Appdirs AuthX
The identity engine is ours.
AuthX governs application, machine, network-device and privileged-server identity from one platform — written in-house on public standards, deployed on your premises, with no third-party identity product at its core.
Four identity planes. One engine.
Most estates run three or four separate products to cover these four. Here it is one engine, sharing one identity store, one role model and one audit trail.
Application identity
Every application, whatever it speaks.
Federation for anything modern, an LDAP interface for what is not, and credential vaulting for the applications that can do neither.
Machine identity
Machine identity issued by the same platform that governs people.
An X.509 certificate authority for your fleet, with issuance rules per certificate class and revocation published to the estate.
Network-device administration
Routers and switches, on the same identity store and the same audit trail.
RADIUS and TACACS+ with shell and per-command authorization and accounting, one privilege resolver across both, and a fail-safe to local authentication.
Privileged server access
Servers, without standing keys.
An ephemeral OpenSSH certificate after you sign in, mapped to a principal — no standing key on the host, and no proxy in the path.
one identity store
one role model
one audit trail
One engine. Every standard it needs to speak.
The OpenID Connect and OAuth 2.1 provider, the SAML 2.0 and WS-Federation identity providers, the RADIUS and TACACS+ servers, the LDAP interface, the SSH certificate authority and the X.509 fleet CA are our own code, built to the published standards and tested against production-grade network hardware.
Application identity
Directory and MFA
Network-device administration
Machine identity and servers
Select a standard to see what AuthX does with it.
Servers, without standing keys.
Sign in and a short-lived OpenSSH certificate is issued against your principal. When it expires the host is left holding nothing — there was never a key on it to rotate, leak or forget.
Sign in, and a certificate is issued.
An issuance record showing short-lived certificates issued against a principal.
Use it. Nothing sits in the path.
The certificates are in use, connecting directly with no proxy in the path.
It expires, and the host holds nothing.
The last certificate has expired and its on-host column shows nothing remaining.
What it does, stated as what you get.
Each line below is a capability we would sign for in a tender, written as the outcome rather than the feature.
- Organizations and delegation
- Departments as child organizations to any depth, scoped by enforced database constraints rather than application convention, with administrative reach that only ever points downward.
- Roles and permissions
- Flat roles definable at system, organization or application scope, over permission catalogues the applications own — and an effective-permission answer that reports which tier decided it, so access can be explained to an auditor.
- Tokens and sessions
- RS256 signing over a rotating, key-id-aware key set; refresh-token rotation that revokes the whole family on replay; and private-key JWT as the default client authentication, so no shared secret lives in production.
- Multi-factor authentication
- Passkeys, security keys and time-based codes, enforced per organization by scope — all users, administrators only, or off — with a per-application allow-list of sign-in methods.
- Directory and provisioning
- Users and groups read from Active Directory or OpenLDAP, or delivered over SCIM by an agent that runs inside your network and connects outward — so no inbound firewall exception is needed.
- Audit
- An append-only trail on a time-partitioned store built for long retention, queryable through a filtered API, and written as structured machine-parsable logs your own log platform can ingest.
- Deployment
- A native operating-system package that bundles its own runtime and installs on a clean server with no interpreter and no Internet, or containers including rootless — with an application tier that runs highly available behind your load balancer.
Yours to run, with nothing phoning home.
- Activates offline from a signed licence file, with no network path to us.
- No licence heartbeat, no phone-home, no telemetry.
- Verifies its own integrity at start-up, and refuses to run if it has been modified.
Every line of the backend is covered by an automated test, and the build refuses to pass below the gate we set — a gate we enforce, not a figure we assert.
Kestryn hunts. Vestryn tracks. Prospica foresees. AuthX governs.
AuthX is the identity and access member of the Appdirs security family, alongside Kestryn for exposure management and MDM for devices.