Skip to main content

Federation

Availability

Cloud & Enterprise · Enterprise plan

Federation lets your agents authenticate with tokens from an identity provider you already run — Microsoft Entra ID, Okta, or Auth0 — instead of holding long-lived Splyntra secrets. You register the issuer as trusted, and agents present a federated token to obtain a short-lived, scoped Splyntra credential just in time.

Trusting an OIDC issuer

Register an issuer so Splyntra will accept tokens signed by it. Each issuer configuration carries:

FieldMeaning
issuer_urlThe OIDC issuer identifier, matched against the token's iss.
jwks_uriWhere Splyntra fetches the issuer's public keys to verify token signatures.
audienceRequired. The audience the token must be minted for.
Claim mappingsHow claims in the incoming token map to Splyntra agent identity.

Issuer endpoints:

  • GET /v1/identity/idp — list trusted issuers.
  • POST /v1/identity/idp — trust an issuer.
  • DELETE /v1/identity/idp/{idpID} — remove a trusted issuer.

JIT token exchange

An agent authenticates with a federated token and exchanges it for a Splyntra credential using an RFC 8693-style token exchange:

POST /v1/identity/token

On exchange, Splyntra validates the presented token before issuing anything:

  1. JWKS signature — verified against the issuer's keys from jwks_uri.
  2. Issuer — the token's issuer must match a trusted issuer_url.
  3. Audience — the token's audience must match the configured audience.

If validation passes, the exchange returns a 15-minute scoped Splyntra credential. The short lifetime means a leaked token grants only a narrow window of access, and the scope limits what it can do.

tip

Federation removes standing secrets from your agents entirely: they carry only tokens from your IdP and mint Splyntra credentials on demand.

  • Agent identity — the registry and scoped credentials that a federated exchange produces.
  • Trust policies — govern what federated agents may do in relation to each other.
  • REST API — the full /v1 identity surface.