Skip to main content
Straventa

Identity & access · Straventa Accounts

Own your login.

Self-hosted single sign-on for Indonesian enterprises

Straventa Accounts is a self-hosted, multi-tenant OpenID Connect provider — single sign-on, step-up MFA, and central permissions for every application your organisation runs. It deploys inside your infrastructure, keeps identity data in Indonesia, and comes with a named engineering team on the other end of the contract. Licensed per deployment, not per employee.

  • Standards-based OpenID Connect
  • Runs on Kubernetes or Docker
  • Jakarta-based engineering
  • Identity data never leaves your environment

Why teams move

Three things every IT director tells us before they switch

01

Per-seat identity is a tax on hiring

Okta and Microsoft Entra ID bill you for every employee, every contractor, and every service identity — every month, forever. Your identity bill tracks your headcount, not the value you get from it. Doubling the team doubles the invoice for a login screen you already had.

02

Your directory is offshore. Your regulator is not

With SaaS identity, your staff and customer identity records — and every authentication log an examiner will eventually ask for — sit in a region you do not control, under a retention policy you did not write. UU PDP 27/2022 and OJK expectations on data residency do not get easier as you grow.

03

Keycloak is free until 03:00

Open-source identity is free to license and expensive to run. Upgrades, key rotation, high availability, backup, and the on-call rotation all become yours. When the token endpoint stops issuing at three in the morning, there is no phone number — there is a mailing list.

What you get

A standards-based identity provider, not a login form

Standards-based OpenID Connect provider

Authorization Code with PKCE, OIDC discovery, and a JWKS endpoint — any application that speaks OpenID Connect or OAuth 2.0 connects without a bespoke adapter.

Single sign-on across every app you run

One login covers every Straventa product and every application you register as a relying party — including the internal tools nobody wants to build auth for twice.

Self-service OIDC client management

Register clients, set redirect URIs and scopes, rotate secrets, and revoke access from the console — your team does it, not a vendor ticket queue and not a config redeploy.

Step-up MFA where it matters

TOTP re-authentication in front of sensitive actions, backed by refresh-token families with reuse detection and family-wide revocation — so a stolen session does not become a stolen approval.

Multi-tenant with descendant-scoped permissions

A real tenant hierarchy: one identity plane serves a holding company, its subsidiaries, and their teams, with platform permissions that scope down the org tree instead of being copied per entity.

Audience-scoped tokens, checked centrally

Access tokens carry an explicit, fail-closed audience set, and authorisation resolves through one central check endpoint — one place to change a rule, one place to audit it.

How it compares

Five ways to run identity. One of them is yours

Written for the person who has to defend the choice in a board pack.

Five ways to run identity. One of them is yours
CriterionStraventa AccountsOktaMicrosoft Entra IDKeycloak (self-run)On-prem AD / LDAP
Deployment modelSelf-hosted on your Kubernetes or Docker, or Straventa-managed at accounts.straventa.com. Your choice, same product.SaaS only.SaaS only — AD Connect syncs to it, it does not run in your data centre.Self-hosted only.Self-hosted only.
Where identity data livesYour infrastructure, in Indonesia. Nothing leaves your environment on the self-hosted deployment.Vendor regions abroad.Microsoft global tenancy.Your infrastructure.Your infrastructure.
Pricing modelPer deployment, annual. Not per seat — headcount growth does not change the invoice.Per user, per month, per add-on module.Per user, per month, tiered by feature plan.Free licence; you pay in engineering time.Server and CAL licensing plus hardware plus administrators.
Who operates itYou, or Straventa under contract. Start managed and take it in-house later without re-platforming.Vendor.Vendor.You. Entirely.Your infrastructure team.
Who answers at 03:00A named Straventa engineering contact, on terms set in your contract, in your timezone.The support tier you purchased, offshore timezone.Your Microsoft support plan.A community forum.Your own on-call.
ProtocolsOpenID Connect / OAuth 2.0 — PKCE, discovery, JWKS. SAML and SCIM are not shipped today; see the FAQ.OIDC and SAML.OIDC and SAML.OIDC and SAML.Kerberos / LDAP — needs ADFS or a bridge for modern apps.
Multi-tenant / group structureNative tenant hierarchy with descendant-scoped permissions — built for holdings with subsidiaries.Separate orgs, priced separately.Separate tenants, cross-tenant work required.Realms, isolated — no inherited scoping.Forests and trusts; heavy to change.
Ships integrated with your payments and ops stackYes — Payops and the Ops platform already authenticate against it and resolve permissions through it on day one.An integration project.An integration project.An integration project.An integration project.
Exit costStandard OIDC. Your apps point at an issuer URL — repoint them and leave.Standard protocols, proprietary policy and workflow layer to rebuild.Deep tenant coupling across Microsoft 365.Low.High.

