Enterprise identity. Zero compromise.
Connect your identity provider, automate user provisioning, and enforce phishing-resistant authentication — across every team and tenant in your Arbitex environment.
Works with every enterprise identity stack
Plug in your existing IdP — no custom integrations required.
SAML 2.0
Federate with any SAML-compliant identity provider. SP-initiated and IdP-initiated flows supported.
SCIM 2.0
Automate user and group provisioning from Okta, Azure AD, or any SCIM-compliant directory.
WebAuthn / FIDO2
Phishing-resistant hardware keys and passkeys. Replaces passwords where it matters most.
OIDC
OpenID Connect for token-based authentication. Full claims mapping and refresh token rotation.
Enterprise SSO
Federate with any SAML 2.0-compliant identity provider. Configure SP-initiated and IdP-initiated login flows, enforce session policies, and map IdP groups to Arbitex roles with no custom code.
Automated User Provisioning
SCIM 2.0 lifecycle management syncs users, groups, and role assignments from your directory in real time. Deprovisioning is immediate — when an employee leaves, access is revoked within seconds.
MFA and Passwordless
Enforce multi-factor authentication across all users with WebAuthn/FIDO2 hardware keys and passkeys. Phishing-resistant by design — eliminates credential theft as an attack vector.
Token and Session Governance
OIDC token validation with full claims inspection, JWT audience enforcement, and configurable refresh token rotation. Session policies enforce idle timeouts and maximum session durations per tenant.
Distributed Session Store
Sessions are backed by Redis — distributed across availability zones, with no sticky sessions required. Any gateway node can validate any session, eliminating single points of failure and enabling seamless horizontal scaling without session affinity routing.
OAuth Client Secret Rotation
Rotate OAuth client secrets with zero downtime. During rotation, both the old and new secrets remain valid for a configurable overlap window — services update their credentials without a hard cutover. The previous secret is automatically expired after the transition period.
How it works
Connect your identity provider
Point Arbitex at your existing SAML 2.0 IdP or OIDC provider — Okta, Azure AD, Google Workspace, Ping, or any compliant directory. Configuration takes minutes, not days. No SDK changes required in your application layer.
Provision users and groups automatically
Enable SCIM 2.0 to sync users and group memberships on a continuous basis. Role assignments in Arbitex reflect your directory in real time. When a user is deprovisioned in your IdP, their Arbitex sessions are terminated immediately.
Enforce authentication policies
Require MFA for all users or specific high-privilege roles. Choose between TOTP, hardware keys, or passkeys per policy tier. Monitor authentication events and policy enforcement in the audit log.