Curity
Curity Identity Server is a commercial, self-hosted identity platform that issues OAuth 2.0 access tokens and OpenID Connect ID tokens, orchestrates multi-factor and contextual authentication, and exposes admin/developer tooling for secure, API-centric apps and APIs.
Key Capabilities
-
Standards-based SSO & tokens: Full OpenID Connect and OAuth 2.0 support, tutorials and flow guides (authorization code, hybrid, etc.).
-
Advanced auth methods: Built-in WebAuthn authenticator for passkeys/FIDO2; articles and admin guides detail setup and use.
-
Adaptive authentication: Policy-driven decisions leveraging context such as geolocation to step up or streamline login.
-
SCIM user management: Curity exposes SCIM 2.0 endpoints for user CRUD and can also use external SCIM sources; a separate User Management service provides OAuth-protected SCIM/GraphQL APIs.
-
SAML options: Works as a SAML 2.0 Service Provider (federate to external IdPs). Curity also provides a SAML IdP Service profile to issue SAML assertions.
Limitations
-
SAML IdP maturity notes: Curity’s SAML IdP Service exists but documentation flags feature evolution—review against your SP requirements before large-scale cutover.
-
Not an IGA suite: Curity focuses on authN/authZ and developer-centric identity. Provisioning/governance beyond SCIM endpoints and user management generally requires adjacent IGA systems.
-
Self-hosted operations: Strength in Kubernetes/automation assumes teams will run and secure the platform (HA, backups, HSM/certs, observability). Evaluate operational fit vs. fully managed SaaS IdPs.