Competitor rows describe each vendor’s publicly documented model at time of writing; confirm current terms with the vendor before making a decision.

Coming from somewhere else

Replacing a specific product?

Each page covers what actually moves, what does not, and the migration path — written for the team leaving that product.

Straight answers

The five questions procurement always asks

Can this actually replace Active Directory?
For application sign-on, yes — that is exactly what it is. Every app that speaks OpenID Connect points at your Accounts issuer and stops having its own user table. What it does not do is replace AD's Windows domain duties: Group Policy, machine join, file-share ACLs, and Kerberos on the LAN. The common shape is Accounts in front of every web and mobile application while AD keeps the Windows estate, then AD shrinks as applications move off it. We map which of your systems fall on which side during the architecture review — before you sign anything.
Do you support SAML, SCIM, and LDAP sync?
Straventa Accounts ships OpenID Connect and OAuth 2.0 today: Authorization Code with PKCE, discovery, and JWKS. SAML 2.0, SCIM 2.0 provisioning, and live LDAP directory sync are not shipped — we would rather tell you that now than in week three of an implementation. For applications that only speak SAML, you keep them on your existing provider or place a third-party OIDC-to-SAML proxy in front of them — Straventa does not ship one. Users and groups are migrated by scripting against the single-resource admin API; bulk invitations are supported natively. If SAML or SCIM is a hard procurement requirement, say so in the architecture review and we will tell you plainly whether the timeline works for you.
What does migration off Okta, Entra, or Keycloak actually look like?
Application by application, with both providers live at once. We stand Accounts up beside your existing identity provider, move one low-risk internal application over, and verify it end to end. Users, groups, and OIDC client registrations are migrated ahead of the cutover by scripting against the admin API — bulk invitations are native, the rest is a script we write with you; passwords that cannot be exported are re-established at first login or through your existing MFA factor. Because every application talks to an issuer URL, a rollback is a configuration change, not a project. The variable in the schedule is how many bespoke integrations you own, not our side of the work.
What about high availability, backups, and support when it breaks?
Accounts runs as a normal stateless service against your database — you run multiple replicas behind your load balancer and back it up the way you back up everything else, so your existing RTO and RPO targets apply because it is your infrastructure. Support terms, response windows, and reporting cadence are set per deployment in the contract, with a Jakarta-based team and a named engineering contact rather than a ticket queue.
How is it priced, and where does the data sit for OJK and UU PDP purposes?
Per deployment on an annual contract, not per seat — adding a thousand users does not change the price. Self-hosted deployments keep every identity record, session, and authentication log inside your own environment, which means residency and retention are governed by your policy, not a foreign vendor's. Straventa's managed plane runs in the Jakarta region. Control-mapping evidence is summarised on /security, and the full control matrix is available under NDA.

Bring us your current identity bill and your org chart.

Forty-five minutes with an engineer, not a sales deck. We will map your applications onto an Accounts deployment, show you the cutover order, and tell you plainly if something in your estate does not fit yet.