ClearLogin
Clearlogin is a multi-tenant SaaS platform that brokers single sign-on to web/SaaS applications. It sits between your directory/IdP (e.g., Azure AD, Okta, AD/LDAP) and target apps and issues SSO assertions/tokens (SAML or JWT) to the apps. Users authenticate to Clearlogin, then launch federated apps from a unified dashboard.
Key Capabilities
-
Standards-based federation to apps: Clearlogin functions as an Identity Provider for SAML 1.1/2.0 (IdP- and SP-initiated) and also supports JWT SSO for apps that accept JSON Web Tokens.
-
MFA options: Built-in Clearlogin Authenticator, Guardian MFA, U2F (hardware key), TOTP one-time passcodes, and Cisco Duo integration; admin controls include “remember device” and policy-based enforcement.
-
Password manager & app launcher: Zero-knowledge password manager with a browser extension to vault credentials for non-federated apps; users access everything from a cloud app dashboard.
-
Operational status & tenancy: Service runs as a hosted, multi-tenant platform.
Limitations
-
OIDC provider role: Public documents confirm that OIDC is used to connect Okta as an identity source. They do not clearly document Clearlogin issuing OpenID Connect tokens to downstream apps.
-
Provisioning (SCIM): Clearlogin materials do not provide a vendor-hosted SCIM 2.0 endpoint/specification.
-
Ecosystem focus: Documentation and examples emphasize SAML/JWT to web apps; API-first/CIAM features (registration flows, consent, progressive profiling) are not surfaced in public docs.
-
Lifecycle/ownership: Clearlogin is an Evolve IP product via acquisition on Oct 17, 2017; buyers should align expectations and support with Evolve IP’s cloud/workspace stack.