Skip to content
AuthMantraPraxis
authmantra.com ↗Start free trial
Praxis / Build / API reference

How workforce identity works in AuthMantra

AuthMantra is the identity provider for your workforce. Instead of a separate password for every application, people sign in once to AuthMantra and each application receives a signed statement of who they are. The same service provisions accounts from your HR system and keeps an audit log.

Hosted in India

Data is hosted in the Mumbai region (asia-south1), with customer-managed encryption keys, a private database and a web application firewall. See Trust & security for what is in place and what is not yet.

1. SAML 2.0

AuthMantra acts as a SAML 2.0 identity provider. An application (the service provider) redirects the person to AuthMantra, which authenticates them and returns a signed assertion. The application verifies the signature, the issuer, the audience and the validity window before creating a session. Pre-built connectors cover common SaaS apps; for others, the tenant-specific metadata and endpoints are supplied when you create the connection.

2. OpenID Connect and PKCE

For web, mobile and single-page apps, AuthMantra supports OpenID Connect using the authorization code flow with PKCE (RFC 7636). The application receives an ID token, a signed JWT. It should check the issuer, audience, expiry, signature and, where used, the nonce. Public keys are published as a JSON Web Key Set (RFC 7517) so signatures can be verified without a shared secret. The article Implementing OpenID Connect with PKCE correctly walks through the checks.

3. SCIM 2.0 provisioning

AuthMantra includes a SCIM 2.0 server (RFC 7643 and RFC 7644) that accepts users and groups from HR systems, and supports outbound SCIM provisioning to applications. When the HR record marks a person inactive, the change flows to connected apps. Read SCIM 2.0 in plain English for the model.

4. Passkeys and MFA

Sign-in supports passkeys (WebAuthn), including Face ID, Touch ID, Windows Hello, security keys and phones, plus authenticator-app codes (TOTP, RFC 6238) and SMS codes. The SMS provider integration is planned. Administrators are asked to re-authenticate before sensitive admin actions (step-up). Admins can see and revoke sessions.

5. Audit log and SIEM streaming

Sign-ins and administrative changes are written to an audit log that can be exported and viewed as a live feed. Events can be streamed to your SIEM through a signed webhook or Splunk HTTP Event Collector. See Streaming identity logs to your SIEM.

6. DPDP-oriented features

The Digital Personal Data Protection Act, 2023 sets duties for organisations that process personal data. AuthMantra provides tools that support those routines:

These tools do not by themselves make an organisation compliant. Check with your compliance counsel. A checklist is in the DPDP readiness guide.

7. API and SDKs

AuthMantra has an API with a documented OpenAPI description, SDKs for JavaScript, Python and Android, and an iOS app. Contact us for access to the API description for your workspace.