Guardhouse features

Authentication, authorization, and machine identity without building it all yourself.

Guardhouse provides hosted sign-in and account recovery, consistent access rules for applications, and operational tools for users and sessions. Your team keeps control of its access model without running the identity screens, tokens, and protocol endpoints behind it.

View Documentation

Identity coverage

People, applications, and services

Available now
People
Hosted sign-in, MFA, passkeys, and self-service
Applications and APIs
OAuth, OpenID Connect, scopes, and token validation
Services and AI
Machine credentials for backend, agent, and MCP workloads

Build versus integrate

Identity work does not end when the login form ships.

An internal solution makes your team responsible for protocols, recovery paths, administration, abuse controls, and ongoing security work. Guardhouse keeps those capabilities together so your team can focus on the access rules and product experience specific to your business.

When you build it internally

Your product and engineering teams own:

  • Sign-in, verification, recovery, MFA, and passkey flows
  • OAuth and OpenID Connect behavior, keys, tokens, and revocation
  • Roles, permissions, administrator tooling, and support workflows
  • Session controls, activity context, email, branding, and upgrades

When you integrate Guardhouse

Your team configures and connects:

  • Hosted authentication methods and customer self-service
  • Standards-based clients, resources, audiences, and scopes
  • Central roles, permissions, user administration, and APIs
  • Branded experiences, security controls, and deployment choices

Authentication

Ship complete sign-in flows without maintaining an identity UI

Guardhouse hosts sign-up, sign-in, recovery, MFA, and profile flows, not just the token endpoint. Teams can offer familiar sign-in methods without owning the security-sensitive UI and flow logic.

Why it matters: Product teams get complete sign-in and recovery journeys. Developers integrate one identity service, and users see the same controls wherever account security appears.

Email, password, and passwordless access

Available now

Use hosted email-and-password sign-up and sign-in, verified email, password recovery, expiring invitations, and single-use magic links.

Launch the essential account journeys without designing token storage, recovery screens, and email-verification state in every application.

Most useful for: Developers, Product and project teams, Business leaders

  • Open or invite-only registration
  • Configurable sign-in methods and primary login
  • Email verification and password recovery

Social login

Available now

Offer Google, Microsoft, Apple, and Facebook sign-in through the same hosted experience as first-party accounts.

Customers can use an existing provider account without your team maintaining four separate integrations and account-linking rules.

Most useful for: Developers, Product and project teams

  • Linked social identity management
  • Provider configuration per project

MFA recovery and passkeys

Available now

Add authenticator-app TOTP, recovery codes, trusted devices, administrator MFA reset, and WebAuthn passkeys for enrollment and sign-in.

Security teams can require stronger sign-in methods while product teams avoid building enrollment, challenge, recovery, and credential-management screens.

Most useful for: Developers, Product and project teams, Security and operations

  • Configurable trusted-device duration
  • User-managed passkey naming and revocation
  • Administrator-assisted MFA recovery

OAuth, OpenID Connect, and API protection

Use standard protocols from the browser to the backend

Guardhouse issues and validates identity and access tokens for web, mobile, API, and service workloads using OAuth 2.0 and OpenID Connect.

Why it matters: Developers work with established protocols and libraries instead of designing a proprietary session and API-token system.

Application authorization flows

Available now

Configure web and mobile clients with the Authorization Code flow and PKCE, refresh tokens, discovery metadata, redirect and logout URIs, and allowed CORS origins.

Connect different application types to one authorization server without maintaining a separate protocol implementation for each client.

Most useful for: Developers, Security and operations

  • OAuth 2.0 and OpenID Connect discovery
  • Authorization Code with PKCE
  • Configurable token lifetimes and client-secret rotation

Scoped API access

Available now

Register API resources, audiences, and OAuth scopes, then protect endpoints with signed JWT access tokens verified through published JWKS keys.

API teams get consistent token validation and explicit access boundaries instead of adding one-off API keys and claim formats to every service.

