Single sign-on for open-source apps
A self-hosted estate often grows one login at a time: a local admin in the file server, another in the automation tool, a shared password for the dashboard. Each one is a place where a leaver keeps access. The identity service replaces them with one sign-in, run by an identity provider your security team controls.
We connect each app over OIDC or SAML, test it with real accounts and only then retire its local passwords. Nextcloud, Open WebUI, LibreChat, Outline and Grafana are common first connections. Where an app reserves single sign-on for a paid edition, we tell you before you choose it.
Keycloak, Entra ID, or both
If you run Microsoft 365, you likely have Entra ID already, and connecting your apps to it keeps one directory and one set of policies. If you want the identity provider on your own machines, Keycloak runs on your premises or in Pilae Cloud, federates Active Directory or LDAP read-only, and can broker Entra ID sign-ins for organisations moving away from Microsoft gradually. Weighing it against a hosted provider? See the Okta alternative.
Joiners, movers and leavers that follow the directory
Roles come from groups. When HR adds a starter to a department group, the right apps open to them. When someone changes team, their group changes and so do their roles. When they leave, disabling one account ends sign-in to every connected app. Sign-in and admin events go to the audit log in the control plane and on to your SIEM.
Identity is also the front door of the private network: staff reach apps on the mesh only after they sign in. Read more on how we secure your apps, or contact us to scope single sign-on for your estate.