive
- SCIM PATCH reaches AuthMantra
- Sessions end, apps deprovisioned
- audit.write, SIEM stream sent
Capability explorer
Pick a capability
Sign-in
- SAML 2.0 and OpenID Connect with PKCE.
- Pre-built connectors for common SaaS apps.
- Apps trust a signed proof, not a stored password.
Passkeys & MFA
- Passkeys work with Face ID, Touch ID, Windows Hello or a key.
- Authenticator-app codes as the backup.
- Passkeys resist phishing by design.
Provisioning
- Joiners, movers and leavers arrive over SCIM 2.0.
- Outbound SCIM carries the change to apps.
- A leaver loses access when the HR record changes.
Step-up
- Sensitive admin actions ask for a fresh sign-in.
- Applies even when the session is already open.
- Every step-up is in the audit log.
Audit & SIEM
- Every sign-in and admin change is recorded.
- Export the log or watch the live feed.
- Stream to your SIEM, signed.
DPDP controls
- Grievance workflow, data export, consent records.
- Data hosted in Mumbai, asia-south1.
- DPDP-oriented: supports your process, not a certificate.
Try it
A look inside the admin console
An interactive demo with example people and apps. Nothing here is real data.
People
Add a joiner or mark a leaver. Apps follow.
| Name | Role | Sign-in | Action |
|---|---|---|---|
| Priya Sharma | People ops | Passkey | |
| Arjun Mehta | IT admin | Passkey | |
| Meera Iyer | Finance | Passkey | |
| Rohan Das | Engineering | Authenticator app |
Apps
Five connected apps. Switch provisioning per app.
- Mail & documentsOIDCProvisioning
- ChatSAML 2.0Provisioning
- Cloud consoleSAML 2.0Provisioning
- Code hostingOIDCProvisioning
- TicketingSAML 2.0Provisioning
Directory
Your HR system is the source of truth.
- No run yet. Press Run sync.
Simulated run with example people.
Sign-in
Choose how people prove who they are.
- PasskeysFace ID, Touch ID, Windows Hello, security keys, phones
- Authenticator appTime-based codes
- SMS codesProvider integration plannedPlanned
Approvals
Sensitive changes ask you to re-authenticate.
Role change request
Meera Iyer → IT admin
Requested by Arjun Mehta
Step-up
Confirm it is you
Changing roles needs a fresh sign-in, even in an open session.
Waiting for your passkey…
Touch the sensor on your device.
Approved
Meera Iyer is now IT admin. The change and the step-up are in the audit log.
Declined
The request is closed and recorded.
My apps
Good morning, Priya. Open any app.
Select an app to sign in with one click.
Passkeys
Only you can remove a passkey.
- Work laptopTouch ID
- PhoneFace ID
- Security keyUSB
Sessions
See where you are signed in. End any other session.
- This laptopMumbai · active nowThis device
- PhonePune · 2 hours ago
- Office desktopBengaluru · yesterday
Sign in
What signing in feels like.
My data
Your records, under your control.
- Download my dataExport what we hold about you
- Consent recordsPrivacy notice acceptedRecorded
- Raise a grievanceOpens the grievance workflow
Live feed
Sign-ins as they happen. Add one yourself.
- Priya SharmaCloud console · PasskeyPassed
- Arjun MehtaTicketing · PasskeyPassed
- Rohan DasChat · Authenticator appPassed
- Meera IyerMail & documents · PasskeyPassed
App access
Who can open which app. Revoke what is no longer needed.
- Arjun MehtaCloud console
- Rohan DasCode hosting
- Meera IyerTicketing
- Priya SharmaMail & documents
All checked
Each revoke is written to the audit log.
Audit log
Every sign-in and admin change, in order.
| Time | Who | What | Target |
|---|---|---|---|
| 09:14 | Priya Sharma | Signed in with a passkey | Cloud console |
| 09:02 | Arjun Mehta | Re-authenticated for an admin action | Role change |
| 08:55 | Arjun Mehta | Role changed | Meera Iyer |
| 08:40 | Arjun Mehta | Provisioning switched on | Chat |
| 08:31 | Rohan Das | Signed in with an authenticator code | Code hosting |
| 08:12 | HR system | User deactivated over SCIM | Imran Qureshi |
SIEM
Stream the audit log to your security tools.
X-AuthMantra-Signature: t=1760000000,v1=<hmac-sha256 of "t.body">
Simulated delivery with example data.
Suspend
Suspending signs a person out everywhere.
- Rohan Das2 active sessions
- Imran Qureshi1 active session
- Sneha Reddy3 active sessions
Watch an event travel
One leaver, from HR to your SIEM
Press Play. Every line is simulated.
$ hr emit leaver --id EMP-0377 SCIM PATCH /scim/v2/Users/3c91 active=false ✓ 202 Accepted by AuthMantra outbound SCIM: Mail & documents, Chat, Cloud console ✓ 3 of 3 apps updated audit.write user.deactivated $ stream --to siem {"event":"user.deactivated","target":"rohan.das@example.in","result":"ok"} X-AuthMantra-Signature: t=1760000000,v1=3b7e41...c9 ✓ 200 OK from your endpoint
Product views
What it looks like
Architecture
Apps, AuthMantra, your systems
Your apps
AuthMantra
Your systems
Integrations
Connect what you already run
Any app that speaks SAML 2.0 or OpenID Connect can sign in. Connector types the product has:
Security posture
True today
Six areas, one console
- Sign-in
- Passkeys & MFA
- Provisioning
- Step-up
- Audit & SIEM
- DPDP controls
These are product facts, not certifications. We hold no SOC 2 report or ISO 27001 certificate yet. See Trust & security.
See it with your own apps
Free for up to 10 people. Or tell us how you sign in today.