The identity platform you can host yourself. Still in development.
Central login, enterprise SSO, directory sync, RBAC, billing-driven entitlements and a tamper-evident audit trail. The code is public and moving fast, but it is pre-1.0 with open security follow-ups, and the hosted version is not open yet.
Illustrative interface
Run it on your own infrastructure
The deployable app, built on the MIT-licensed laravel-id framework. Pre-1.0 and dogfooded, not something to put in front of real users yet. The app is Elastic License 2.0: use, modify and redistribute it, but not as a hosted service for third parties.
Or let us host it
Not available yet. Hosted Cbox ID with SSO, SCIM and audit is planned; leave your details to hear when it opens.
Own your identity layer
Self-host the whole platform. Your users, secrets and audit trail never leave your own infrastructure.
Bind, don't fork
Every capability is a contract you implement, mock or swap. No forking, no framework lock-in.
Compliance-ready
OAuth, OIDC, SCIM and SAML with control mappings to SOC 2, ISO 27001, GDPR, HIPAA and PCI-DSS.
Everything an identity layer is expected to do
Authentication & SSO
Central login with passwords, magic links, TOTP, passkeys and social, plus enterprise single sign-on over SAML and OIDC, and an OAuth/OIDC provider of your own so other apps log in against you.
Directory sync (SCIM)
SCIM 2.0 push plus Google Workspace and Microsoft Entra pull, so an upstream directory creates, updates and deactivates users and groups automatically. Deprovisioning revokes sessions immediately.
RBAC, deny-by-default
Role-based access control with an authorization kernel where every check is explicit rather than assumed.
Billing-fed entitlements
What a user or organization can do follows their plan, without hand-wired feature flags.
Tamper-evident audit
A cryptographically-backed audit trail you can query and prove, for the who-did-what a compliance review will ask for.
Standards & compliance
OAuth, OIDC, SCIM, SAML, FAPI and MCP, with control mappings to SOC 2, ISO 27001, NIS2, GDPR, HIPAA and PCI-DSS.
Consuming Cbox ID tokens from your own services? The cbox-id-jwks-auth and cbox-id-tokens libraries (PHP and Go) validate JWKS-only tokens and handle service-to-service OAuth, so resource servers verify tokens without calling home.
Built on open source
These are the packages underneath, maintained in the open and run in production. No black box.
Core packages
Add-ons
Get Cbox ID managed
No spam. Just a heads-up when it is ready for you.
Request Early Access
A few details so I can prioritize the right people.
No spam. I'll email you personally when it's ready.