soma-iam

shipped

Every way in, one surface — WebAuthn to SCIM, none of it a tier.

Routes
21637 modules
Applied migrations
52
Auth methods
9human + machine
OpenSSL in build
0pure Rust
The soma-iam surface: WebAuthn, TOTP, email OTP and passwords for humans; M2M tokens, personal access tokens, device flow for systems; SAML, OIDC and SCIM federation above; multi-tenant RBAC with deny overrides under every request FEDERATION & PROVISIONING SAML 2.0 OIDC provider · JWKS / ES256 SCIM 2.0 HUMANS SIGN IN WITH WebAuthn / Passkeys TOTP authenticator apps email OTP passwords — Argon2id SYSTEMS AUTH WITH M2M tokens personal access tokens device authorization flow sessions — ES256 JWT soma-iam 216 routes · 37 modules · 52 migrations pure-Rust crypto · no OpenSSL EVERY REQUEST PASSES multi-tenant RBAC deny overrides audit hooks One surface, every protocol — no per-connection pricing, no adapter marketplace.

In the box

  • WebAuthn / Passkeys — credential blobs encrypted with AES-256-GCM
  • SAML 2.0 federation and a full OIDC provider (JWKS / ES256)
  • SCIM 2.0 provisioning for enterprise directory sync
  • TOTP, email OTP, and the device authorization flow
  • M2M tokens and personal access tokens for services and CLIs
  • Multi-tenant RBAC with deny overrides
← All of SOMA-ControlSource on GitHub →