Enterprise

Enterprise controls, self-hosted

Organizations, SSO, directory sync and audit export in the same MIT-licensed library as agent identity. You run it, so the data stays in your database.

Enterprise datasheet

DatasheetTypeScript core unless noted

Identity and access

Organizations and RBAC
Create orgs, invite members, assign roles, enforce per-org RBAC, cap members and orgs per user. Docs.
SAML 2.0 and OIDC SSO
Connections for providers such as Okta and Azure AD, with just-in-time provisioning and routing by email domain. Docs.
SCIM 2.0
Directory sync from Okta, Azure AD and Google Workspace, authenticated with a bearer token. Docs.
Admin controls
List users, permanent or time-limited bans, impersonation for support, user deletion. Docs.
API keys
Scoped keys you create, validate, revoke and rotate. Docs.
Tenant tagging
Agents carry a tenantId and can be listed by it. theAuth does not enforce isolation between tenants for you, so scope your own resource checks. Docs.

Audit and data

Audit export
TypeScript exports JSON or CSV. Go streams to sinks: Splunk HEC, OTLP and a generic CloudEvents webhook.
GDPR tools
Self-service export, delete and anonymize endpoints. Your policies and processor agreements stay your responsibility. Docs.
Compliance mapping
Documentation maps audit fields to EU AI Act, NIST, SOC 2 and ISO 42001 controls, as mapping and evidence. It is not a certification. Docs.

Go also ships a SAML 2.0 service provider, SCIM 2.0 and RBAC. See the Go package.

SSO connections link an organization to an identity provider over SAML 2.0 or OIDC, and a SCIM 2.0 endpoint takes users and groups from the customer's directory. Agents can carry a tenantId so you can list them by tenant; enforcing tenant boundaries stays in your own resource checks.
audit.go
sink, err := splunkhec.New("https://splunk.example.com:8088", os.Getenv("SPLUNK_HEC_TOKEN"))
if err != nil {
    log.Fatal(err)
}

a, _ := theauth.New(theauth.Config{
    Storage: store,
    BaseURL: "https://myapp.com",
    Audit: &theauth.AuditConfig{
        Sinks: []theauth.AuditSink{sink},
    },
})

Audit export

Stream audit events to your SIEM

The Go audit log is append-only and asynchronous. If the buffer fills, events are dropped and counted rather than slowing sign-in. A failing sink never blocks storage writes.

Compliance mapping

Mapped, not certified

These are evidence aids for your own assessment. theAuth holds no certification against any of them.

  • EU AI ActAudit records for record-keeping (Article 12), approval gates and depth limits for human oversight (Article 14).mapping
  • NISTIdentity provenance, least-privilege permissions, revocation and expiry, audit trail.mapping
  • SOC 2Access control, agent limits, role-based grants and event logging mapped to CC6 and CC7.mapping
  • ISO 42001Logged inputs, results and durations mapped to Annex A.8.mapping
Contact

No sales channel is documented. Questions about enterprise needs go to GitHub Discussions. Pricing is on the pricing page.

Get started

Give your first agent an identity.

Install the package, create an agent with scoped permissions, and read its first audit record. The core runs on Postgres, SQLite, MySQL or D1, and the Go module needs a single go get.

  • npm install @glinr/theauth
  • go get github.com/glincker/theauth-go
Or skip hosting with theAuth Cloud