🔑 IAM

Identity Management

Identity and access management: applications, users, roles and MFA. Access tokens are opaque high-entropy bearer tokens (384 bits from the OS CSPRNG, stored as SHA-256 hashes) — not JWTs, and not post-quantum.

There is no hosted login page and no OAuth authorization-code (browser sign-in) flow — only client_credentials. Qntyx does not send MFA codes by email or SMS: your backend delivers them. Authenticator-app (TOTP) setup is not available yet. Login tokens carry only the permissions the user's roles grant.

Quick Example

curl -X GET https://iam-api.qntyx.io/applications/ \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json"

API Base URL

https://iam-api.qntyx.io

Endpoints

MethodPathDescription
GET/applications/List applications
POST/users/registerCreate a user
GET/roles/{app_id}List an application's roles
POST/auth/loginSign a user in (add otp_code when the app requires MFA)
POST/mfa/generateCreate a one-time MFA code — returned to your backend, which delivers it to the user
POST/oauth/tokenOAuth client_credentials grant (service-to-service)
GET/stats/Dashboard statistics

Authentication

All endpoints require a bearer token. See Authentication for details.

Dashboard

Manage this product visually at app-iam.qntyx.io

Marketing Page

Learn more at iam.qntyx.io