Customer Identity Platform

Customer identity,
made clear.

SeeAuth is a complete CIAM platform — authentication, federation, and multi-tenant administration — running live right now, with nothing to sign up for and nothing to wait on.

Passkey verified
Live sandbox you can click through
Self-hosted — your infrastructure, your data
Standards-based — OIDC & SAML
Multi-tenant since day one
What's inside

Everything a real identity platform needs — already built.

Not a roadmap. Every capability below is running in the live sandbox today.

Authentication & MFA

Password and passkey sign-in, magic links, social login, and adaptive risk-based checks — built to keep real accounts safe, not just check a box.

Passkeys / WebAuthn Magic link Breached-password check Adaptive CAPTCHA

Federation & SSO

Full OIDC and SAML, in both directions — be the identity provider for your customers or federate out to theirs, including legacy Artifact Binding.

OIDC + PKCE SAML IdP & SP Back-channel logout Dynamic client reg.

Multi-tenant SaaS, built in

Every tenant gets its own subdomain, its own admins, and its own subscription tier — provisioned in seconds, isolated by design, not bolted on later.

Subdomain routing Self-service provisioning Custom domains Tiered feature gating

Admin & automation

A real administration console plus a public API — RBAC, groups, SCIM provisioning, outbound webhooks, and a visual policy engine for custom sign-in flows.

SCIM 2.0 Webhooks Public Management API Policy engine

Security & compliance

Internal service calls run over mutual TLS, every action is audited, and your customers can export or erase their own data on demand.

Mutual TLS mesh Full audit trail DSAR export / erase Consent tracking

Legacy system migration

Move users off an old identity system without a hard cutover — accounts migrate quietly the moment each person signs in, on your own schedule.

Just-in-time migration Any HTTPS legacy backend Automated retirement
One platform, three surfaces

Every audience gets the interface it actually needs.

Your customers, your tenant admins, and your own platform team never share a screen — each gets an interface purpose-built for what they're actually doing.

SeeAuthCustomer
SeeAuth ControlTenant admin
4,812
Users
99.98%
Sign-in success
12
Applications
3
Federation partners
SeeAuth OperatorPlatform ops
Internal staff only
northwind.seeauth.comActive
lumen-retail.seeauth.comActive
forge-labs.seeauth.comTrial
atlas-health.seeauth.comActive

Illustrative — not live data. Explore the real thing in the sandbox linked above.

How it fits together

Identity, moving through a protected boundary.

01

Your application

Redirects to SeeAuth using standard OIDC or SAML — no proprietary SDK to integrate.

02

SeeAuth verifies

Password, passkey, or federated login, plus adaptive risk checks — resolved to the right tenant automatically.

03

A trusted session

Your app receives a signed token, scoped to that one tenant — with nothing else on the platform visible to it.

For developers

Open standards, no lock-in.

Discovery documents, real OIDC/SAML metadata, and a public Management API — built the way you'd build it yourself, on a stack that's easy to reason about.

.NET Angular PostgreSQL Redis Cosmos DB SCIM 2.0
GET /.well-known/openid-configuration

{
  "issuer": "https://northwind.seeauth.com/",
  "authorization_endpoint": ".../connect/authorize",
  "token_endpoint": ".../connect/token",
  "scopes_supported": ["openid", "profile", "email"]
}

See it for yourself.

No signup walls, no sales calls — the sandbox is live and waiting.