Skip to content

tinyguard

Identity, tenant-scoped.

tinyguard is a self-contained OpenID Connect / OAuth2 identity provider: authorization-code with PKCE, client-credentials, refresh, and device flows; WebAuthn passkeys; dynamic client registration; backchannel logout; an admin and users REST API with API keys, roles, and groups; an event and notification system; Argon2id password policies; and JWKS rotation — with a built-in admin console and per-tenant isolation.

  • Getting started — run it locally or in Docker, first login.
  • Configuration — every key, its default, and its env override.
  • Observability — OTLP traces and logs, and the masking that keeps credentials out of telemetry.
  • Tenants — the multitenancy model, platform vs tenant admins, scoped endpoints.
  • Administration — the admin console, section by section.
  • API reference — the HTTP surface.
  • Security — hashing defaults, the login proof-of-work gate, CSRF pairing.