Apache 2.0Pre-1.0 · managed cloud and self-hosted previewsRead the open-source commitment

Identity plane

Carry real identity all the way to the tool call.

Issue scoped gateway sessions today and evaluate Better Auth federation wiring, while connected accounts and production claim mapping remain planned.

Product boundary

The identity preview binds an authenticated subject to organization context and a short-lived MCP session. It does not yet broker upstream credentials.

Available now
Behavior backed by the current local vertical slice and automated tests.
Preview
Useful implementation exists, but the complete operating journey is not proven.
Planned
Part of the open MCP-native roadmap, not current product behavior.
Deployment
Managed cloud and self-hosted targets share portable packages; live parity remains an acceptance test.

Capabilities

What identity controls

Status labels distinguish tested behavior from useful previews and the open roadmap.

01Preview

Workforce identity wiring

Configure Better Auth OIDC/SAML providers; live enterprise provider and group/claim mapping tests remain outstanding.

02Planned

Lifecycle provisioning

Target open SCIM user and group lifecycle management with comprehensive credential invalidation.

03Planned

Connected accounts

Broker approved OAuth, API-key, and service-account connections per identity and environment.

04Available now

Scoped sessions

Issue short-lived gateway sessions for a precise composition, principal, and policy context.

Operating flow

The target journey, with current maturity called out above.

01

Authenticate

Resolve the workforce user, workload, or service principal at the control plane.

02

Bind

Attach organization roles, groups, claims, and approved connected accounts.

03

Issue

Mint a short-lived data-plane session with explicit audience and scope.

Target control surface

Designed for platform and security teams.

These controls define the intended product boundary; the capability labels above are the current implementation record.

  • OIDC and SAML SSO
  • SCIM directories
  • Group-to-role mapping
  • Service principals
  • Credential references
  • Revocation and session expiry

Evaluate locally or inspect either deployment target.

The managed cloud and Kubernetes paths are previews of one open codebase, with no intended capability gate or mandatory call-home path.