Beta

Conjoin Auth

Add user authentication to your application with passwordless login, OAuth, SAML, directory sync, multi-factor authentication, and role-based access control.

User identity

Handle sign-up, login, and sessions without building auth from scratch

Secure authentication APIs with passwordless login, password hashing with breach detection, OAuth, SAML SSO, directory sync, and MFA support. Focus on your product instead of security protocols.

Conjoin IDE

Select a file to view its contents

Capabilities

Complete authentication without building from scratch

Email and password authentication

Secure password hashing with breach detection, email verification, and password reset flows.

Passwordless authentication

Magic links and PIN codes delivered via email for sign-in without passwords.

Phone authentication

SMS verification for sign-up and login with automatic carrier routing by country.

OAuth provider integration

Connect 30+ OAuth providers including Google, GitHub, Microsoft, Apple, and Slack.

Enterprise SSO

SAML 2.0 and OIDC authentication with Okta, Azure AD, and other identity providers.

Directory sync

SCIM 2.0 user provisioning with JIT enrollment and group reconciliation from enterprise IdPs.

Organization management

Multi-tenant support with organization groups, invitations, and membership hierarchies.

Multi-factor authentication

SMS, email, or authenticator app-based MFA with configurable enforcement policies.

Session management

JWT access tokens, refresh tokens, and PKCE support with device-based session tracking.

Role-based access control

Custom roles with fine-grained permissions and hierarchical access inheritance.

Audit logging

Track login attempts, password changes, and security events for compliance and debugging.

Threat detection

Detect bots, brute force attacks, impossible travel, and suspicious logins with Auth Guard.

256-bit
Encryption

AES encryption for sensitive data at rest

< 10ms
Token verification

JWT validation and session checks

ISO 27001
Compliance

Information Security Management System

Why it matters

Ship secure authentication without security expertise

Add authentication without building infrastructure

Use APIs for password hashing, token generation, email verification, OAuth flows, and session management with security protocols handled correctly by default.
In practice

Add user registration to your app in under an hour. Call the signup endpoint with email and password. Passwords are hashed securely, verification emails sent automatically, and tokens generated for you.

Add OAuth in minutes

Connect Google, GitHub, or Microsoft sign-in without managing client secrets. Choose from 30+ pre-configured providers, or integrate with any custom OAuth 2.0 provider using the universal client.
In practice

Enable Google sign-in by calling one endpoint with your OAuth credentials. Users click the Google button, authenticate, and land back in your app with a valid session.

Enterprise-ready SSO

Support enterprise customers with SAML 2.0 and Directory Sync. Connect to Okta, Azure AD, and other IdPs without building custom integrations.
In practice

Close enterprise deals faster by offering SSO. Configure a SAML connection in the dashboard, and users can log in with their corporate credentials immediately.

Enforce MFA without complexity

Enable multi-factor authentication with SMS, email, or authenticator apps. Require MFA for specific roles or all users with one config change.
In practice

Flip the MFA toggle in your dashboard settings. Admin users now receive a six-digit code via SMS on login. TOTP codes, backup codes, and recovery flows work without writing verification logic.

Built for Your Workflow

Ship faster with solutions designed for real-world needs

How Conjoin solves this

Generate OAuth authorization URLs with state validation and PKCE handled automatically. The callback endpoint exchanges authorization codes for tokens and creates user sessions in one step.

Impact

Add Google, GitHub, or Microsoft sign-in in minutes without debugging redirect flows.

How Conjoin solves this

Create sessions that return JWT access tokens and refresh tokens with configurable expiration. Token validation, refresh rotation, and session invalidation work through a single API.

Impact

Deploy authentication without writing JWT signing, verification, or refresh middleware.

How Conjoin solves this

Enable SMS, email, or TOTP-based multi-factor authentication with one API call. QR codes for authenticator apps, backup codes for account recovery, and challenge flows generate automatically.

Impact

Add multi-factor auth in an afternoon instead of building verification and recovery systems.

How Conjoin solves this

Define roles with specific permissions and assign them to users. Roles support inheritance, so an admin role includes all editor permissions automatically. Check user permissions with a single method call.

Impact

Enforce access controls across your application without building authorization middleware.

FAQ

Common questions about Conjoin Auth

Ship your application today

Start building with Conjoin today. Free tier includes everything you need to prototype and launch. Scale when you're ready.