Identity Management
Identity and access management: applications, users, roles and MFA. Access tokens are opaque high-entropy bearer tokens (384 bits from the OS CSPRNG, stored as SHA-256 hashes) — not JWTs, and not post-quantum.
There is no hosted login page and no OAuth authorization-code (browser sign-in) flow — only client_credentials. Qntyx does not send MFA codes by email or SMS: your backend delivers them. Authenticator-app (TOTP) setup is not available yet. Login tokens carry only the permissions the user's roles grant.
curl -X GET https://iam-api.qntyx.io/applications/ \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json"
https://iam-api.qntyx.io
| Method | Path | Description |
|---|---|---|
GET | /applications/ | List applications |
POST | /users/register | Create a user |
GET | /roles/{app_id} | List an application's roles |
POST | /auth/login | Sign a user in (add otp_code when the app requires MFA) |
POST | /mfa/generate | Create a one-time MFA code — returned to your backend, which delivers it to the user |
POST | /oauth/token | OAuth client_credentials grant (service-to-service) |
GET | /stats/ | Dashboard statistics |
All endpoints require a bearer token. See Authentication for details.
Manage this product visually at app-iam.qntyx.io
Learn more at iam.qntyx.io