For identity & security teams

Extend your identity provider to your AI agents.

Same joiner-mover-leaver controls. Zero standing agent privileges.

Your IdP already governs every employee. Eniyan extends it to every agent: people and groups sync in over SCIM, operators delegate the entitlements they actually hold, and agents act on 10-minute OAuth tokens that die with the human's access.

Book a demo

Pick a time that works for you. We'll walk you through Eniyan for your use case.

See the platform

How it works

From connected IdP to governed agents in four steps.

01

Connect your identity provider

Point Eniyan at your IdP over OIDC or SAML 2.0: a discovery URL and client credentials, or your IdP's SAML metadata. Per-org opt-in; password sign-in keeps working.

02

SCIM syncs your people and groups

Mint a SCIM token from the dashboard, paste it into your IdP's provisioning settings, and your users and groups flow in and stay current. Deactivations flow through too.

03

Operators delegate live entitlements

Each operator sees the IdP groups they currently hold and delegates them to the agents they're accountable for. A delegation lives only as long as the human keeps the group.

04

Agents mint scoped 10-minute tokens

Agents exchange their signed credential for OAuth 2.0 access tokens scoped to exactly those live entitlements: PKCE issuance, RFC 7662 introspection, nothing standing.

No identity provider yet? Eniyan runs standalone too — admins sign in with a password, assign each agent's permissions directly, and agents still get 10-minute OAuth tokens with the full Risk Management stack. Federate whenever you're ready.

Joiner · Mover · Leaver

Offboard an agent the way you offboard an employee.

Agent access is tied to a live human identity, not a static secret. Deactivate the person in your IdP and their agents lose access automatically: elapsed time, one token lifetime.

01

Deactivate the human in your IdP

An operator leaves, or loses a role. You deactivate them in your identity provider. It's the same action you already take today.

02

SCIM tells Eniyan

SCIM 2.0 deprovisioning flows through in real time. The operator's record suspends, and every agent anchored to them suspends with it.

03

Delegations lapse instantly

Every entitlement that operator delegated disappears the moment they lose the underlying IdP group. Lose the group, lose the scope.

04

Tokens age out in minutes

Agent tokens live 10 minutes and re-check entitlements at every mint. No standing privileges, no orphaned service accounts.

Compatibility

Works with the identity provider you already run.

Federate over standard OIDC, SAML 2.0, and SCIM. No rip-and-replace, no proprietary connectors. If it speaks OIDC or SAML, it works.

And on the agent side: works with Claude Code, Cursor, and any MCP-compatible agent — including governed gates for what your agents can touch on your own machine and which websites they can visit.

Identity providerOIDC SSOSAML 2.0SCIM provisioningGroup Push
OktaSupportedSupportedSupportedSupported
Microsoft Entra IDSupportedSupportedSupportedSupported
Auth0SupportedSupportedSupportedSupported
OneLoginSupportedSupportedSupportedSupported
Ping IdentitySupportedSupportedSupportedSupported
JumpCloudSupportedSupportedSupportedSupported
Google WorkspaceSupportedSupportedUsers onlyNot supported
Any OIDC / SAML IdPSupportedSupportedSupportedSupported

Google Workspace supports SSO today; group-based delegation needs an IdP with SCIM group push. Don't see yours? If it speaks OIDC or SAML, it works.

Questions about IdP federation, delegation, and offboarding are answered on the FAQ page

Your IdP governs people. Now let it govern agents.

Book a demo

Pick a time that works for you. We'll walk you through Eniyan for your use case.

See the platform