Identity management built right.
SineAuth is an identity provider built on open standards. Add secure authentication, single sign-on, and multi-factor authentication to your applications.

Everything you need to secure your users.
Enterprise-grade authentication features, built on open standards.
Protect accounts with TOTP authenticator apps and FIDO2 passkeys. Users can enroll multiple methods and fall back to recovery codes when needed.

More tools for the full picture.
Security goes beyond the login screen.
Security event log
A complete audit trail for every account action.
Every login, password change, session revocation, and 2FA event is recorded with timestamp, IP address, and user agent for full visibility.

Application management
Manage your connected applications in one place.
Create and configure OAuth clients with custom redirect URIs, grant types, scopes, and consent screens directly from the admin panel.

Multi-tenancy
Teams and organizations.
Support for organizations, letting users create tenants (organizations) and manage access for their own applications independently. Internal teams for delegated management coming soon.

A complete audit trail for every account action.
Every login, password change, session revocation, and 2FA event is recorded with timestamp, IP address, and user agent for full visibility.
Manage your connected applications in one place.
Create and configure OAuth clients with custom redirect URIs, grant types, scopes, and consent screens directly from the admin panel.
Teams and organizations.
Support for organizations, letting users create tenants (organizations) and manage access for their own applications independently. Internal teams for delegated management coming soon.


See it in action.
SineAuth is deployed and running. Try the demo instance to explore the full login experience, including multi-factor authentication and account settings.
Built on open standards.
SineAuth implements established protocols — no proprietary lock-in, no custom auth schemes.
Simple pricing.
Free to use while in development. An enterprise tier with on-premises deployment is on the roadmap.
Alpha
Available nowFree while in development. It always works, most of the time.
$0/ month
Get started for free- Hosted by us, easy to integrate
- OAuth2 & OIDC single sign-on (SSO)
- Multi-factor authentication (TOTP + WebAuthn/Passkeys)
- Register and manage your own client applications
- Session management & revocation
- Security event logging
- Rate limiting & CAPTCHA protection
- Best-effort support

Frequently asked questions
Can't find what you're looking for? Feel free to reach out.
What OAuth flows does SineAuth support?
Authorization Code with PKCE is the primary flow. SineAuth also supports token introspection, token revocation, and a full OIDC userinfo endpoint.
What multi-factor authentication methods are available?
SineAuth supports TOTP via authenticator apps like Google Authenticator and WebAuthn (FIDO2) for security keys and passkeys. Users can enroll both methods and use recovery codes as a fallback.
Can I run SineAuth on my own server?
The Alpha tier uses the hosted service at auth.sinenie.cl. Enterprise customers can deploy on-premises, and our team will work with you to make it happen.
Does SineAuth support multiple applications?
Yes. You can register multiple OAuth2 client applications under a single account, each with its own redirect URIs, scopes, and client credentials.
Does SineAuth support passkeys?
Yes. WebAuthn (FIDO2) is fully supported, including both roaming security keys and platform authenticators like Touch ID and Windows Hello.
What claims are included in the ID token?
The standard OIDC claims: sub, name, email, email_verified, and picture. A custom session_id claim is also included for session-level validation. Support for custom claims is on the roadmap.
Is SineAuth production-ready?
Not yet, but we're building towards it. The interface and feature set are still actively evolving during the Alpha period, also.
Is there a demo instance I can try?
Yes, a live instance is running at auth.sinenie.cl. You can register an account, enable 2FA, and explore the full account settings interface.
How does it handle brute force attacks?
Failed login attempts trigger Cloudflare Turnstile CAPTCHA after a configurable threshold (default: 3 attempts). All sensitive endpoints are also rate-limited per IP address.


