Casa
Self-service MFA with Casa
A self-service credential management portal is key to a successful MFA rollout. Casa lets end users register FIDO, TOTP, Super Gluu, SMS, X.509 certificate and external IDP credentials — with plugins for third-party providers.
Multi-factor authentication under one roof
People accumulate credentials. Casa gives end users a single place to view, enroll and remove them, including FIDO passkeys, software tokens, biometric credentials and federated accounts such as Google, Microsoft Entra and Apple.
Casa is brandable and extensible. Plugins can add third-party authentication services, or light identity management features such as registration approval and delegated administration.
Why it matters
No more password resets
Users enroll, manage and remove passwordless credentials on all their devices without calling the help desk. An MFA rollout is only as strong as its weakest account recovery workflow.
Eliminate phishing with FIDO
To defeat phishing you have to stop the man-in-the-middle. Passwords, OTP tokens and push notifications are all vulnerable; FIDO passkeys are not. Casa is where users enroll USB, platform and Bluetooth FIDO credentials.
Enforce strong authentication
Casa exposes an OpenID Connect API and returns a standard JWT id_token that downstream policy enforcement can consume.
Deploy cloud-native
Cloud-native deployment with standard tooling such as Helm, on Kubernetes, Amazon EKS, Google GKE or SUSE Rancher. Backends include LDAP, Couchbase, RDBMS, Amazon Aurora and Google Spanner.
