Skip to main content

Modern identity control plane for applications, users, and AI agents.

O2 Identity gives your products a secure, polished sign-in experience out of the box — one place to manage applications, users, and access, so your teams stop rebuilding authentication from scratch for every new product. Run it yourself and keep full ownership of your users' data.

o2idctl

$ o2idctl users create --email jane@acme.com

user created id=usr_3f91a

$ o2idctl roles assign --user jane@acme.com --role admin

role assigned status=active

Authorize access

Allow access?

Acme CRM wants to read your profile and manage contacts.

AllowDeny
app.acme.com

Welcome back

Sign in to continue to your account

you@company.comContinueorContinue with single sign-on
Self-hosted, always

Run it in your own cloud or on-prem. Your users’ data never has to leave your infrastructure.

Open standards, no lock-in

OAuth 2.0 and OpenID Connect under the hood, so nothing about your integration is proprietary.

Built to grow with you

Start small with zero setup and scale up as you grow — your apps never notice the difference.

What's included

Everything an identity provider should ship with.

No add-ons, no upsells — role-based access, your own APIs, and your customers' identity providers all come standard.

Bring the providers you already use

Plug in your SMS or email provider, or let people sign in with Google, Microsoft, or their own enterprise SSO.

Built for B2B from day one

Give every customer their own organization, with admins who manage their own people — never anyone else’s.

Credentials that travel

Issue verifiable, cryptographically signed credentials people can present anywhere — no separate wallet infrastructure to run.

Scriptable, not clickable

There’s no admin console to click through — manage everything with the o2idctl CLI or the official SDKs, and check it into version control.

Sign-in experience

Sign-in that feels like part of your product.

Use O2 Identity’s embedded sign-in screen, styled to match your product, or host your own — either way, sessions, security, and login tracking are handled for you.

  • Embedded screen or your own hosted portal — you choose
  • Passwordless and single sign-on supported
  • Every session backed by open, auditable standards
app.acme.com

Welcome back

Sign in to continue to your account

you@company.comContinueorContinue with single sign-on
Access control

Every user, app, and agent — scoped to exactly what they need.

Role-based access control isn’t a paid add-on. Define roles, assign scopes, and protect your own APIs as resource servers — all from day one, all from the CLI.

  • Scopes are enforced on every token, not just checked at login
  • Register your own APIs as resource servers in minutes
  • Roles, scopes, and resource servers — all scriptable, no console required
o2idctl

$ o2idctl roles create --name billing-admin --scope invoices:read,invoices:write

role created id=role_7c2a

$ o2idctl resource-servers create --name billing-api --identifier https://api.acme.com/billing

resource server registered status=active

Identity for the AI era

Built for people — and the AI agents acting for them.

Your customers no longer show up alone. They send agents to research, buy, and negotiate on their behalf — and every one of them needs an identity you can trust.

Agent identity

Every agent gets a verifiable identity of its own.

O2 Identity issues AI agents their own credentials, tied to a mandate from a verified human — so automation never means anonymous, and delegation never means handing over the keys.

  • Every agent action traces back to the person who authorized it
  • Mandates are scoped and time-boxed — never blanket access
  • Revoke an agent instantly without touching the user's account
o2idctl

$ o2idctl agents create --name research-agent --scope users:read

agent created id=agt_8f2c1

$ o2idctl agents mandates create --agent research-agent --for jane@acme.com --ttl 2h

mandate issued expires=2h status=active

Continuous verification

Identity is checked on every action, not just once at the door — so a stolen session or a runaway agent gets caught in the act, not in next quarter’s audit.

Enterprise-grade integration

Provision and deprovision users automatically, and federate sign-in with the identity systems your enterprise customers already run — landing bigger deals without rebuilding auth.

Post-quantum ready

Cryptography that moves as standards do. Signing algorithms upgrade in place — including post-quantum ones — without breaking a single login.

Run your own identity plane in minutes.

Starts with zero setup, and scales to production the moment you need it to.

Get Started