Standards-based token services
The documented identity core supports OAuth 2.1 and OpenID Connect authentication and token workflows.
A shared identity foundation.
Arga's product-agnostic core identity service provides shared authentication and token issuance, with documented passkeys, OAuth/OpenID Connect, federation, provisioning, and audit controls.
Why it exists
A growing product portfolio needs a coherent identity foundation. ARGA | CIS is designed as a standalone service that Arga products can join through client configuration rather than changes to the identity core. It is an internal, self-hosted platform: the portfolio entry explains infrastructure we build, not a promise of public sign-up.
What it covers
The documented identity core supports OAuth 2.1 and OpenID Connect authentication and token workflows.
WebAuthn passkeys support biometric and hardware-key authentication experiences.
SAML 2.0 and SCIM 2.0 are described integration surfaces for identity federation and user provisioning.
Product teams register clients through configuration, keeping product-specific changes out of the shared identity service.
Documented controls include hardened password hashing, encryption at rest, a tamper-evident audit chain, and token-security mechanisms such as DPoP.
Who it's for
Teams integrating applications with a shared identity core.
Operators managing authentication, federation, and provisioning.
Engineers maintaining a self-hosted foundation across multiple products.
Current project stage
ARGA | CIS is in Beta and progressing toward a release candidate. It is Arga's shared internal identity platform. Talk to us about product integration, federation, provisioning, and deployment requirements.
Ask about availability →