What is Authwise
Authwise is a multi-tenant OAuth 2.0 and OpenID Connect identity platform.
One deployment, called an install, serves many tenants, each with its own
issuer, signing keys, users, and clients. You run an install on Kubernetes with
the Authwise operator, and you administer it through the admin console, the
awctl command line, or the Terraform provider. All three talk to the same
Admin API.
Products
Section titled “Products”An install runs one product, selected at install time and fixed for the life of the install:
| Product | Preset | For |
|---|---|---|
| Authwise | authwise-full | Customer-facing identity: self-service sign-up, social and enterprise sign-in, any population of users. |
| Authwise Workplace | workplace | Workforce identity: federation first, a multi-factor floor, no open sign-up. The lockdown is compiled into the product, not configured. |
Authwise Guard is a separate component: a policy engine and console that authenticates against an install’s issuer and delegates every permission decision to that install’s Access evaluator. It issues no tokens of its own.
The objects
Section titled “The objects”Everything in Authwise lives under a parent, and every object has a stable,
typed identifier called an AWID. An AWID is unique across the whole install and
carries a type prefix, such as t- for a tenant or c- for a client. Objects
are also addressed by their full resource name, which spells out the parent
chain: tenants/t-01/realms/r-01/users/u-01.
- Tenant. The isolation boundary. A tenant owns its issuers, realms, audiences, and the people who administer it. Every install starts with one tenant, the admin tenant, which owns the admin console and the Admin API.
- Issuer. The OpenID Connect issuer a set of clients shares: the URL users are sent to, the signing keys, the token lifetimes. An issuer is reached on a domain the tenant serves logins on, and it routes each login to a realm.
- Realm. A population of users with its own sign-in providers, multi-factor policy, and branding. A realm belongs to a tenant and is served by one or more issuers.
- Audience. An API that tokens are minted for. Scopes, permissions, roles, and role bindings hang off an audience; together they are the Access catalog.
- Client. An OAuth 2.0 client of an issuer: a browser app, a native app, or a machine with a client secret. A client names the audience its tokens are for.
- User. A person in a realm. A user signs in with one or more identifiers, such as a password-backed email address or a federated account, and can enrol authenticators for a second factor.
- Provider and factor. A provider is a way to sign in to a realm: password, magic link, passkey, a social provider, an enterprise OpenID Connect or SAML identity provider. A factor is a second step the realm’s policy can require.
- Theme, appearance profile, asset. Branding for the hosted login pages and the admin console: layouts, colors, logos.
- Secret, certificate, endpoint. Named credentials an integration needs, the X.509 material for SAML, and outbound HTTP or gRPC destinations the install calls with a checked TLS configuration.
The surfaces
Section titled “The surfaces”An install is a set of workloads the operator deploys and keeps in step:
| Surface | What it does |
|---|---|
| Identity server | Serves the OAuth 2.0 and OpenID Connect endpoints for every issuer, and the hosted login and account pages. Clients and users talk to this. |
| Admin API | Manages everything inside a tenant over gRPC with an HTTP gateway. The console, awctl, and the Terraform provider talk to this. |
| Admin console | The browser application for administrators of a tenant. |
| Login layouts and account page | The hosted user interface the identity server serves for sign-in, consent, and account security. |
| Platform service | Key management, object storage for assets, and outbound messaging such as email. |
| ID service | Optional. Mints short, sortable AWIDs instead of the default UUID-derived ones. |
Creating tenants is not an Admin API operation. The bearer-token Admin API lists the tenants you belong to and manages objects inside them; tenant lifecycle lives on a separate operator-only surface.
The tools
Section titled “The tools”| Tool | Use it for |
|---|---|
| Authwise operator | Running an install on Kubernetes: the workloads, the database bootstrap, the first administrator, and upgrades. |
awctl | Day-to-day administration from a terminal, and scripting. Its commands mirror the Terraform resources. |
| Terraform provider | Configuration as code inside a tenant: issuers, realms, clients, the Access catalog, sign-in providers, branding. |
The Quickstart walks the three in order: install, sign in, connect the tools.