Free, foreverAI-native

Authentication, detached from authorization.

Sudomimus is an identity provider and authentication platform for trusted application sessions.

Sign in with Sudomimus
Open the application you want to use and select its “Sign in with Sudomimus” button.
Manage your account
Review your profile, control which applications can see your email and name, and manage every way you sign in — all from one place.
Build with Sudomimus
Build your application on Sudomimus without worry about authentication.

Explore application sign-in

Or, hand it to your AI

Read https://docs.sudomimus.com/en-us/ai/overview.md. Choose the matching
integration path and read only its flow and API contracts. Integrate Sudomimus
authentication into my application.

Stack: <your stack, e.g. Next.js 14 + Drizzle + Postgres>
Auth methods: <e.g. passkeys + email OTP>
Application anchor: app_xxxxxxxxxxxxxxxx
Callback URL: <your callback URL>

Connect your AI assistant with MCP

Give software its own identity
Create agents for context-driven software and automations for defined workflows. Give each one credentials that you can revoke separately. Each agent or automation can sign in with an access key or an Ed25519 public key. You keep the private key.
Adopt a domain
If you own a domain, you can adopt it in Sudomimus. Set a login policy for accounts that use email addresses on that domain.

Security you can trust

Modern authentication primitives, secure by default.

Rehearse application rules
Passwordless by default
Passkeys and WebAuthn let users sign in with no password to phish or steal.
Signed, verifiable tokens
Every token is RS256-signed with a dedicated RSA-2048 key per application.
Encrypted at rest
Private keys are encrypted at rest. Signed Connect /establish requests use replay protection.
Many ways to sign in
Passkeys, email OTP, Steam, and OAuth providers — gated per application.

Privacy by design

Your users stay in control of their identity.

Explore the Trust Journey
Applications never see your real ID
Each application receives a per-user pairwise identifier, never your underlying account.
You decide what is shared
Choose per application whether it can receive your email and name through UserInfo.
Delete your account
Erase your account and personal data. If you solely own an organization with live applications or sectors, retire those resources or add another active owner first.

Works with the stack you already know.

Start with a framework adapter, a typed SDK, or the protocol your application already supports.

  • Next.js
  • React Router
  • Nuxt
  • Django
  • TypeScript
  • Python

Start building Free, forever.

Add authentication to your application without the cost or the complexity.

Create an application