Trust / SSO
Enterprisesinglesign-on
Identity is brokered through Authentik and the platform control plane. Domain APIs never trust raw tenant headers from the internet — only gateway-signed identity.
Supportedfederationpatterns
OIDC upstream
Entra ID, Okta, Google Workspace — configured as Authentik sources; console uses standard authorization code flow.
SAML upstream
Enterprise SAML IdPs via Authentik; group attributes mapped to NeuroCluster roles.
Customer-only IdP
Private deployment postures where the customer operates the identity provider and NeuroCluster is not in the authentication path.
Automation
Platform-issued API keys for service accounts; separate from human SSO sessions.
Commondiligencequestions
- Do domain APIs accept X-Tenant-ID directly from clients?
- No in production. APIs run with strict identity verification: headers must be signed by the platform gateway after OIDC session validation.
- Is SCIM supported?
- Full SCIM is on the roadmap. Today, group mapping is handled in Authentik with platform org provisioning APIs for tenant lifecycle.
- Can we use our own IdP without Authentik?
- In customer-infrastructure postures, yes — the platform OIDC client can target your issuer directly; we document the exact claims and group mapping required.
Bring us one operational problem.
You do not need a finished brief. Bring the problem — we will work out the next step together.
Or book a call with the team