Nauthilus in 76 seconds
Who decides?
Today every service decides alone: different lockouts, different MFA rules, different blind spots. Here is what changes when one engine makes the call.
How it works
Facts in. Decision out.
Declarative policies evaluate the facts at each checkpoint of a request and answer with a clear verdict and the obligations that go with it. Try new rules in observe mode first, then enforce them once you trust them.
- user@corp.example
- IP · geo · ASN
- brute-force history
- blocklists (RBL)
- LDAP attributes
- MFA state
Policy engine- DecisionALLOW+ step-up MFA · audit
- DecisionDENY+ rate-limit source · audit
- DecisionTEMPFAIL+ retry later · backend degraded
Same rules. Every service. Every time.
Integrations
One engine. Every entry point.
Mail authentication
Dovecot, Postfix and Nginx mail proxies ask Nauthilus before a session starts, so every mail login follows the same rules.
OIDC · SAML 2.0 · WebAuthnNative identity provider
Browser sign-in, consent and MFA for your web applications, with the policy engine deciding on every step.
REST · gRPC · Policy APIHTTP services & APIs
Reverse proxies and web apps authenticate over HTTP or gRPC, and any other service can ask the generic Policy API for a decision.
gRPC identity proxyDistributed edges
Edge instances forward identity and policy questions to a central authority, so remote sites decide like headquarters.
Why Nauthilus
Observable. Safe to change live. Open source.
Running it in production?
Enterprise support. Directly from the maintainer.
- Architecture
- Integration
- Customization
- Troubleshooting
Nauthilus is open source under the GPLv3, written in Go. You can also sponsor its development.
