Modern identity control plane for applications, users, and AI agents.
O2 Identity gives your products a secure, polished sign-in experience out of the box — one place to manage applications, users, and access, so your teams stop rebuilding authentication from scratch for every new product. Run it yourself and keep full ownership of your users' data.
$ o2idctl users create --email jane@acme.com
user created id=usr_3f91a
$ o2idctl roles assign --user jane@acme.com --role admin
role assigned status=active
Allow access?
Acme CRM wants to read your profile and manage contacts.
Welcome back
Sign in to continue to your account
you@company.comorContinue with single sign-onRun it in your own cloud or on-prem. Your users’ data never has to leave your infrastructure.
OAuth 2.0 and OpenID Connect under the hood, so nothing about your integration is proprietary.
Start small with zero setup and scale up as you grow — your apps never notice the difference.
What's included
Everything an identity provider should ship with.
No add-ons, no upsells — role-based access, your own APIs, and your customers' identity providers all come standard.
Bring the providers you already use
Plug in your SMS or email provider, or let people sign in with Google, Microsoft, or their own enterprise SSO.
Built for B2B from day one
Give every customer their own organization, with admins who manage their own people — never anyone else’s.
Credentials that travel
Issue verifiable, cryptographically signed credentials people can present anywhere — no separate wallet infrastructure to run.
Scriptable, not clickable
There’s no admin console to click through — manage everything with the o2idctl CLI or the official SDKs, and check it into version control.
Sign-in that feels like part of your product.
Use O2 Identity’s embedded sign-in screen, styled to match your product, or host your own — either way, sessions, security, and login tracking are handled for you.
- Embedded screen or your own hosted portal — you choose
- Passwordless and single sign-on supported
- Every session backed by open, auditable standards
Welcome back
Sign in to continue to your account
you@company.comorContinue with single sign-onEvery user, app, and agent — scoped to exactly what they need.
Role-based access control isn’t a paid add-on. Define roles, assign scopes, and protect your own APIs as resource servers — all from day one, all from the CLI.
- Scopes are enforced on every token, not just checked at login
- Register your own APIs as resource servers in minutes
- Roles, scopes, and resource servers — all scriptable, no console required
$ o2idctl roles create --name billing-admin --scope invoices:read,invoices:write
role created id=role_7c2a
$ o2idctl resource-servers create --name billing-api --identifier https://api.acme.com/billing
resource server registered status=active
Identity for the AI era
Built for people — and the AI agents acting for them.
Your customers no longer show up alone. They send agents to research, buy, and negotiate on their behalf — and every one of them needs an identity you can trust.
Every agent gets a verifiable identity of its own.
O2 Identity issues AI agents their own credentials, tied to a mandate from a verified human — so automation never means anonymous, and delegation never means handing over the keys.
- Every agent action traces back to the person who authorized it
- Mandates are scoped and time-boxed — never blanket access
- Revoke an agent instantly without touching the user's account
$ o2idctl agents create --name research-agent --scope users:read
agent created id=agt_8f2c1
$ o2idctl agents mandates create --agent research-agent --for jane@acme.com --ttl 2h
mandate issued expires=2h status=active
Continuous verification
Identity is checked on every action, not just once at the door — so a stolen session or a runaway agent gets caught in the act, not in next quarter’s audit.
Enterprise-grade integration
Provision and deprovision users automatically, and federate sign-in with the identity systems your enterprise customers already run — landing bigger deals without rebuilding auth.
Post-quantum ready
Cryptography that moves as standards do. Signing algorithms upgrade in place — including post-quantum ones — without breaking a single login.
Run your own identity plane in minutes.
Starts with zero setup, and scales to production the moment you need it to.