Most useful for: Developers, Security and operations

  • Custom API resources and audiences
  • Signed JWT access tokens and JWKS verification
  • Scope and claim enforcement in application middleware

Introspection and revocation

Available now

Use token introspection where an API must check current authorization state, and revoke grants, refresh tokens, or sessions when access should end.

APIs that use introspection can reject revoked access on the next status check, while other endpoints can keep efficient local JWT validation.

Most useful for: Developers, Security and operations

  • Revocation enforcement on the API’s next introspection check
  • Locally validated JWTs remain valid until their configured expiry
  • Revocation and introspection endpoints

Authorization

Keep product access rules in one understandable model

Roles, inherited and direct permissions, OAuth scopes, and token claims connect administrative policy to application enforcement.

Why it matters: Teams can change who may do what without duplicating permission tables and policy plumbing across every application and API.

Roles and fine-grained permissions

Available now

Define reusable roles, assign precise permissions, inherit access through role relationships, and grant exceptions directly to individual users.

Product and support teams can model real responsibilities while developers avoid scattering role-name checks throughout the codebase.

Most useful for: Developers, Product and project teams, Security and operations

  • Custom roles and role inheritance
  • Role-based and direct user permissions
  • Administrative role and permission assignment

Scopes, claims, and API enforcement

Available now

Expose approved access as scopes and claims that applications and APIs can enforce with standard authorization middleware.

Developers receive a consistent contract for access decisions, and security teams can trace those decisions back to centralized configuration.

Most useful for: Developers, Security and operations

  • Configurable OAuth scopes
  • Role and permission claims in tokens
  • API-side policy enforcement

User administration

Give operations teams the controls they need to help users

The administrator console and Management API cover day-to-day account operations, authorization assignments, and controlled migration into Guardhouse.

Why it matters: Support staff resolve common identity problems directly, while developers stop building internal account-management tools for routine work.

User lifecycle administration

Available now

Search and filter users, create or invite accounts, block and unblock access, reset passwords or MFA, assign access, and delete or anonymize personal data.

Support and operations teams can respond to account issues without database access or an engineering handoff.

Most useful for: Product and project teams, Business leaders, Security and operations

  • User search and filtering
  • Password and MFA reset
  • Role and permission assignment
  • Blocking, deletion, and personal-data handling

System and Management API

Available now

Automate supported user, role, and permission operations through documented administrative endpoints.

Developers can connect existing back-office workflows without screen automation or direct writes to identity storage.

Most useful for: Developers, Security and operations

  • User administration endpoints
  • Role and permission endpoints

Migration assistance and bulk user import

Available now

Move an existing user base with bulk user import and migration assistance scoped to the source system and rollout.

Teams get an agreed import and cutover plan for the source system instead of building an ad hoc migration process.

Most useful for: Developers, Product and project teams, Business leaders, Security and operations

  • Bulk user import
  • Migration scope agreed before rollout

Note: Migration requirements vary by source system. Guardhouse defines the supported import and cutover scope with the customer before rollout.

User self-service

Let users manage account security without opening a ticket

A hosted, branded profile portal gives each user a clear place to update personal details, credentials, linked identities, and active access.

Why it matters: Customers get direct control over their account, support queues stay smaller, and product teams avoid maintaining a second security-settings application.

Profile and credentials

Available now

Users can manage their profile and avatar, complete a verified email change, update their password, and link or unlink supported social identities.

Common profile and credential changes stay secure and self-contained instead of becoming custom forms and support procedures.

Most useful for: Developers, Product and project teams, Business leaders

  • Profile, avatar, verified email, and password management
  • Linked social accounts
  • User-managed MFA and passkeys

Session visibility and sign-out

Available now

Users can review active browser sessions and OAuth application sessions, revoke individual access, or sign out every other device.

Users can revoke a lost or unfamiliar session without resetting the whole account. APIs can reject revoked tokens on their next introspection check.

Most useful for: Product and project teams, Security and operations

  • Browser session controls
  • OAuth application session controls
  • Sign out all other devices

Account deletion and profile export

Available now

Let users delete their account under configured policy and download a ZIP containing their basic Guardhouse profile data.

