Skip to content

What is Authwise

Authwise is a multi-tenant OAuth 2.0 and OpenID Connect identity platform. One deployment, called an install, serves many tenants, each with its own issuer, signing keys, users, and clients. You run an install on Kubernetes with the Authwise operator, and you administer it through the admin console, the awctl command line, or the Terraform provider. All three talk to the same Admin API.

An install runs one product, selected at install time and fixed for the life of the install:

ProductPresetFor
Authwiseauthwise-fullCustomer-facing identity: self-service sign-up, social and enterprise sign-in, any population of users.
Authwise WorkplaceworkplaceWorkforce identity: federation first, a multi-factor floor, no open sign-up. The lockdown is compiled into the product, not configured.

Authwise Guard is a separate component: a policy engine and console that authenticates against an install’s issuer and delegates every permission decision to that install’s Access evaluator. It issues no tokens of its own.

Everything in Authwise lives under a parent, and every object has a stable, typed identifier called an AWID. An AWID is unique across the whole install and carries a type prefix, such as t- for a tenant or c- for a client. Objects are also addressed by their full resource name, which spells out the parent chain: tenants/t-01/realms/r-01/users/u-01.

  • Tenant. The isolation boundary. A tenant owns its issuers, realms, audiences, and the people who administer it. Every install starts with one tenant, the admin tenant, which owns the admin console and the Admin API.
  • Issuer. The OpenID Connect issuer a set of clients shares: the URL users are sent to, the signing keys, the token lifetimes. An issuer is reached on a domain the tenant serves logins on, and it routes each login to a realm.
  • Realm. A population of users with its own sign-in providers, multi-factor policy, and branding. A realm belongs to a tenant and is served by one or more issuers.
  • Audience. An API that tokens are minted for. Scopes, permissions, roles, and role bindings hang off an audience; together they are the Access catalog.
  • Client. An OAuth 2.0 client of an issuer: a browser app, a native app, or a machine with a client secret. A client names the audience its tokens are for.
  • User. A person in a realm. A user signs in with one or more identifiers, such as a password-backed email address or a federated account, and can enrol authenticators for a second factor.
  • Provider and factor. A provider is a way to sign in to a realm: password, magic link, passkey, a social provider, an enterprise OpenID Connect or SAML identity provider. A factor is a second step the realm’s policy can require.
  • Theme, appearance profile, asset. Branding for the hosted login pages and the admin console: layouts, colors, logos.
  • Secret, certificate, endpoint. Named credentials an integration needs, the X.509 material for SAML, and outbound HTTP or gRPC destinations the install calls with a checked TLS configuration.

An install is a set of workloads the operator deploys and keeps in step:

SurfaceWhat it does
Identity serverServes the OAuth 2.0 and OpenID Connect endpoints for every issuer, and the hosted login and account pages. Clients and users talk to this.
Admin APIManages everything inside a tenant over gRPC with an HTTP gateway. The console, awctl, and the Terraform provider talk to this.
Admin consoleThe browser application for administrators of a tenant.
Login layouts and account pageThe hosted user interface the identity server serves for sign-in, consent, and account security.
Platform serviceKey management, object storage for assets, and outbound messaging such as email.
ID serviceOptional. Mints short, sortable AWIDs instead of the default UUID-derived ones.

Creating tenants is not an Admin API operation. The bearer-token Admin API lists the tenants you belong to and manages objects inside them; tenant lifecycle lives on a separate operator-only surface.

ToolUse it for
Authwise operatorRunning an install on Kubernetes: the workloads, the database bootstrap, the first administrator, and upgrades.
awctlDay-to-day administration from a terminal, and scripting. Its commands mirror the Terraform resources.
Terraform providerConfiguration as code inside a tenant: issuers, realms, clients, the Access catalog, sign-in providers, branding.

The Quickstart walks the three in order: install, sign in, connect the tools.