One identity forge for every application you ship.

WeldForge is a multi-tenant identity platform that unifies workforce SSO, customer sign-in, API authentication and internal PKI behind a single, audit-first backend. Built on open standards — OAuth 2.0, OIDC, SAML 2.0, SCIM 2.0 — and designed so a small team can run it without compromising on compliance.

What it is, in one screen

WeldForge consolidates the pieces every company otherwise stitches together from three vendors: an identity provider, a directory sync service, and a secrets & certificate backend. Each capability is tenant-isolated by default, so you can run one installation that serves several organisations — or a single business with strict separation between dev, staging and production.

Standards-firstOAuth 2.0, OIDC, SAML 2.0, SCIM 2.0, WebAuthn.
Multi-tenantEvery query is tenant-scoped from the database up.
Audit-firstAppend-only log with webhook fan-out for every event.
ResilientCircuit breakers on every external dependency.

Choose your application

WeldForge is organised around the outcomes you need, not the protocols underneath. Pick the scenario that fits and the platform takes care of the plumbing.

Workforce

Workforce SSO

Give your staff one sign-on for every internal tool. SAML and OIDC for apps, LDAP/AD for the directory you already run, MFA enforced by policy.

Read more →
Customer

Customer Identity

Registration, social login, MFA, password reset, email verification. A complete CIAM stack that your product teams integrate in an afternoon.

Read more →
API

API & M2M Authentication

API keys with path and method scopes, service-account tokens, OAuth 2.0 client credentials, mutual TLS. Secure backend-to-backend calls without reinventing key rotation.

Read more →
Certificates

Internal PKI

Run your own certificate authority per tenant. Issue client certs for mTLS, publish a CRL, answer OCSP queries, get renewal warnings 30/14/7/1 days before expiry.

Read more →
Compliance

Compliance & Observability

Every authentication, admin action and lifecycle event lands in an append-only audit log. Subscribe to the webhook stream for SIEM, GRC or custom downstream workflows.

Read more →
Integrations

Directory & CRM sync

Pull users from LDAP or Active Directory on login. Push identities to Salesforce or HubSpot after sign-in. Configurable field mappings, no code required.

Read more →

What's in the box

A non-exhaustive snapshot of the capabilities shipped today. Every item is covered by an automated BDD test suite before it reaches production.

Authentication

  • Password + MFA (TOTP, SMS OTP, WebAuthn, backup codes)
  • Per-tenant MFA enrolment & step-up policies
  • OAuth 2.0 social login (Google, Microsoft, GitHub, Apple, …)
  • SAML 2.0 federation as SP and IdP
  • LDAP / Active Directory upstream

Authorisation & tokens

  • OIDC issuer with per-tenant signing keys
  • Admin RBAC (SUPER_ADMIN / TENANT_ADMIN / READ_ONLY / NONE)
  • Hashed, single-reveal API keys with path + method scopes
  • Service-account tokens for M2M without OAuth2
  • Per-tenant custom JWT claims and session TTL

Provisioning & federation

  • SCIM 2.0 for Users and Groups
  • Group-to-role binding with priority resolution
  • JSONPath claim transforms + ordered matching rules
  • CRM push to Salesforce / HubSpot / Dynamics / Pipedrive

Platform & ops

  • Outbound webhooks, HMAC-signed, with retry + dead-letter
  • Internal CA, CRL and OCSP per tenant
  • Resilience4j circuit breakers on every downstream
  • Prometheus metrics, liveness/readiness probes, graceful shutdown
Built on open standards WeldForge does not invent a new wire protocol. Every capability maps to an RFC or OASIS specification — so the clients, SDKs and tooling you already know just work. Want to swap WeldForge out later? Your applications don't need to change.