Skip to content

Flex

Enterprise IAM infrastructure

Some businesses must self-host authentication and authorization rather than hand them to a cloud service. Gluu Flex is a software distribution for building multi-datacenter, highly available identity and access management infrastructure.

Gluu Flex Components

Flex is Gluu's flagship product: a commercial Identity Provider with an open source core. It includes all the components found in the Linux Foundation Janssen Project, plus the Flex Admin UI, a web control plane with enterprise features like reporting and audit.

An optional deployment profile is conformant with DISA STIG requirements for Red Hat Linux.

Gluu Flex at the centre, connected to the Auth Server, Config API, Admin UI, Casa, SCIM, FIDO, Agama, Lock and the Cedarling

Common use cases

  • OpenID Federation
  • SAML federation
  • Single sign-on (SSO)
  • Mobile authentication
  • Web identity orchestration
  • API client management and dynamic registration
  • Multi-factor authentication and passwordless
  • Active Directory or Keycloak synchronization
  • Self-service credential management
  • Open Banking
  • OAuth federation with published software statement key material
  • Internal identity connection via SCIM
  • Stepped-up authentication
  • Smart card and FIDO authentication
  • OTP and email authentication, including message signing
  • Device flow authentication

Flex is good for business

  • No lock-in

    If a Gluu subscription expires the commercial Admin UI locks, but the authentication service keeps running: the core components are open source, and you can configure them with open source tools or move to the Janssen Project distribution.

  • Cost effective

    A Gluu subscription is priced on peak monthly active users, so you do not pay for users who never log in.

  • Use the database you have

    Use existing database infrastructure instead of deploying a single-purpose LDAP topology, which improves both total cost of ownership and uptime.

  • Multi-factor authentication

    End users self-service their MFA credentials in Casa, with out-of-the-box support for SMS, one-time passwords, FIDO authentication and passkeys.

  • Social login

    Built-in support for Google, Facebook, Apple, Microsoft Entra ID, or any consumer identity provider that supports OpenID Connect, through Agama-based identity orchestration.

  • JWT access tokens

    Flex mints many kinds of JWTs and provides a real-time solution to expire them, so access tokens can carry policy information without becoming a liability.

Ready to look at Flex in detail?