Product teams can offer core account-data controls without building a separate deletion and export workflow.

Most useful for: Product and project teams, Business leaders, Security and operations

  • Configurable self-service policies
  • Basic profile ZIP export

Note: The profile export covers basic Guardhouse profile data. It is not presented as a complete export of every record held by the customer’s product.

White-label branding

Keep authentication inside the product’s visual identity

Guardhouse hosts sign-up, sign-in, recovery, consent, and profile pages, with controls for their appearance and custom hostname.

Why it matters: Customers move through one recognizable experience, and design and engineering teams do not have to own a parallel set of identity screens.

Hosted pages with HTML and CSS control

Available now

Apply themes, logos, favicons, typography, layout, custom text, legal links, and advanced per-page or per-state HTML and CSS.

Design teams can match the product closely while Guardhouse continues to operate the underlying authentication and account flows.

Most useful for: Developers, Product and project teams, Business leaders

  • Visual theme editor and brand assets
  • Advanced HTML and CSS customization
  • Custom social and legal links

Localized identity experience

Available now

Present the hosted interface in seven supported languages with consistent branded content across authentication and profile pages.

Product teams can serve supported markets without maintaining translations across a separate identity interface.

Most useful for: Product and project teams, Business leaders

  • Seven supported interface languages
  • Shared brand content across hosted flows

Custom authentication domains

Available now

Configure a customer-controlled authentication hostname through the Guardhouse Customer Portal workflow, including the required DNS and activation steps.

Customers use a recognizable authentication hostname without the product team building domain verification and routing tools.

Most useful for: Developers, Product and project teams, Business leaders, Security and operations

  • Customer Portal setup workflow
  • DNS verification and domain activation

Security, sessions, and activity

Investigate account access and revoke it from one place

Guardhouse combines account protections, access invalidation, security history, and sign-in context in one console.

Why it matters: Security and operations teams can investigate and respond without assembling a separate session console or identity event store.

Account and session controls

Available now

Lock accounts after repeated failed sign-ins, inspect active sessions, invalidate access when an administrator blocks a user, and rotate application secrets.

Operations teams can contain common access incidents without editing identity records or waiting for every session to expire naturally.

Most useful for: Developers, Security and operations

  • Configurable account lockout
  • Administrator-triggered access invalidation
  • Session and OAuth grant revocation
  • Client-secret rotation

Security activity

Available now

Review sign-in, password, MFA, passkey, token, and session events alongside device, browser, IP, and available location details.

Support and security teams can reconstruct relevant account activity without asking developers to correlate application logs by hand.

Most useful for: Product and project teams, Security and operations

  • Sign-in and account-security events
  • Device, browser, IP, and location context
  • Activity retention follows the selected plan or agreed Enterprise configuration

Enriched sign-in context

Available on Enterprise

Enterprise teams can record ASN and ISP, country and city, language, proxy and hosting indicators, bot indicators, and confidence signals alongside sign-in activity.

Investigators get more context for triage without operating a separate IP-enrichment pipeline.

Most useful for: Security and operations

  • Context for investigation and policy review
  • Signals do not automatically block access

Webhooks and transactional email

Connect identity changes to the rest of the product

Guardhouse sends the identity email users expect and exposes a precise set of signed user-lifecycle events for downstream systems.

Why it matters: Teams can operate branded verification and recovery email and react to supported user changes without adding another email-template system or polling job.

Your choice of email delivery provider

Available now

Configure SMTP, Postmark, SendGrid, or Amazon SES for each project.

Operations teams can use an established delivery account and policy instead of adopting a second email stack solely for authentication.

Most useful for: Developers, Product and project teams, Security and operations

  • SMTP
  • Postmark
  • SendGrid
  • Amazon SES

Editable transactional email templates

Available now

Customize 17 identity-email templates, preview their output, and send tests before using them in a live account flow.

Product and support teams can keep critical account messages clear and on-brand without changing application code.

Most useful for: Product and project teams, Business leaders

  • 17 editable templates
  • Preview and test delivery
  • Branded account messaging

Signed user webhooks

Available now

Subscribe to UserCreated and UserUpdated events with HMAC-SHA256 signatures, configurable retries, endpoint controls, secret rotation, and delivery history.

