DOCUMENTATION & WIKI

How Workforce Identity Works in AuthMantra

AuthMantra acts as the sovereign root of trust for your workforce. Rather than having separate passwords for dozens of SaaS and internal tools, your users authenticate once against AuthMantra, and receive cryptographically signed assertions across all applications.

🔒 100% Sovereign Indian Data Residency

All private keys, password hashes, and user records are stored strictly in AWS Mumbai (ap-south-1). No credentials or session tokens ever cross international boundaries.

1. SAML 2.0 Identity Provider (IdP)

AuthMantra provides an enterprise-grade SAML 2.0 engine that supports both Service Provider (SP)-initiated and Identity Provider (IdP)-initiated Single Sign-On.

When an application redirects a user to AuthMantra, the request is parsed, authenticated against your workforce policies, and returned with an RSA-SHA256 XMLDSig enveloped digital signature signed by your dedicated X.509 certificate.

SAML Endpoint Configuration
IdP Entity ID: https://authmantra.com/saml/metadata.xml
SSO Service URL: https://authmantra.com/saml/sso
Signature Algorithm: RSA-SHA256 (XMLDSig)
NameID Format: urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
Certificate Download: https://authmantra.com/saml/cert

2. OpenID Connect (OIDC) & PKCE

For modern SPAs, mobile applications, and cloud-native microservices, AuthMantra implements OAuth 2.0 with the OpenID Connect (OIDC) identity layer.

Tokens are minted using RS256 asymmetric cryptography. Downstream applications verify token authenticity by fetching public keys from our RFC 7517 JSON Web Key Set (JWKS) endpoint at /.well-known/jwks.json.

All public clients are strictly required to use Proof Key for Code Exchange (PKCE) via RFC 7636 with SHA-256 code challenges (S256).

OIDC Token Exchange Endpoint
POST /oidc/token HTTP/1.1
Host: authmantra.com
Content-Type: application/x-www-form-urlencoded

grant_type=authorization_code
&code=auth_code_xyz123
&client_id=your-client-id
&redirect_uri=https://yourapp.com/callback
&code_verifier=dBjftJeZ4CVP-mB92K27uhbUJU1p1r_wW1gFWFOEjXk

3. SCIM 2.0 Automated User Provisioning

Manual account creation and offboarding is the number one cause of orphaned accounts and security breaches. AuthMantra solves this via the System for Cross-domain Identity Management (SCIM 2.0) standard (RFC 7643 / RFC 7644).

When an employee joins or leaves your company, your HRMS automatically triggers updates to AuthMantra, which instantaneously provisions or revokes access across AWS, RazorpayX, Google Workspace, and GitHub.

4. Digital Personal Data Protection Act, 2023

AuthMantra is architected specifically to help Indian organizations comply with the DPDP Act 2023: