Identity
One sign-in, one permission model, for every Garuda product
Garuda Identity is the OpenID Connect authority behind every product — members, tenants, roles, fine-grained permissions, subscriptions and audit, managed once.
- Built for
- Every organization using a Garuda product, and every Garuda product itself.
- Where it runs
- Admin portal for tenant and platform administrators
- OpenID Connect issuer for web, mobile and service clients
In the product
Capabilities
What Identity does
-
Tenants and sub-tenants
An organization is a tenant. Its branches, institutes or centres are sub-tenants. Products read that structure from Identity and never keep a copy.
-
Roles built from permissions
Each product publishes a catalogue of permissions. Tenants compose roles from it, and a member's token carries exactly the permissions that role grants.
-
Subscriptions and tiers
A tenant is entitled to a product through a subscription. No subscription, no sign-in — enforced by Identity before the product is ever reached.
-
Guardians and consent
A guardian can be linked to a minor member, and parental consent is recorded before a product processes the minor's data.
-
Central audit
Sign-ins, invitations, role changes and permission grants are recorded once, in one place, for every product.
Why products do not own their users
Every Garuda product is multi-tenant and shares customers with the others. If each product kept its own users and roles, an organization would manage the same people three times and the products could never trust each other’s claims. Identity is the single authority, and each product holds no user record, role or grant of its own.
Standard protocol, no lock-in
Identity is a standards-based OpenID Connect server. Web apps use authorization code with PKCE, native apps use the same flow, and automated services authenticate as service principals. Anything that speaks OIDC can be a client.
Where Identity sits
Every Garuda product shares one identity and one engineering foundation. The lit edges are Identity's.