Enterprise
Enterprise controls, self-hosted
Organizations, SSO, directory sync and audit export in the same MIT-licensed library as agent identity. You run it, so the data stays in your database.
Enterprise datasheet
Identity and access
- Organizations and RBAC
- Create orgs, invite members, assign roles, enforce per-org RBAC, cap members and orgs per user. Docs.
- SAML 2.0 and OIDC SSO
- Connections for providers such as Okta and Azure AD, with just-in-time provisioning and routing by email domain. Docs.
- SCIM 2.0
- Directory sync from Okta, Azure AD and Google Workspace, authenticated with a bearer token. Docs.
- Admin controls
- List users, permanent or time-limited bans, impersonation for support, user deletion. Docs.
- API keys
- Scoped keys you create, validate, revoke and rotate. Docs.
- Tenant tagging
- Agents carry a tenantId and can be listed by it. theAuth does not enforce isolation between tenants for you, so scope your own resource checks. Docs.
Audit and data
- Audit export
- TypeScript exports JSON or CSV. Go streams to sinks: Splunk HEC, OTLP and a generic CloudEvents webhook.
- GDPR tools
- Self-service export, delete and anonymize endpoints. Your policies and processor agreements stay your responsibility. Docs.
- Compliance mapping
- Documentation maps audit fields to EU AI Act, NIST, SOC 2 and ISO 42001 controls, as mapping and evidence. It is not a certification. Docs.
Go also ships a SAML 2.0 service provider, SCIM 2.0 and RBAC. See the Go package.
sink, err := splunkhec.New("https://splunk.example.com:8088", os.Getenv("SPLUNK_HEC_TOKEN"))
if err != nil {
log.Fatal(err)
}
a, _ := theauth.New(theauth.Config{
Storage: store,
BaseURL: "https://myapp.com",
Audit: &theauth.AuditConfig{
Sinks: []theauth.AuditSink{sink},
},
})
Audit export
Stream audit events to your SIEM
The Go audit log is append-only and asynchronous. If the buffer fills, events are dropped and counted rather than slowing sign-in. A failing sink never blocks storage writes.
Compliance mapping
Mapped, not certified
These are evidence aids for your own assessment. theAuth holds no certification against any of them.
- EU AI ActAudit records for record-keeping (Article 12), approval gates and depth limits for human oversight (Article 14).mapping
- NISTIdentity provenance, least-privilege permissions, revocation and expiry, audit trail.mapping
- SOC 2Access control, agent limits, role-based grants and event logging mapped to CC6 and CC7.mapping
- ISO 42001Logged inputs, results and durations mapped to Annex A.8.mapping
No sales channel is documented. Questions about enterprise needs go to GitHub Discussions. Pricing is on the pricing page.
Get started
Give your first agent an identity.
Install the package, create an agent with scoped permissions, and read its first audit record. The core runs on Postgres, SQLite, MySQL or D1, and the Go module needs a single go get.
npm install @glinr/theauthgo get github.com/glincker/theauth-go