ArkID enterprise-level IDaaS/IAM platform system is an open source unified identity authentication and authorization management solution that supports multiple standard protocols (LDAP, OAuth2, SAML, OpenID), fine-grained permission control, complete WEB management functions, DingTalk, Enterprise WeChat integration, etc.
Extensible underlying application architecture based on Plug-in
New functions can be added to the main program flexibly and quickly without changing the main program.
unified directory
Achieve centralized and secure storage of enterprise organizational structure and massive personnel identity information
Establish multi-dimensional correspondence and securely integrate enterprise identity data sources
Achieve efficient and unified management of enterprise personnel, organizational structure, and application information on one platform
Single sign-on
Access all work systems with one username and password
Support single sign-on protocols such as OIDC, OAuth2, CAS, SAML2, etc.
Support various own protocols or non-standard protocols through plug-in targeting
Support the method of filling in account and password through browser plug-in
Account life cycle
Realize the automated flow of identity information in different application systems such as personnel transfers/organizational structure changes
Effectively improve account configuration efficiency and shorten management time by 90%
Increase audit efficiency
Multi-factor authentication
Supports various authentication factors such as mobile phone, email, face, fingerprint, scan code, etc.
Supports various secondary authentications such as graphic verification codes and dynamic verification codes.
Support third-party authentication such as WeChat, DingTalk, and Enterprise WeChat
Intelligently evoke different combinations of authentication rules based on customers' different business scenarios and security needs.
Centralized authorization
Support RBAC, ABAC permission management
Support unified entry, storage and distribution of permission data
Unified permission verification and support third-party permission system integration
Centralized approval
Support custom approval actions
Supports docking with third-party approval systems
Data synchronization
Supports SCIM protocol to synchronize user and organizational structure data across systems
Supports synchronization of various data including users, organizational structure, authentication, permissions, etc.
Supports synchronization of multiple third-party systems in various combinations, such as synchronizing HR system data to AD or LDAP services
security audit
Record all request behaviors of users and administrators in real time
Supports reading logs into third-party data analysis or security analysis systems
Supports displaying charts of third-party data analysis systems directly in the system
Support the security analysis system to intervene in certification rules and certification results to achieve intelligent control of security
client
Comes with WEB page
Supports various small programs and mobile clients
Plug-ins display pages without writing front-end code
cloud native
Support Docker development
Support Docker, K8S container deployment
Low code development framework
Extend OpenAPI so that front-end pages are driven by back-end configuration
Quickly build page prototypes
Support custom CSS themes
Plug-ins and App Stores
Support developers to share and sell plug-ins
Support pseudo-localization of SaaS applications
Support agents and sharing