Xirag Gate
Developer corner
Codename: Golden Cage

Their identity provider.
Your login screen.

Xirag Gate is a Home Realm Discovery broker: type a work email, and we route the sign-in straight to your organization's own OIDC or SAML identity provider — Okta, Microsoft Entra ID, Google Workspace, or anything standards-based — without Xirag ever importing or storing that directory.

OIDC & SAML HRD · HMAC-SHA256 signed assertions · Zero inbound ports · JIT tenant provisioning
Xirag Gate · Home Realm Discovery
alex@acme.com AC
Resolving organization…
Assertion signature verifying…
New device detected Chrome · Mumbai, IN · pending approval
// identity_layer

Your IdP stays the source of truth

Gate is a broker, not a copy machine — nothing about your directory ever leaves your organization's own identity provider.

Home Realm Discovery

Type a work email and Gate resolves the right identity provider automatically — no dropdown of fifty companies, no guessing which button to click.

Zero directory retention

Xirag never imports, syncs, or caches your organization's user directory. Every sign-in is brokered live, not mirrored into a second copy.

HMAC-signed assertions

Every handoff back from your identity provider is HMAC-SHA256 signed and verified with a timing-safe comparison — a forged or tampered link is rejected outright.

Zero inbound ports

Your cloud never opens a port to Xirag. Every exchange is outbound-initiated, so Gate fits inside networks your security team already locked down.

JIT tenant & seat provisioning

The first person from a new company who signs in through Gate provisions their tenant and an admin seat on the spot — no separate onboarding form.

Single-trusted-device model

Every login registers a device fingerprint. A second, unrecognized device sits pending until an admin approves it — approval quietly retires the old one.

White-labeled broker

Your people never see Xirag branding mid-flow. Gate acts as an invisible hop between your login screen and your organization's own IdP.

Short-lived signed handoffs

Assertions carry a server-checked expiry timestamp — a captured redirect link is worthless the moment it lapses.

// sign-in_sequence

Four steps. No password to invent.

1

Enter your work email

Type your organization address at sign-in — no separate "Sign in with SSO" button to go hunting for.

2

Gate resolves your IdP

Home Realm Discovery matches your email's domain to your organization's registered identity provider.

3

Authenticate with your org

You're redirected to your own Okta, Entra ID, or Google Workspace tenant. Xirag never sees your password.

4

Signed, verified, in

Your IdP redirects back with a signed assertion; Gate verifies it, registers your device, and starts your session.

// broker_topology

One broker. Your infrastructure.

Gate sits between your login screen and your identity provider — verifying, registering, and provisioning, without ever becoming a second directory.

Gate
BrokerHRD core
Your identity providerOIDC · SAML
Assertion verifierHMAC-SHA256
Device trust ledgerFingerprint · approval
Tenant & seat provisioningJIT on first sign-in
// provider_matrix

Works with the identity provider you already run

Any standards-based OIDC or SAML provider works — these are the ones we're tuned for on day one.

OktaOIDC & SAML Microsoft Entra IDOIDC Google WorkspaceOIDC OneLoginSAML Ping IdentitySAML Any OIDC / SAML IdPStandards-based
// developer_corner

Built it. Documented it. Made it easy to try.

A full OpenAPI 3.1 reference, interactive Swagger explorer, and integration guides for Web, Windows, Linux, and Android — every code sample copy-pasteable.

REST API + Swagger

Five documented operations, browsable and testable right in your browser.

OAuth 2.1 + PKCE + DPoP

Sender-constrained tokens by default — no bearer token to steal and replay.

Web · Windows · Linux · Android

A real SDK guide per platform, with the exact code that was compiled and run.

Open the Developer Corner →

Enterprise SSO, without the enterprise SSO tax.