Skip to content
AuthMantra
Start free trial

Platform

One identity layer. Six capabilities.

Sign-in, provisioning and audit for Indian organisations. Explore each one below.

Live flow, simulated

HR systemsource
AuthMantrapolicy
AppsSSO + SCIM
AuditSIEM
  • HR marks a leaver inactive
  • SCIM PATCH reaches AuthMantra
  • Sessions end, apps deprovisioned
  • audit.write, SIEM stream sent
3open standards: SAML 2.0, OIDC, SCIM 2.0
4admin roles: admin, IT admin, auditor, member
6capability areas in one console
10people free on Launch

Capability explorer

Pick a capability

Sign-in

Personsigns in once
AuthMantrachecks policy
Appgets a signed proof
SAML 2.0OpenID ConnectPKCE
  • SAML 2.0 and OpenID Connect with PKCE.
  • Pre-built connectors for common SaaS apps.
  • Apps trust a signed proof, not a stored password.

Passkeys & MFA

DeviceFace ID, Touch ID, Hello
PasskeyWebAuthn challenge
AuthMantraverifies
PasskeysAuthenticator app (TOTP)Security keys
  • Passkeys work with Face ID, Touch ID, Windows Hello or a key.
  • Authenticator-app codes as the backup.
  • Passkeys resist phishing by design.

Provisioning

HR systemsource of truth
SCIM 2.0inbound
AuthMantrapolicy
Appsoutbound SCIM
  • Joiners, movers and leavers arrive over SCIM 2.0.
  • Outbound SCIM carries the change to apps.
  • A leaver loses access when the HR record changes.

Step-up

Adminopen session
Risky actionroles, data export
Re-authenticatecheck again
Allowedlogged
  • Sensitive admin actions ask for a fresh sign-in.
  • Applies even when the session is already open.
  • Every step-up is in the audit log.

Audit & SIEM

Eventsign-in, change
Audit logexport, live feed
Your SIEMwebhook or Splunk HEC
ExportLive feedSigned webhookSplunk HEC
  • Every sign-in and admin change is recorded.
  • Export the log or watch the live feed.
  • Stream to your SIEM, signed.

DPDP controls

Requestaccess, erasure
Grievance workflowtracked
Data exportfor access
Consent recordsMumbai regionIndia data residency
  • Grievance workflow, data export, consent records.
  • Data hosted in Mumbai, asia-south1.
  • DPDP-oriented: supports your process, not a certificate.

Try it

A look inside the admin console

An interactive demo with example people and apps. Nothing here is real data.

Admin consoleTry it: pick a page with the dotsExample workspace · Mumbai

People

Add a joiner or mark a leaver. Apps follow.

NameRoleSign-inAction
Priya SharmaPeople opsPasskey
Arjun MehtaIT adminPasskey
Meera IyerFinancePasskey
Rohan DasEngineeringAuthenticator app

Apps

Five connected apps. Switch provisioning per app.

5 connected
  • Mail & documentsOIDCProvisioning
  • ChatSAML 2.0Provisioning
  • Cloud consoleSAML 2.0Provisioning
  • Code hostingOIDCProvisioning
  • TicketingSAML 2.0Provisioning

Directory

Your HR system is the source of truth.

  • No run yet. Press Run sync.

Simulated run with example people.

Sign-in

Choose how people prove who they are.

  • PasskeysFace ID, Touch ID, Windows Hello, security keys, phones
  • Authenticator appTime-based codes
  • SMS codesProvider integration plannedPlanned

Approvals

Sensitive changes ask you to re-authenticate.

Role change request

Meera Iyer → IT admin

Requested by Arjun Mehta

Step-up

Confirm it is you

Changing roles needs a fresh sign-in, even in an open session.

Waiting for your passkey…

Touch the sensor on your device.

Approved

Meera Iyer is now IT admin. The change and the step-up are in the audit log.

Declined

The request is closed and recorded.

My apps

Good morning, Priya. Open any app.

Select an app to sign in with one click.

Passkeys

Only you can remove a passkey.

  • Work laptopTouch ID
  • PhoneFace ID
  • Security keyUSB

Sessions

See where you are signed in. End any other session.

