Identity infrastructure, without compromise

Control every
identity decision.

Authentication, federation, lifecycle and fine-grained authorization in one extensible platform—delivered as SaaS or deployed inside your infrastructure.

  • 01 Multi-tenant by design
  • 02 Protocol compliant
  • 03 Deploy anywhere
Runtime live auth.heimdall.local •••

Identity signal

VERIFIED
ACCESS DECISION12 ms
JDPrincipaljane@northstar.io
Authentication
Passkey
Risk level
Low · 0.08
Policy
workspace.editor
Relationship
member → project
DecisionALLOW
BUILT ON OPEN STANDARDS OAuth 2.1OpenID ConnectSAML 2.0SCIM 2.0WebAuthn
01 / PLATFORM

One control plane.
Every identity surface.

Heimdall keeps administration and runtime execution deliberately separate. Teams configure, publish and observe centrally while login and authorization remain fast, isolated and resilient.

ADAPTIVE AUTHENTICATION

Compose the right sign-in for every context.

Build versioned login flows with passwords, OTP, passkeys and enterprise federation. Apply pre-login rules and step-up authentication without rebuilding the application.

  • Visual flow orchestration
  • Custom hosted and headless experiences
  • Risk-aware step-up decisions
02 / CAPABILITIES

Identity primitives.
Product-ready.

Use Heimdall as a complete platform or adopt the capabilities your architecture needs. Each domain has explicit boundaries and stable contracts.

02
AUTHORIZATION

Decisions beyond roles

Combine RBAC, ABAC and relationship-based policies with context, obligations and custom decision strategies.

03
FEDERATION

Enterprise connections

Broker trusted OIDC and SAML connections with domain discovery, bounded claim mapping and safe account linking.

04
LIFECYCLE

SCIM-native provisioning

Synchronize users and groups through a tenant-scoped SCIM 2.0 surface with lifecycle-aware identity storage.

Directory syncHEALTHY
05
EXPERIENCE

Your brand, your flow

Design localized hosted login pages on a free canvas, publish immutable versions and bind them per application.

06
SECURITY & AUDIT

Evidence you can act on

Capture append-only audit evidence, session activity, risk signals and operational telemetry without exposing secrets.

authentication.succeeded
03 / ARCHITECTURE

Built to evolve
without breaking trust.

Seventeen bounded domain modules begin as a modular application. Runtime roles can scale independently when topology, ownership or release cadence demands it.

  • 01
    Explicit boundaries

    Modules communicate through APIs, commands, queries and durable events—not shared internal tables.

  • 02
    Fail-closed runtime

    Published immutable configuration keeps authentication available when the control plane is not.

  • 03
    Extract when proven

    Move a module into a service only when independent scale or isolation justifies the operational cost.

HEIMDALL / SYSTEM MAP HEALTHY
ENTRY SURFACES
Admin ConsoleHosted LoginManagement API
RUNTIME ROLES
ManagementIdentity RuntimeAuthorizationWorker
DOMAIN CORE
IdentityAuthenticationFederationAuthorizationExperienceFlow EngineRiskAudit
DATA & EVENTS
PostgreSQLRedisOutboxOpenTelemetry
04 / DEPLOYMENT

Your identity plane.
Your operating model.

Keep the same contracts and operational model across managed and customer-controlled environments.

MANAGED

Heimdall SaaS

Operate identity without owning the platform infrastructure. Isolated tenant configuration with managed upgrades and operations.

  • Fastest path to production
  • Managed availability and upgrades
  • Regional deployment options
CUSTOMER CONTROLLED

Private cloud & on-prem

Run Heimdall inside your network and security boundary using the same product capabilities and deployment roles.

  • Your cloud or data centre
  • External secrets and key custody
  • Private observability and audit
HYBRID

Split control and runtime

Place latency-sensitive authentication and authorization close to applications while centralizing safe configuration workflows.

  • Independent runtime scaling
  • Immutable published snapshots
  • Resilient control-plane separation
SECURITY BY CONSTRUCTION

Trust is a system property.

Tenant isolation, bounded configuration, encrypted secrets, replay protection, transactional audit evidence and fail-closed provider contracts are part of the architecture—not optional add-ons.

AES-256-GCMSecret protectionPKCE + NONCEProtocol defenceIMMUTABLEPublished versions
THE GATEWAY IS YOURS

Identity infrastructure
on your terms.

Build branded authentication, enterprise federation and fine-grained authorization on one coherent platform.