Skip to content
All building blocks

Platform

Let customers sign in with the identity provider they already run

Federate Entra ID, Okta, Google Workspace, or any OIDC provider, without building and maintaining the protocol plumbing yourself.

The problem it removes

Every enterprise customer brings a different identity provider. Building and maintaining a connector for each one drains your engineering time.

Get it wrong and you inherit token-handling bugs, replay risk, and a fresh security review for every provider you add.

How Thoryn solves it

Thoryn is an OAuth 2.0 and OIDC broker. Your app integrates once, and each customer attaches their own provider behind that single connection.

Entra ID, Okta, Google Workspace, and generic OIDC providers are self-service through the console wizard or the federation-member API.

PKCE and Pushed Authorization Requests are on by default. SAML providers are attached by our team on request, so eIDAS and long-tail SAML tenants are covered too.

What you get

  • One OIDC connection for your app; customers attach their own provider

  • Self-service Entra ID, Okta, Google Workspace, and generic OIDC federation

  • PKCE (RFC 7636) and Pushed Authorization Requests (RFC 9126) on by default

  • Per-tenant claim mapping from the provider's ID token

  • SAML federation attached on request for enterprise and eIDAS tenants

Ready to build on the platform?

Create an account and wire your first login, or talk to us about a pilot.