Developers can synchronize supported lifecycle changes without polling the Management API or accepting unsigned callbacks.

Most useful for: Developers, Security and operations

  • UserCreated and UserUpdated events
  • HMAC-SHA256 request signatures
  • Retries and delivery history

Machine identities, APIs, and AI

Issue scoped OAuth tokens to services and AI workloads

Client Credentials, API resources, scopes, audiences, and standard token validation protect service-to-service calls, AI agents, and MCP servers.

Why it matters: Engineering and security teams can govern machine access without distributing permanent shared API keys or introducing a separate identity layer for agents.

Service-to-service authentication

Available now

Issue scoped tokens through the OAuth 2.0 Client Credentials flow for backend services, automation, scheduled jobs, and API clients.

Developers replace long-lived shared secrets at API boundaries with short-lived, audience-bound access tokens.

Most useful for: Developers, Security and operations

  • Client Credentials flow
  • Service clients, scopes, and audiences
  • JWT validation or introspection

OAuth protection for AI agents and MCP servers

Available now

Protect an agent, tool API, or MCP server as an OAuth resource and validate the same scoped tokens used by other Guardhouse-protected APIs.

Use scoped OAuth access for agents and MCP servers instead of creating a separate credential scheme.

Most useful for: Developers, Product and project teams, Security and operations

  • Standards-based OAuth resource protection
  • Token introspection for revocable service access
  • Guardhouse authorizes access to MCP servers; it is not an MCP gateway

SDKs and integrations

Integrate with the stack your team already uses

Guardhouse SDKs handle common OAuth, session, and framework integration work for web, mobile, and backend applications. Each SDK is marked Stable or Beta.

Why it matters: Developers spend less time on middleware and session plumbing while retaining standards-based integration options.

.NET and ASP.NET Core

Available now

Use the stable .NET SDK and ASP.NET Core integration for authentication, authorization, API protection, and service clients.

.NET teams can adopt Guardhouse through familiar dependency injection and middleware patterns.

Most useful for: Developers

React

Available now

Use the stable React SDK and hooks to connect browser applications to hosted sign-in and authenticated application state.

Frontend teams avoid writing their own redirect, callback, token, and session-state layer.

Most useful for: Developers, Product and project teams

Node.js and React Native

Beta

Evaluate Beta SDK support for Node.js server applications and React Native mobile applications.

Teams get framework-specific helpers, with Beta status shown before production adoption.

Most useful for: Developers, Product and project teams

Python, FastAPI, and Flask

Beta

Use the Beta Python SDK with helpers for FastAPI and Flask applications and protected APIs.

Python teams can start from framework-aware integration code rather than assembling OAuth and token validation from low-level libraries.

Most useful for: Developers

Deployment and infrastructure

Start managed, or choose who operates Enterprise

Guardhouse Cloud provides primary EU and US regions. Enterprise is tailored to your requirements and can be operated by your team or by LegioSoft on LegioSoft infrastructure.

Why it matters: Business and technical leaders can choose operational convenience or infrastructure control without changing the identity model used by their product.

Guardhouse Cloud in the EU and US

Available now

Run a managed Cloud instance in the EU primary region in Madrid or the US primary region in Chicago.

Teams can begin without operating the identity infrastructure and select the primary region that fits their deployment plan.

Most useful for: Developers, Business leaders, Security and operations

  • EU primary region: Madrid
  • US primary region: Chicago

Cloud storage and email providers

Available now

Choose the email provider and supported object-storage provider used by the Cloud project, including Cloudflare R2, Amazon S3, and Oracle Object Storage.

Operations teams can use existing provider accounts and policies for identity email and stored assets.

Most useful for: Developers, Business leaders, Security and operations

  • Cloudflare R2
  • Amazon S3
  • Oracle Object Storage
  • Customer-selected transactional-email provider

Customer-operated self-hosting

Available on Enterprise

Run Guardhouse Enterprise in customer-controlled infrastructure and choose the database, storage, and hosting components.

