The platform

One fabric for every identity.

HelixIAM is a complete, Keycloak-class identity platform — and the only one that treats humans, AI agents, and workloads as first-class citizens of the same system. Explore the eight pillars.

Feature complete

Everything, shipped and documented.

Authentication

  • Passkeys / WebAuthn (FIDO2)
  • TOTP, SMS-OTP, Email-OTP, HOTP
  • Device push + mobile SDK
  • Magic-link passwordless
  • Recovery codes
  • Risk-based / adaptive step-up

SSO & Federation

  • OpenID Connect provider
  • SAML 2.0 IdP & SP
  • Social & OIDC brokers
  • LDAP / Active Directory
  • JIT provisioning + account linking
  • Single Logout (front, back, SAML)

Non-human identity

  • AI-agent registry & lifecycle
  • RFC 8693 token exchange (act-as)
  • Workload Identity Federation
  • Scoped & attenuated tokens
  • Consent + kill-switch
  • MCP-ready auth (OAuth 2.1)

European eIDs

  • eIDAS (EU cross-border)
  • eHerkenning (NL business)
  • DigiD (NL citizen)
  • Assurance levels
  • Per-realm branding
  • NL-i18n

Developer & admin

  • Keycloak-class admin console
  • TypeScript SDK + adapters
  • Terraform provider (IaC)
  • Config-as-code (import/export)
  • Keycloak importer
  • OpenAPI + SCIM 2.0

Security & compliance

  • FAPI + mTLS-bound tokens
  • DPoP (RFC 9449)
  • Per-realm KMS keys + rotation
  • Searchable audit log + SIEM
  • GDPR rights tooling
  • Brute-force + password policy

See HelixIAM on your own stack.

A 30-minute demo: realms, agents, workload identity, and a live migration off Keycloak — mapped to your use case.

No credit card. Self-hostable. Engineered in Europe.