- Can this actually replace Active Directory?
- For application sign-on, yes — that is exactly what it is. Every app that speaks OpenID Connect points at your Accounts issuer and stops having its own user table. What it does not do is replace AD's Windows domain duties: Group Policy, machine join, file-share ACLs, and Kerberos on the LAN. The common shape is Accounts in front of every web and mobile application while AD keeps the Windows estate, then AD shrinks as applications move off it. We map which of your systems fall on which side during the architecture review — before you sign anything.
- Do you support SAML, SCIM, and LDAP sync?
- Straventa Accounts ships OpenID Connect and OAuth 2.0 today: Authorization Code with PKCE, discovery, and JWKS. SAML 2.0, SCIM 2.0 provisioning, and live LDAP directory sync are not shipped — we would rather tell you that now than in week three of an implementation. For applications that only speak SAML, you keep them on your existing provider or place a third-party OIDC-to-SAML proxy in front of them — Straventa does not ship one. Users and groups are migrated by scripting against the single-resource admin API; bulk invitations are supported natively. If SAML or SCIM is a hard procurement requirement, say so in the architecture review and we will tell you plainly whether the timeline works for you.
- What does migration off Okta, Entra, or Keycloak actually look like?
- Application by application, with both providers live at once. We stand Accounts up beside your existing identity provider, move one low-risk internal application over, and verify it end to end. Users, groups, and OIDC client registrations are migrated ahead of the cutover by scripting against the admin API — bulk invitations are native, the rest is a script we write with you; passwords that cannot be exported are re-established at first login or through your existing MFA factor. Because every application talks to an issuer URL, a rollback is a configuration change, not a project. The variable in the schedule is how many bespoke integrations you own, not our side of the work.
- What about high availability, backups, and support when it breaks?
- Accounts runs as a normal stateless service against your database — you run multiple replicas behind your load balancer and back it up the way you back up everything else, so your existing RTO and RPO targets apply because it is your infrastructure. Support terms, response windows, and reporting cadence are set per deployment in the contract, with a Jakarta-based team and a named engineering contact rather than a ticket queue.
- How is it priced, and where does the data sit for OJK and UU PDP purposes?
- Per deployment on an annual contract, not per seat — adding a thousand users does not change the price. Self-hosted deployments keep every identity record, session, and authentication log inside your own environment, which means residency and retention are governed by your policy, not a foreign vendor's. Straventa's managed plane runs in the Jakarta region. Control-mapping evidence is summarised on /security, and the full control matrix is available under NDA.