Skip to content

Casa

Self-service MFA with Casa

A self-service credential management portal is key to a successful MFA rollout. Casa lets end users register FIDO, TOTP, Super Gluu, SMS, X.509 certificate and external IDP credentials — with plugins for third-party providers.

Multi-factor authentication under one roof

People accumulate credentials. Casa gives end users a single place to view, enroll and remove them, including FIDO passkeys, software tokens, biometric credentials and federated accounts such as Google, Microsoft Entra and Apple.

Casa is brandable and extensible. Plugins can add third-party authentication services, or light identity management features such as registration approval and delegated administration.

Why it matters

  • No more password resets

    Users enroll, manage and remove passwordless credentials on all their devices without calling the help desk. An MFA rollout is only as strong as its weakest account recovery workflow.

  • Eliminate phishing with FIDO

    To defeat phishing you have to stop the man-in-the-middle. Passwords, OTP tokens and push notifications are all vulnerable; FIDO passkeys are not. Casa is where users enroll USB, platform and Bluetooth FIDO credentials.

  • Enforce strong authentication

    Casa exposes an OpenID Connect API and returns a standard JWT id_token that downstream policy enforcement can consume.

  • Deploy cloud-native

    Cloud-native deployment with standard tooling such as Helm, on Kubernetes, Amazon EKS, Google GKE or SUSE Rancher. Backends include LDAP, Couchbase, RDBMS, Amazon Aurora and Google Spanner.

Roll out MFA people can actually manage

Casa ships with Gluu Flex and Gluu 4.