Identity Plane

Identity that carries context, not just a login.

Alpin Insight Identity Plane gives people, applications, gateways, and service clients one standards-based issuer with Organization context, governed scopes, and auditable access assignments.

Standards-first identity

  • OpenID Connect and OAuth 2.0
  • PKCE and Dynamic Client Registration
  • JWT, JWKS, scopes, and resource indicators
  • MFA, passkeys, social login, and SAML

One issuer, clear ownership

Built for a product ecosystem, not a single application.

Organization-aware access

Stable Organization claims and roles travel with the session without conflating provider administration, product roles, or Django Groups.

Developer self-service

Teams register clients, rotate secrets, restrict scopes, and review their contracts through governed product journeys.

Gateway-ready authorization

Scopes and capability bundles give Istio, Envoy, oauth2-proxy, MCP gateways, and APIs precise values to enforce.

Operational evidence

Audits, contract checks, lifecycle controls, and UAT evidence make access changes reviewable across repositories.

Clear security boundaries

The provider issues identity. Other systems enforce and decide.

People and workloads Browser users, apps, agents, service clients
Alpin Insight Identity Plane Identity, clients, claims, scopes, audit
Gateway and policy Istio, Envoy, oauth2-proxy enforce route rules
Product services Entitlements and resource decisions

Start with your journey

Documentation for the people who operate and integrate identity.

Application developers

Register an OIDC client and integrate a relying party.

Platform operators

Run the issuer, audit access, and prove deployment readiness.