tinyguard
Identity, tenant-scoped.
tinyguard is a self-contained OpenID Connect / OAuth2 identity provider: authorization-code with PKCE, client-credentials, refresh, and device flows; WebAuthn passkeys; dynamic client registration; backchannel logout; an admin and users REST API with API keys, roles, and groups; an event and notification system; Argon2id password policies; and JWKS rotation — with a built-in admin console and per-tenant isolation.
Where to go next
Section titled “Where to go next”- Getting started — run it locally or in Docker, first login.
- Configuration — every key, its default, and its env override.
- Observability — OTLP traces and logs, and the masking that keeps credentials out of telemetry.
- Tenants — the multitenancy model, platform vs tenant admins, scoped endpoints.
- Administration — the admin console, section by section.
- API reference — the HTTP surface.
- Security — hashing defaults, the login proof-of-work gate, CSRF pairing.