
Identity & Access ManagementAI Security
Curity Identity Server
OAuth and OpenID Connect token service securing customer, machine, and AI agent access.
Curity Identity Server Overview
What it does
The Curity Identity Server is a Customer Identity and Access Management (CIAM) and access management platform built around token issuance rather than a login portal. It consolidates authentication, federation, token services, API access control, and user management into software the buyer deploys and operates. Its distinguishing mechanism is Token Intelligence: a Token Designer that shapes each token's scopes and claims dynamically from identity, context, policy, and risk, turning every API call into a scoped, auditable access decision.
How it works
Self-hosted on Linux, macOS, Docker, or Kubernetes with Helm charts, the platform exposes OAuth 2.0, OpenID Connect, Financial-grade API (FAPI) 2.0, CIBA, PAR, and SCIM 2.0 endpoints. Journey orchestration chains authentication factors in any order across browser and native apps, and the Hypermedia Authentication API keeps mobile flows server-controlled so passkeys and multifactor authentication changes ship without an App Store redeployment. Token Exchange translates credentials across APIs and external identity providers, sender-constrained tokens block replay, and Phantom Token keeps token data private to internal APIs. Access Intelligence issues ephemeral, dual-context tokens for AI agents acting on a user's behalf.
Credentials and traction
SOC 2 Type II and ISO 27001 certified, with OpenID Foundation conformance certification for Financial-grade API (FAPI) profiles, including the Kingdom of Saudi Arabia Open Banking profile certified in 2024. Production deployments span financial services, telecom, healthcare, government, and retail, among them ICA Gruppen, Santander, Skandia, Tele2, Volvo Finans, E.ON, PagerDuty, and Scandic Hotels. The platform targets organizations that must keep identity data and login availability under their own control across multiple regulated markets.
Key Capabilities
mapped to solution categoriesFederates login with Google, Apple, Facebook, Microsoft, and other external identity providers via OIDC, returning normalized user attributes.
Supports passkey registration and authentication via the WebAuthn API, enabling biometric-authenticated, phishing-resistant login for consumer-facing applications.
Handles authentication and session management for millions of concurrent external users at low latency, sustaining consumer traffic spikes such as product launches and seasonal peaks.
Captures and stores user consent for data processing at the identity layer, integrated with the registration and preference management flows.
Verifies a real-world identity during registration or step-up, such as document or government-ID proofing and liveness checks, to establish trust for high-value consumer accounts before granting access.
Requests additional user attributes across multiple sessions rather than collecting a full profile at registration, reducing abandonment at the point of sign-up.
Manages OAuth 2.0 client credentials and JWT issuance for machine-to-machine API authentication, with rate limiting and scope enforcement.
Defines and enforces authorization policies that decide which users and machines can access which applications and APIs, evaluated at runtime alongside authentication.
Enforces externalized, fine-grained authorization policy using ABAC or RBAC for applications and APIs.
Implements SAML 2.0, OIDC, and OAuth 2.0 for SSO across SaaS and on-premises applications, with a pre-built application catalog and custom app support.
Provides phishing-resistant MFA such as FIDO2 and X.509, with protections against compromised passwords and common MFA attacks.
Supports FIDO2 hardware keys, platform biometrics (Touch ID, Windows Hello), and passkeys for phishing-resistant authentication without password entry.
Evaluates contextual risk signals (device fingerprint, geolocation, IP reputation, behavioral anomaly) at each authentication and step-up challenge request, applying stronger authentication when risk is elevated.
Provides low-code or no-code journey-time orchestration to customize and extend access flows.
Provides a directory or integrated identity repository with synchronization across all user constituencies.
Supports basic create, read, update and delete identity life-cycle operations across all user types.
Provides access management functions for machines, workloads, services and agentic AI.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on July 26, 2026
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.