Integrations — what it works with
It fits what you already run.
Each is in the binary, switched on by a setting, and proven by a named test. What your systems send is verified before it is read; what AuthBox decides never leaves as a claim.
Sign-in for your applications
OpenID Connect and SAML
Your web applications log people in with the certificate they already hold. An OpenID Connect provider with PKCE and certificate-bound tokens; a SAML 2.0 identity provider for the applications that speak nothing newer. SAML, explained →
Provisioning
SCIM, LDAP and Active Directory
Joiners and leavers arrive from the system that already knows them: a SCIM 2.0 adapter pulling from a directory or taking a push from Okta or Entra, an LDAP connector for Active Directory. Each runs outside and produces one signed bundle, all AuthBox takes in.
Certificates and hardware
ACME, EST, OCSP, CRLs, HSMs
Enrol servers over ACME with device attestation, or devices over EST. Revocation over OCSP and CRLs. Keys in a PKCS#11 hardware module, and post-quantum ML-DSA certificates beside the classical set.
Policy and signals
AuthZEN, Rego, Cedar, CAEP
Ask the decision as an API (OpenID AuthZEN), export the policy as Rego or Cedar for the engine you run, and let your other systems learn of revocations and lapses as shared signals (CAEP). Or take those answers in your own API's shape, from your OpenAPI document and a mapping proved at load.
Data and labels
OpenTDF, STANAG 4774
Classified responses labelled per request and sealed to a key access service that releases a data key only to a caller cleared for it; NATO confidentiality labels translated at the seam rather than re-modelled.
Object storage
S3, sealed, per mission
A separate add-on that holds the files so AuthBox never does. A bucket is a mission ↓
Shell and infrastructure
SSH, Kubernetes, DNS
An SSH certificate authority for your hosts and cluster nodes, SSH through the door by name, an ingress mode that follows your Kubernetes Services, and authoritative DNS with DNSSEC for a federation's names. SSH, explained →
Operations
Prometheus, your SIEM, PostgreSQL
Metrics in Prometheus form, structured logs, a signed audit export your SIEM can prove it received, a transparency log, and a store on files, PostgreSQL or MySQL.