Feature

API and app security

Protect modern, legacy and custom applications with the same access layer.

  • SAML 2.0, OIDC and OAuth 2.0
  • JWT-SSO handoff for custom apps
  • Browser extension for legacy apps
  • Per-app certificates and callback details

What it does

Cover standard protocols

Modern applications can use SAML 2.0, OIDC or OAuth 2.0, with the protocol chosen and configured per application rather than once for the whole tenant.

Support custom handoff flows

JWT-SSO redirect mode gives custom applications a simpler handoff when a full federation setup is not the right fit.

Do not leave legacy apps outside

The browser extension brings non-federated applications into the same launcher and access model.

Keep configuration per application

Certificates, reply URLs and vendor-side details live on each app entry so setup stays traceable.

Setting it up

What the rollout looks like

Choose the app type

Pick SAML, OIDC, OAuth, JWT-SSO or browser extension.

Add protocol details

Enter callback, certificate and vendor-side configuration details.

Assign access

Grant the app to the right roles, groups or departments.

Test and publish

Verify sign-in before making the app visible to users.

Questions about api and app security

Can custom apps be added?

Yes. Custom applications can be published with the protocol or handoff pattern they support, then assigned like any other app.

One sign-in for every app your team uses.

Set up your organisation, connect your directory and give your people a single secure launchpad.