Single sign-on
One session across every application.
Users sign in once and move between applications without re-authenticating. Sessions are managed centrally with configurable lifetimes and single logout.
Loading...
Everything Key can do — the full feature catalog.
One session across every application.
Users sign in once and move between applications without re-authenticating. Sessions are managed centrally with configurable lifetimes and single logout.
Companies, teams and memberships as first-class objects.
Model customer companies natively: each organization has its own members, roles and optional identity provider, isolated from every other tenant.
Customers bring their corporate login (OIDC/SAML).
Each organization can federate its own identity provider. Users are routed by e-mail domain and arrive with the correct membership — passwords stay with the customer.
MFA, brute-force protection, password policies.
Time-based one-time codes, per-realm MFA requirements, brute-force detection with progressive lockout and configurable password complexity rules.