Enterprisesinglesign-on

Identity is brokered through Authentik and the platform control plane. Domain APIs never trust raw tenant headers from the internet — only gateway-signed identity.

Supportedfederationpatterns

  • OIDC upstream

    Entra ID, Okta, Google Workspace — configured as Authentik sources; console uses standard authorization code flow.

  • SAML upstream

    Enterprise SAML IdPs via Authentik; group attributes mapped to NeuroCluster roles.

  • Customer-only IdP

    Private deployment postures where the customer operates the identity provider and NeuroCluster is not in the authentication path.

  • Automation

    Platform-issued API keys for service accounts; separate from human SSO sessions.

Commondiligencequestions

Do domain APIs accept X-Tenant-ID directly from clients?
No in production. APIs run with strict identity verification: headers must be signed by the platform gateway after OIDC session validation.
Is SCIM supported?
Full SCIM is on the roadmap. Today, group mapping is handled in Authentik with platform org provisioning APIs for tenant lifecycle.
Can we use our own IdP without Authentik?
In customer-infrastructure postures, yes — the platform OIDC client can target your issuer directly; we document the exact claims and group mapping required.

Bring us one operational problem.

You do not need a finished brief. Bring the problem — we will work out the next step together.

Or book a call with the team