Skip to main content
Straventa

Evaluating Accounts against Okta, Entra ID, Keycloak, or on-prem Active Directory?

Read the SSO comparison
All product lines
AccountsAvailable

Accounts

Straventa Accounts is the identity plane behind the estate: a multi-tenant OpenID Connect provider with single sign-on, OIDC client management, and step-up MFA. Every Straventa product authenticates against it, and you can register your own applications as OIDC relying parties — run it at accounts.straventa.com or deploy it on your own Kubernetes or Docker, where identity records, sessions, and authentication logs never leave your environment.

At a glance

Self-hosted single sign-on — a multi-tenant OpenID Connect provider that runs inside your own infrastructure, licensed per deployment rather than per employee.

Deployed on your own Kubernetes or Docker. Identity data, sessions, and authentication logs stay inside your environment. Security posture and control evidence: /security.

What it does

Built for the work, end to end

OpenID Connect provider
A standards-based OIDC / OAuth 2.0 identity provider — authorization code with PKCE, discovery, and a JWKS endpoint any relying party can verify against.
Single sign-on
One login across every Straventa app; your own applications join as plain OIDC relying parties.
OIDC client management
Register, edit, rotate secrets for, and revoke OIDC clients from the console.
Multi-tenant
A tenant hierarchy with descendant-scoped platform permissions, so one identity plane serves many organisations.
Step-up MFA
TOTP-based re-authentication on sensitive actions, with token revocation and refresh-token families.
Fail-closed token audiences
Access tokens carry an explicit, fail-closed audience set, and permissions resolve centrally through one check endpoint — one place to change a rule, one place to audit it.
How it works

From kick-off to day-to-day

1
Point apps at the issuer
Configure each app as an OIDC relying party against your Accounts issuer — discovery and JWKS do the rest.
2
Register your clients
Create OIDC clients in the console, set redirect URIs and scopes, and manage secrets and rotation.
3
Sign in once
Users authenticate at accounts.straventa.com, step up with MFA where required, and single sign-on carries across apps.

See it

What you actually get

The live hosted-identity surface at accounts.straventa.com — captured from the running product, not a mockup.

Straventa Accounts hosted-identity home, showing the Account, Organization admin, and Connection portal entry points

Want Accounts for your team?

Bring your rails, controls, and deployment constraints. We will show where the platform fits and where it does not.