Skip to content

Identity provider / Built by Combine

One identity.
Every door.

Your applications belong together. Give people one account to move between them, and give your team one place to manage access.

Isolated by space. Connected by design.
One space · One session · Every connected app

Sign in once. Keep moving.

Single sign-on across your applications.

A space of your own.

Your users, your providers, your rules.

Standards at the core.

OpenID Connect and OAuth 2.1.

01 / How it works

One less barrier.
A lot more possibility.

Authentication should get people where they’re going. Citadel brings your applications into a shared space, so the next sign-in is one they can skip.

  1. 01 — A place to belong

    Start with your space.

    Give an organisation or application group its own identity home, on its own subdomain or a verified domain you bring.

  2. 02 — A familiar entrance

    Connect the ways in.

    Choose your sign-in methods, connect your identity providers, and register applications using OpenID Connect.

  3. 03 — Room to move

    Let one account do more.

    People sign in once and move between connected applications. Their profile, security settings and active sessions have one home.

02 / The platform

Everything identity.
All in its place.

A considered foundation for the people who use your apps and the teams who build them.

Separate spaces. Shared simplicity.

Each space keeps its own users, sessions, providers and applications. Clear boundaries for your organisations, with a consistent way to manage them.

Acme

acme.example.com

One account. Every app here.

Studio

studio.example.com

One account. Every app here.

A familiar way in.

Passwords, magic links, email codes or a provider people already know. Choose what fits each application.

  • Google
  • Steam
  • Email
  • OpenID

Your brand at the door.

A login that feels like your product. Choose a design, make it yours, and preview it before it goes live. Customise by space or application.

Confidence, built in.

Add a second factor with authenticator and recovery codes. Keep provider credentials encrypted at rest and give people control of their sessions.

More than a password.

A clear control centre.

Manage users, applications, domains and connections in one console. People get their own account area for profiles, security and access.

The right tools for each role.

03 / For developers

Your stack.
A common language.

Use the OpenID Connect client you already know. Citadel handles identity; your application gets back to doing what makes it useful.

  • Authorization code flow with PKCE
  • Discovery, JWKS and userinfo endpoints
  • Refresh tokens, revocation and logout
Let’s talk integration
A familiar handshake OpenID Connect

// Your space. Your issuer.

issuer = "https://auth.example.com"

GET/.well-known/openid-configuration
GET/oauth/authorize
POST/oauth/token
GET/oauth/userinfo

One integration. All your sign-in methods.

Example endpoints for a space using a custom domain.

04 / A little clarity

Good questions.
Straight answers.

Have something else in mind?
Talk to the people building it.

Citadel is the identity provider built by Combine. It handles sign-in, accounts and sessions for a group of applications, so each application can use a standard OpenID Connect identity instead of building its own authentication.

Built for what you’re building.

Bring your apps together.

Let’s give your people a simpler way in. Tell us about your applications. We’ll take it from there.