How workforce identity works in AuthMantra
AuthMantra is the identity provider for your workforce. Instead of a separate password for every application, people sign in once to AuthMantra and each application receives a signed statement of who they are. The same service provisions accounts from your HR system and keeps an audit log.
Hosted in India
Data is hosted in the Mumbai region (asia-south1), with customer-managed encryption keys, a private database and a web application firewall. See Trust & security for what is in place and what is not yet.
1. SAML 2.0
AuthMantra acts as a SAML 2.0 identity provider. An application (the service provider) redirects the person to AuthMantra, which authenticates them and returns a signed assertion. The application verifies the signature, the issuer, the audience and the validity window before creating a session. Pre-built connectors cover common SaaS apps; for others, the tenant-specific metadata and endpoints are supplied when you create the connection.
2. OpenID Connect and PKCE
For web, mobile and single-page apps, AuthMantra supports OpenID Connect using the authorization code flow with PKCE (RFC 7636). The application receives an ID token, a signed JWT. It should check the issuer, audience, expiry, signature and, where used, the nonce. Public keys are published as a JSON Web Key Set (RFC 7517) so signatures can be verified without a shared secret. The article Implementing OpenID Connect with PKCE correctly walks through the checks.
3. SCIM 2.0 provisioning
AuthMantra includes a SCIM 2.0 server (RFC 7643 and RFC 7644) that accepts users and groups from HR systems, and supports outbound SCIM provisioning to applications. When the HR record marks a person inactive, the change flows to connected apps. Read SCIM 2.0 in plain English for the model.
4. Passkeys and MFA
Sign-in supports passkeys (WebAuthn), including Face ID, Touch ID, Windows Hello, security keys and phones, plus authenticator-app codes (TOTP, RFC 6238) and SMS codes. The SMS provider integration is planned. Administrators are asked to re-authenticate before sensitive admin actions (step-up). Admins can see and revoke sessions.
5. Audit log and SIEM streaming
Sign-ins and administrative changes are written to an audit log that can be exported and viewed as a live feed. Events can be streamed to your SIEM through a signed webhook or Splunk HTTP Event Collector. See Streaming identity logs to your SIEM.
6. DPDP-oriented features
The Digital Personal Data Protection Act, 2023 sets duties for organisations that process personal data. AuthMantra provides tools that support those routines:
- Data export: export the data held about a person.
- Consent records: keep a record of what was agreed and when.
- Grievance workflow: a route for people to raise concerns about their data.
- India data residency: hosting in the Mumbai region.
These tools do not by themselves make an organisation compliant. Check with your compliance counsel. A checklist is in the DPDP readiness guide.
7. API and SDKs
AuthMantra has an API with a documented OpenAPI description, SDKs for JavaScript, Python and Android, and an iOS app. Contact us for access to the API description for your workspace.