FusionAuth
FusionAuth is an IdP/authorization server that issues OAuth 2.0 access tokens and OpenID Connect ID tokens, and can also act as a SAML 2.0 IdP or SP. It ships a full REST API, hosted/embeddable login options with customizable themes, and operational flexibility.
Key Capabilities
-
Standards-based SSO & Tokens: Offers Authorization Code, Device, Client Credentials, Refresh, and other OAuth/OIDC grants; SAML 2.0 IdP/SP configuration guides.
-
Passkeys / WebAuthn: Built-in WebAuthn flows and APIs to register and authenticate with passkeys.
-
Provisioning via SCIM 2.0 (Enterprise): FusionAuth can act as a SCIM server for Users/Groups and exposes SCIM APIs.
-
Deployment choice: Can be self-hosted anywhere or via the vendor’s managed cloud.
Limitations
-
Edition gating: SCIM and some theme features are paid-edition capabilities. Validate required features against your license.
-
IGA scope: FusionAuth focuses on authN/authZ and user management; full identity governance (certifications/SoD) requires external IGA. (No vendor docs asserting native IGA.)
-
Policy/risk depth: Adaptive/risk scoring features are not a primary focus in public docs; pair with upstream risk engines if needed.
-
SaaS vs self-host operations: Self-hosting provides control but adds responsibility for HA, upgrades, keys/certs, and observability.