Customer Identity · public betaBuild your first Test integration.Create a Test project
NamoID
Organizations and SSOPreview · request access

Give every customer company its own identity boundary.

Model downstream companies inside a Customer Identity instance. Keep memberships, invitations, verified domains, enterprise connections, and organization-bound sessions attached to the customer they belong to.

Roles belong to memberships

The same person can participate in several organizations without receiving one global role across all of them.

One organization per session

The selected organization becomes explicit OAuth context so your backend can enforce the same boundary on every request.

Connect SAML per customer

Verify a domain, test the SAML metadata, choose a provisioning policy, and audit configuration changes before enforcement.

Product scope

A downstream customer boundary—not your NamoID workspace.

Customer Organizations and inbound SAML are a request-access preview. OIDC enterprise connections, SCIM directory sync, custom roles, customer-managed SSO setup, and organization billing are not generally available. Your application must still enforce organization scope on its own business data and APIs.

  • Instance-owned organization records
  • Admin and member roles on each membership
  • Expiring invitations with revoke controls
  • Verified-domain ownership challenges
  • SAML connection metadata and test flow
  • Invitation-only or verified-domain JIT provisioning
  • Organization-bound sessions and refresh tokens
  • Organization-scoped configuration audit history

Preview · request access

Validate one customer organization in Test.