One identity provider for every AI agent.
The agents you run, and the agents your customers send.
Your workforce signs in with your IdP. Now your agents do too.
Operators delegate their live entitlements. Agents get 10-minute tokens scoped to exactly those. Deactivate the human, and their agents suspend with them.
See how the platform works →Willa's grocery agent shops with her money: under her rules.
Consent-scored delegations with per-transaction caps, budgets, and approved counterparties baked into every 5-minute token. Revoke it, and the very next check says inactive.
Explore Transaction Governance →Both directions, on the record.
Every mint, refusal, revocation, and attestation, workforce and consumer alike, lands in one tamper-evident audit chain, delivered by webhook in real time.
The platform
One control plane. Identity and risk.
Federate your agents to the identity provider you already run, delegate live entitlements instead of secrets, and govern every action at runtime: one auditable chain from an accountable human to the agents acting for them.
Federate
Connect your identity provider
OIDC/SAML SSO and SCIM 2.0 sync your people and groups, and when someone is deactivated, their agents suspend with them. Your joiner–mover–leaver process, extended to agents.
Delegate
Entitlements, not secrets
Operators delegate their live IdP entitlements to agents. Each agent trades a verifiable credential for a 10-minute OAuth token scoped to exactly those entitlements. No static secrets, no standing access.
Govern
Risk Management
Control what agents actually do at runtime. Enforce scope, grant access just-in-time with zero standing privileges, attest tasks after the fact, and detect operator and insider risk.
Capabilities
Everything an identity team expects, and the risk controls agents demand.
IdP Federation
Connect your identity provider
Risk Management
Govern what agents do
Consumer Delegation
Agentic transaction governance
Verification & Transparency
Public agent verification
What your customers see
Verification anyone can check. No account required.
Consumer-facing agents get a public verification page with a structured scope checklist and the Eniyan seal, supporting EU AI Act Article 50 disclosure. And a signed view link shows each customer exactly what they delegated: scopes, caps, remaining budget, and the step-up rules protecting them.
public verification page · pairwise · no PII
Compatibility
Works with the identity provider you already run.
Federate over standard OIDC, SAML 2.0, and SCIM. No rip-and-replace, no proprietary connectors. If it speaks OIDC or SAML, it works.
| Identity provider | OIDC SSO | SAML 2.0 | SCIM provisioning | Group Push |
|---|---|---|---|---|
| Okta | Supported | Supported | Supported | Supported |
| Microsoft Entra ID | Supported | Supported | Supported | Supported |
| Auth0 | Supported | Supported | Supported | Supported |
| OneLogin | Supported | Supported | Supported | Supported |
| Ping Identity | Supported | Supported | Supported | Supported |
| JumpCloud | Supported | Supported | Supported | Supported |
| Google Workspace | Supported | Supported | Users only | Not supported |
| Any OIDC / SAML IdP | Supported | Supported | Supported | Supported |
Google Workspace supports SSO today; group-based delegation needs an IdP with SCIM group push. Don't see yours? If it speaks OIDC or SAML, it works.
Why Eniyan
Not another secret to rotate.
Service accounts and secrets managers still leave you with standing credentials no one owns. Eniyan ties every agent to a live human identity, and takes the access away the moment that human loses it.
| DIY service accounts | Secrets manager | Eniyan | |
|---|---|---|---|
| Agent credentials | Long-lived static secrets | Rotated, still standing | 10-minute tokens, none at rest |
| Tied to a human's live access | No | No | Lapses when they lose the group |
| Offboarding | Manual, easily missed | Manual revoke | Automatic SCIM cascade |
| Who approved this agent | Unknown | Unknown | Accountable operator on record |
| Runtime scope enforcement | None | None | Advisory flag or hard block |
| Public verifiability | None | None | Verification seals (EU AI Act) |
Who it's for
Built for the teams accountable for what agents do.
Pricing
One platform. Identity and risk in every plan.
Federation, delegation, and runtime risk controls ship in every tier. No SSO tax, none of the security features gated behind the top plan. Simple per-agent pricing, the way your IdP prices people.
Bring every agent under governance: the ones you run, and the ones your customers send.
See your own IdP groups delegated to a live workforce agent, and a consumer delegation minted, capped, and revoked, live: in about 30 minutes.