Infrastructure and security teams retain operational ownership while product teams keep the same Guardhouse identity capabilities.

Most useful for: Developers, Business leaders, Security and operations

  • Docker-based deployment foundations
  • Customer-selected database and storage architecture
  • Customer-controlled hosting and operations

LegioSoft-operated Enterprise

Available on Enterprise

Choose an Enterprise deployment operated by LegioSoft on LegioSoft infrastructure.

Organizations can agree a managed Enterprise operating model without taking on day-to-day platform operations.

Most useful for: Business leaders, Security and operations

  • Hosting and location tailored to your requirements
  • Responsibilities, support, and account management agreed with your team

Enterprise identity

Connect workforce directories and model B2B access

Enterprise identity covers organizations and memberships, federation, and managed user provisioning for products with customer or workforce directories.

Why it matters: Enterprise customers can connect established identity systems and lifecycle processes instead of duplicating directory data and account operations by hand.

B2B organizations and memberships

Available on Enterprise

Model customer organizations, membership, and organization-aware access within the Guardhouse identity layer.

B2B teams can represent customer tenancy and assign access without building a separate membership service.

Most useful for: Developers, Product and project teams, Business leaders, Security and operations

Enterprise OIDC and SAML SSO

Available on Enterprise

Connect an enterprise customer’s identity provider through OpenID Connect or SAML single sign-on.

Business customers can use their established sign-in policy while the product team avoids maintaining separate federation implementations.

Most useful for: Developers, Business leaders, Security and operations

  • Enterprise OpenID Connect connectors
  • SAML SSO

Active Directory and LDAP federation

Available on Enterprise

Connect compatible Active Directory and LDAP identity environments for Enterprise sign-in requirements.

Users keep their directory credentials, and product teams do not maintain a separate password store for them.

Most useful for: Developers, Business leaders, Security and operations

SCIM provisioning

Available on Enterprise

Provision, update, and deprovision users through SCIM as their access requirements change.

IT and security teams can connect employee onboarding, role changes, and offboarding without manual account updates in the product.

Most useful for: Developers, Business leaders, Security and operations

Value across the team

What each team gets from Guardhouse

Developers integrate Guardhouse, product and delivery teams configure it, and security and operations teams control access and deployment.

  1. Developers

    Integrate identity without inheriting an identity codebase

    Use standard OAuth and OpenID Connect, documented APIs, and framework SDKs while Guardhouse operates the account flows around them.

    • Less authentication, recovery, MFA, and session code to own
    • Scoped API and machine access built on standard protocols
    • Stable .NET and React SDKs, with clearly labeled Beta integrations
  2. Product and project teams

    Keep account infrastructure off the product backlog

    Start with complete hosted journeys, then configure methods, policies, branding, and self-service as the product changes.

    • Reusable sign-up, sign-in, recovery, and profile experiences
    • Clear administrative and customer self-service scope
    • Brand and localization controls without maintaining every screen
  3. Business leaders

    Start on managed Cloud and retain a flexible Enterprise option

    Keep the customer journey on-brand, evaluate published plan allowances, and move to Enterprise operated by your organization or LegioSoft when requirements change.

    • Predictable plan allowances for human and machine usage
    • White-label experiences and customer-controlled domains
    • Migration assistance with agreed scope, plus managed Cloud or tailored Enterprise
  4. Security and operations

    Centralize identity controls and choose how APIs enforce access

    Manage authentication strength, permissions, sessions, revocation, sign-in context, and deployment boundaries from one identity system.

    • Account lockout, MFA, passkeys, and administrator access invalidation
    • Session visibility and introspection for current revocation status
    • Managed Cloud plus customer-operated or LegioSoft-operated Enterprise models

Continue evaluating

Review pricing, integrations, and deployment options

Compare plans, choose an SDK or protocol guide, and review Cloud and Enterprise deployment options.

Put Guardhouse behind your next sign-in.

Start with the hosted flow, follow the integration guides, or talk through an Enterprise deployment with the Guardhouse team.