PK-IDP
A lightweight Identity Provider that deeply simplifies and hardens authentication through Passkey-first security (OAuth 2.1, PKCE, & OIDC).
The Problem & The Solution
The Problem
Traditional password-based authentication is a constant battle between user friction and security vulnerabilities like phishing and credential stuffing. Managing identity across fragmented microservices adds another layer of complexity to every new app built.
The Solution
PK-IDP provides a lightweight but robust identity layer for private ecosystems. By prioritizing WebAuthn and Passkeys, it deeply simplifies and hardens authentication—removing the burden of passwords while providing seamless, cryptographically secure SSO across your entire service stack.
One Console for Every Registered App

Every consuming app gets registered once — a slug, a display name, and its allowed redirect URIs — and the admin console is where an owner enables OAuth clients, rotates SSO secrets, and mints server-to-server invite-signing keys, all from a single screen instead of hunting through per-app configuration.
Key Features
Passkey-First Security
Built around WebAuthn/Passkeys to eliminate passwords, providing a frictionless login experience that is inherently resistant to phishing and credential theft.
OAuth 2.1 & PKCE
Full support for the latest OAuth 2.1 standards and Proof Key for Code Exchange (PKCE), ensuring secure authorization flows for mobile, web, and server-side clients.
OIDC Compliant
Supports OpenID Connect discovery and JWKS endpoints, making it compatible with most modern client libraries and middleware.
Server-to-Server Invites
Secure application provisioning via signature-verified invites, allowing automated onboarding of trusted service accounts within the ecosystem.
Securing the ecosystem.
The core identity layer powering our suite of interconnected tools.
Have a project like this one?
We'd be glad to talk through your goals, your constraints, and whether we're the right team for the work.
