One identity forge for every application you ship.
WeldForge is a multi-tenant identity platform that unifies workforce SSO, customer sign-in, API authentication and internal PKI behind a single, audit-first backend. Built on open standards — OAuth 2.0, OIDC, SAML 2.0, SCIM 2.0 — and designed so a small team can run it without compromising on compliance.
What it is, in one screen
WeldForge consolidates the pieces every company otherwise stitches together from three vendors: an identity provider, a directory sync service, and a secrets & certificate backend. Each capability is tenant-isolated by default, so you can run one installation that serves several organisations — or a single business with strict separation between dev, staging and production.
Choose your application
WeldForge is organised around the outcomes you need, not the protocols underneath. Pick the scenario that fits and the platform takes care of the plumbing.
Workforce SSO
Give your staff one sign-on for every internal tool. SAML and OIDC for apps, LDAP/AD for the directory you already run, MFA enforced by policy.
Read more →Customer Identity
Registration, social login, MFA, password reset, email verification. A complete CIAM stack that your product teams integrate in an afternoon.
Read more →API & M2M Authentication
API keys with path and method scopes, service-account tokens, OAuth 2.0 client credentials, mutual TLS. Secure backend-to-backend calls without reinventing key rotation.
Read more →Internal PKI
Run your own certificate authority per tenant. Issue client certs for mTLS, publish a CRL, answer OCSP queries, get renewal warnings 30/14/7/1 days before expiry.
Read more →Compliance & Observability
Every authentication, admin action and lifecycle event lands in an append-only audit log. Subscribe to the webhook stream for SIEM, GRC or custom downstream workflows.
Read more →Directory & CRM sync
Pull users from LDAP or Active Directory on login. Push identities to Salesforce or HubSpot after sign-in. Configurable field mappings, no code required.
Read more →What's in the box
A non-exhaustive snapshot of the capabilities shipped today. Every item is covered by an automated BDD test suite before it reaches production.
Authentication
- Password + MFA (TOTP, SMS OTP, WebAuthn, backup codes)
- Per-tenant MFA enrolment & step-up policies
- OAuth 2.0 social login (Google, Microsoft, GitHub, Apple, …)
- SAML 2.0 federation as SP and IdP
- LDAP / Active Directory upstream
Authorisation & tokens
- OIDC issuer with per-tenant signing keys
- Admin RBAC (SUPER_ADMIN / TENANT_ADMIN / READ_ONLY / NONE)
- Hashed, single-reveal API keys with path + method scopes
- Service-account tokens for M2M without OAuth2
- Per-tenant custom JWT claims and session TTL
Provisioning & federation
- SCIM 2.0 for Users and Groups
- Group-to-role binding with priority resolution
- JSONPath claim transforms + ordered matching rules
- CRM push to Salesforce / HubSpot / Dynamics / Pipedrive
Platform & ops
- Outbound webhooks, HMAC-signed, with retry + dead-letter
- Internal CA, CRL and OCSP per tenant
- Resilience4j circuit breakers on every downstream
- Prometheus metrics, liveness/readiness probes, graceful shutdown