Skip to content
Start free
XID

Your customers need sign-in, SSO and admins.XID is one product for all of it.

Hosted sign-in, OIDC, SSO and SCIM per organization, one console.

Free today. No plans or tiers.

XID console users list for Northwind Logistics, with sign-in methods and organizations per userXID console users list for Northwind Logistics, with sign-in methods and organizations per user

You don't want to build sign‑in and account pages.XID hosts them in your brand.

Your app redirects to XID and gets the user back with tokens. Afterward, people manage their sessions, devices and data on their own account page.

Hosted sign-in docs
Account devices page where a user sees and signs out their sessionsAccount devices page where a user sees and signs out their sessions

Email link and code sign-in: verified in production on xid.dev. Other sign-in methods and the account page: verified locally.

Your auth vendor shouldn't be in every service.XID is a standard OpenID Connect provider.

Use our SDKs or any OIDC library. Access tokens are signed JWTs that carry the organization, and your backend verifies them without a network call.

Connect your app
server.tsts
import { authenticateRequest } from '@xid-kit/backend'

const state = await authenticateRequest(request, {
  jwtKey: env.XID_JWKS_PUBLIC_KEY,
  issuer: 'https://xid.dev',
})
if (!state.isSignedIn) return new Response('Unauthorized', { status: 401 })

Example access token

Decoded header and payload
typ
at+jwt
alg
ES256
iss
https://xid.dev
sub
user_ExampleUser0000000001
aud
examplenorthwindweb0000001
azp
examplenorthwindweb0000001
client_id
examplenorthwindweb0000001
scope
openid profile email organization
iat
1791394200
exp
1791397800
tenant_id
org_ExampleNorthwind00001Northwind Logistics

Example values in the shape XID issues. This is not a real token.

Authorization code flow: verified locally with protocol clients. SDKs are not yet published to npm.

Your biggest deal is waiting on SSO and SCIM.Every customer gets an organization with both.

Each organization has its own SAML or OIDC connection, SCIM directory, verified domains and MFA policy. When IT deactivates someone, XID ends their sessions.

Enterprise SSO docs
Inbound SSO connections in the XID console with an active Okta SAML connectionInbound SSO connections in the XID console with an active Okta SAML connection
Directory sync in the XID console with an active Okta SCIM directory, its user and group counts and last syncDirectory sync in the XID console with an active Okta SCIM directory, its user and group counts and last sync

Verified locally against test identity providers. Not yet verified with a live Okta or Entra ID tenant.

Every customer's SSO setup lands in your support queue.Their admins can do it themselves.

One console for you and them. You see every organization; their admins see only theirs, with the same pages for members, SSO, branding and audit logs.

Organizations docs
Organization switcher in the XID console listing the organizations and projects the admin managesOrganization switcher in the XID console listing the organizations and projects the admin manages

Switching organizations in the console: verified in production on xid.dev.

Choosing hosted shouldn't lock you in.Cloud and self‑hosted are one product.

XID Cloud is free today. If it ever charges, it bills only per monthly active user, never by plan. Self-hosted, billing is off unless you turn it on.

License
MIT
Codebase for Cloud and self-hosted
1
Cloudflare Workers
3
Interface languages
8

Type to search

Use arrow keys to navigateEnter to selectEscape to close