  • This laptopMumbai · active nowThis device
  • PhonePune · 2 hours ago
  • Office desktopBengaluru · yesterday

Sign in

What signing in feels like.

My data

Your records, under your control.

  • Download my dataExport what we hold about you
  • Consent recordsPrivacy notice acceptedRecorded
  • Raise a grievanceOpens the grievance workflow

Live feed

Sign-ins as they happen. Add one yourself.

  • Priya SharmaCloud console · PasskeyPassed
  • Arjun MehtaTicketing · PasskeyPassed
  • Rohan DasChat · Authenticator appPassed
  • Meera IyerMail & documents · PasskeyPassed

App access

Who can open which app. Revoke what is no longer needed.

0 of 4 checked
  • Arjun MehtaCloud console
  • Rohan DasCode hosting
  • Meera IyerTicketing
  • Priya SharmaMail & documents

Audit log

Every sign-in and admin change, in order.

TimeWhoWhatTarget
09:14Priya SharmaSigned in with a passkeyCloud console
09:02Arjun MehtaRe-authenticated for an admin actionRole change
08:55Arjun MehtaRole changedMeera Iyer
08:40Arjun MehtaProvisioning switched onChat
08:31Rohan DasSigned in with an authenticator codeCode hosting
08:12HR systemUser deactivated over SCIMImran Qureshi

SIEM

Stream the audit log to your security tools.

StreamingOff
X-AuthMantra-Signature: t=1760000000,v1=<hmac-sha256 of "t.body">

Simulated delivery with example data.

Suspend

Suspending signs a person out everywhere.

  • Rohan Das2 active sessions
  • Imran Qureshi1 active session
  • Sneha Reddy3 active sessions

All people and numbers are fictional.

Watch an event travel

One leaver, from HR to your SIEM

Press Play. Every line is simulated.

one leaver, end to endSimulated output
$ hr emit leaver --id EMP-0377
SCIM PATCH /scim/v2/Users/3c91  active=false
✓ 202 Accepted by AuthMantra
outbound SCIM: Mail & documents, Chat, Cloud console
✓ 3 of 3 apps updated
audit.write user.deactivated
$ stream --to siem
{"event":"user.deactivated","target":"rohan.das@example.in","result":"ok"}
X-AuthMantra-Signature: t=1760000000,v1=3b7e41...c9
✓ 200 OK from your endpoint

Product views

What it looks like

01 / 06

Single sign-on

One sign-in opens every connected app.

02 / 06

Passkeys and MFA

Phishing-resistant sign-in, with a backup code.

03 / 06

Step-up

A second check before the risky click.

04 / 06

Provisioning

HR changes reach apps over SCIM.

05 / 06

Audit and SIEM

Every action logged, streamed on.

06 / 06

DPDP controls

Grievance, export and consent in one place.

Architecture

Apps, AuthMantra, your systems

Hosted in India: Mumbai, asia-south1

Your apps

SaaS appsSAML or OIDC
Internal appsOIDC with PKCE

AuthMantra

Sign-in and policySSO, passkeys, step-up
ProvisioningSCIM in and out

Your systems

HR / directorySCIM source
SIEMsigned webhook or HEC

Integrations

Connect what you already run

Mail & documents
Chat & meetings
Cloud consoles
HR systems
Ticketing & IT service
Code & CI
Finance & ERP
Analytics & BI
In-house apps

Any app that speaks SAML 2.0 or OpenID Connect can sign in. Connector types the product has:

SAML 2.0
OpenID Connect
SCIM 2.0
Signed webhook
Splunk HEC

Security posture

True today

Six areas, one console

  • Sign-in
  • Passkeys & MFA
  • Provisioning
  • Step-up
  • Audit & SIEM
  • DPDP controls
Hosted in Mumbai (asia-south1)Customer-managed encryption keysPrivate databaseWeb application firewallPasskeys (WebAuthn)Step-up for admin actionsSigned SIEM webhooksDPDP-oriented workflows

These are product facts, not certifications. We hold no SOC 2 report or ISO 27001 certificate yet. See Trust & security.

See it with your own apps

Free for up to 10 people. Or tell us how you sign in today.