Security Stack Logo
Curity Identity Server logo

Identity & Access ManagementAI Security

Curity Identity Server

OAuth and OpenID Connect token service securing customer, machine, and AI agent access.

Customer Identity and Access Management (CIAM)Access Management

Curity Identity Server Overview

What it does

The Curity Identity Server is a Customer Identity and Access Management (CIAM) and access management platform built around token issuance rather than a login portal. It consolidates authentication, federation, token services, API access control, and user management into software the buyer deploys and operates. Its distinguishing mechanism is Token Intelligence: a Token Designer that shapes each token's scopes and claims dynamically from identity, context, policy, and risk, turning every API call into a scoped, auditable access decision.

How it works

Self-hosted on Linux, macOS, Docker, or Kubernetes with Helm charts, the platform exposes OAuth 2.0, OpenID Connect, Financial-grade API (FAPI) 2.0, CIBA, PAR, and SCIM 2.0 endpoints. Journey orchestration chains authentication factors in any order across browser and native apps, and the Hypermedia Authentication API keeps mobile flows server-controlled so passkeys and multifactor authentication changes ship without an App Store redeployment. Token Exchange translates credentials across APIs and external identity providers, sender-constrained tokens block replay, and Phantom Token keeps token data private to internal APIs. Access Intelligence issues ephemeral, dual-context tokens for AI agents acting on a user's behalf.

Credentials and traction

SOC 2 Type II and ISO 27001 certified, with OpenID Foundation conformance certification for Financial-grade API (FAPI) profiles, including the Kingdom of Saudi Arabia Open Banking profile certified in 2024. Production deployments span financial services, telecom, healthcare, government, and retail, among them ICA Gruppen, Santander, Skandia, Tele2, Volvo Finans, E.ON, PagerDuty, and Scandic Hotels. The platform targets organizations that must keep identity data and login availability under their own control across multiple regulated markets.

Key Capabilities

mapped to solution categories
Customer Identity and Access Management (CIAM)

Federates login with Google, Apple, Facebook, Microsoft, and other external identity providers via OIDC, returning normalized user attributes.

Supports passkey registration and authentication via the WebAuthn API, enabling biometric-authenticated, phishing-resistant login for consumer-facing applications.

Handles authentication and session management for millions of concurrent external users at low latency, sustaining consumer traffic spikes such as product launches and seasonal peaks.

Captures and stores user consent for data processing at the identity layer, integrated with the registration and preference management flows.

Verifies a real-world identity during registration or step-up, such as document or government-ID proofing and liveness checks, to establish trust for high-value consumer accounts before granting access.

Requests additional user attributes across multiple sessions rather than collecting a full profile at registration, reducing abandonment at the point of sign-up.

Access Management

Manages OAuth 2.0 client credentials and JWT issuance for machine-to-machine API authentication, with rate limiting and scope enforcement.

Defines and enforces authorization policies that decide which users and machines can access which applications and APIs, evaluated at runtime alongside authentication.

Enforces externalized, fine-grained authorization policy using ABAC or RBAC for applications and APIs.

Implements SAML 2.0, OIDC, and OAuth 2.0 for SSO across SaaS and on-premises applications, with a pre-built application catalog and custom app support.

Provides phishing-resistant MFA such as FIDO2 and X.509, with protections against compromised passwords and common MFA attacks.

Supports FIDO2 hardware keys, platform biometrics (Touch ID, Windows Hello), and passkeys for phishing-resistant authentication without password entry.

Evaluates contextual risk signals (device fingerprint, geolocation, IP reputation, behavioral anomaly) at each authentication and step-up challenge request, applying stronger authentication when risk is elevated.

Provides low-code or no-code journey-time orchestration to customize and extend access flows.

Provides a directory or integrated identity repository with synchronization across all user constituencies.

Supports basic create, read, update and delete identity life-cycle operations across all user types.

Provides access management functions for machines, workloads, services and agentic AI.

Compliance

certifications
FAPIISO 27001SOC 2 Type II

Integrations

compatible tools
Active Directory Federation Services (ADFS)ApigeeAWS API GatewayBankIDDuoF5Freja eIDKongMicrosoft Entra IDMitIDOktaPing IdentitySignicatTykYubico

Implementation & support

Deployment model
CloudHybridOn-Premises
Pricing structure
Community EditionFlat RateFree Trial
Support channels
24/7 SupportBusiness Hours SupportCommunity ForumDocumentationSlack (Customer Channel)Ticketing PortalTraining / Academy

Info last updated on July 26, 2026

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.