Core Capabilities

On this page

The Curity Identity Server is a comprehensive identity and access management platform. Built on principles of separation of concerns, extensibility, and reliability, the Curity Identity Server provides organizations with a flexible and powerful toolbox for securing their applications, APIs, and user interactions at scale.

This article provides an overview of its major capabilities and features.

What is the Curity Identity Server?

The Curity Identity Server is a standards-based product that authenticates users, applications and services, manages identity data, and enables APIs to protect enterprise data. It is built on open standards, so applications and APIs integrate once. This allows for security policies to change without requiring code changes. The software runs in a customer-controlled environment, on-premise and in the cloud.

What Does the Curity Identity Server do?

The Curity Identity Server provides a central authentication and token service. It issues and validates OAuth 2.0 access tokens and OpenID Connect ID tokens, enables authorization at the API and AI gateways, connects to various types of identity stores and identity providers, and supports federation and token exchange across identity domains.

Authentication

The Authentication Service in the Curity Identity Server provides flexible authentication mechanisms that protect applications without requiring code changes for different methods.

CapabilityDescription
Multiple Authentication MethodsThe Curity Identity Server enables authentication of users like customers, partners and other requesting parties by a range of configurable authentication methods, including passwordless, multi-factor and step-up authentication.
Sessions and Single Sign-onEstablishment, maintenance and termination of authenticated sessions across multiple applications. Applications that share the same authentication requirements can reuse the session using single sign-on.
Federation and InteroperabilityThe Curity Identity Server can act as an intermediary between external identity providers, applications, service providers and relying parties, thereby enabling identity federation for users and machines across organizational and technical boundaries.
No-code Designer for Authentication FlowsThe Curity Identity Server includes a graphical interface that lets you customize the prerequisites, steps and actions for each authentication method using visual elements. This enables organization to set up an authentication journey that fits their needs and policies without writing code.

Authorization and Access Control

The Token Service is the OAuth 2.0 Authorization Server and OpenID Connect Provider. It generates and manages security tokens that control access to APIs and applications in a standards-based manner, catering to basic as well as high-security requirements.

CapabilityDescription
Delegated Authorization and Token IssuanceThe Curity Identity Server handles the issuance, validation, renewal, introspection and revocation of security tokens in accordance with configured policy. It can adapt the content, scope and duration of such tokens.
Application, API and Non-human Access ControlThe Curity Identity Server enables the enforcement of access decisions in respect of applications, APIs and automated software clients, including software acting on its own behalf and software acting on behalf of an identified user.
Fine-grained Access ControlThe Curity Identity Server can take into consideration identity, delegation, contextual and risk-related information when crafting security tokens and granting access. It provides organizations with fine-grained control over their access policies allowing them to model their access control policies in many different ways.

User Management and Identity Data

The User Management Service of the Curity Identity Server centers around API-driven access to user data. Curity ships out-of-the-box interfaces on top of these APIs to cover common requirements while keeping the choice for organizations to completely create their own interfaces and flows.

CapabilityDescription
Identity and Account ManagementThe Curity Identity Server offers graphical and programmatic interfaces for authorized systems and personnel to administer accounts and related data.
Open Data ModelThe Curity Identity Server supports an open data model for identity data with custom user attributes and integrates with many different types of datastores. Enterprises can take full control over data residency, across regions and tenants if required.
User Self-serviceThe Curity Identity Server provides a self-service portal where users can manage their account data including authentication-related data such as email addresses, phone numbers, passwords and passkeys as well as multi-factor settings.
Consent ManagementThe Curity Identity Server provides user control over data sharing and privacy, giving granular permissions for what data to share with third parties.

Extensibility

The Curity Identity Server is built on extensibility principles, allowing customization without modifying core functionality.

CapabilityDescription
Customized AuthenticationExtension points targeting authentication let you customize steps in an authentication flow or even define complete, proprietary authentication methods.
Customized AuthorizationExtension points targeting authorization let you customize the retrieval of data, construction and issuance of access tokens. They also allow for integrating with external services for authorization decisions.
Branded User InterfacesUser interfaces can be adapted and branded, even per application if required, supporting multiple brands under the same umbrella.
SDKCurity ships a documented software development kit and extension interfaces permitting the configuration of supplied components and the development of additional integrations and customizations.
Management APIsThe Curity Identity Server exposes APIs for administrative tasks which allow you to to integrate with third-party, existing, new or custom portals like a common developer portal or custom self-service portal.

Administration, Deployment and Operations

CapabilityDescription
Configuration ManagementThe Curity Identity Server supports multiple interfaces to configure the product including a graphical interface, the Admin UI, a command line interface and APIs. It also supports loading the configuration from file upon startup for modern deployment flows.
Flexible DeploymentThe Curity Identity Server is a cloud-native product, which means it runs on any modern cloud environment, including private clouds and on-premise installations. Deployments can span multiple regions and tenants when required, and ensure locality with APIs.
High AvailabilityThe Curity Identity Server can be deployed with multiple nodes. Metrics allow for monitoring the state of each node. Together with zero-downtime updates, this ensures high availability of the services.
Monitoring and LoggingThe Curity Identity Server publishes metrics, events and logs that allow monitoring the system and integrate with Security Identity and Event Management (SIEM) systems to discover anomalies in real time. Alerts immediately notify when something appears broken and impacts the operation of the product.

Summary

The Curity Identity Server provides a standards-based platform for identity and access management. Its core capabilities span authentication and session management, user management, authorization, and API security, all built on principles of extensibility and reliability.

For more detailed information on specific capabilities, explore the related articles on Authentication, Tokens, and High Availability.

Architecture

See how Curity fits into modern identity and API architectures.

Explore architecture

Customer Stories

Learn how organizations run identity and API security at scale.

Read customer stories