Roles belong to memberships
The same person can participate in several organizations without receiving one global role across all of them.
Product
Customer IdentityPublic beta · Hosted customer authenticationMCP AuthorizationDeveloper preview · Scoped AI-client accessAgent AccessDesign partner · External provider accessWorkforce IdentityDesign partner · Employee lifecycle and SSODevelopers
OverviewHosted Auth, OAuth/OIDC, and MCPDocumentationGuides & integrationAPI referenceEndpoints & schemasTrust
DPDP readinessChecklist & readiness reviewSecurityHow we protect your dataPrivacyHow we handle your dataModel downstream companies inside a Customer Identity instance. Keep memberships, invitations, verified domains, enterprise connections, and organization-bound sessions attached to the customer they belong to.
The same person can participate in several organizations without receiving one global role across all of them.
The selected organization becomes explicit OAuth context so your backend can enforce the same boundary on every request.
Verify a domain, test the SAML metadata, choose a provisioning policy, and audit configuration changes before enforcement.
Customer Organizations and inbound SAML are a request-access preview. OIDC enterprise connections, SCIM directory sync, custom roles, customer-managed SSO setup, and organization billing are not generally available. Your application must still enforce organization scope on its own business data and APIs.
Preview · request access