Capnis SSO

One sign-in for Capnis websites

Capnis.one is the shared identity layer for the Capnis ecosystem—create a customer account once, then sign in to every Capnis website that trusts this authorization server.

Capnis SSO

One identity for every Capnis website — OAuth 2.0, OpenID Connect, passkeys, and MFA.

How it works

From Capnis website to signed-in user

Any Capnis website that uses this SSO sends users here to authenticate once, then returns them signed in.

1

Capnis website redirects

Any Capnis website that uses this SSO sends the user to capnis.one with client_id, scopes, and a PKCE challenge.

2

User signs in

The user authenticates once (password or passkey), reviews consent, and approves the scopes that website requested.

3

Return with tokens

Capnis returns an authorization code; the Capnis website exchanges it for access and refresh tokens and the user continues signed in.

Trusted across the Capnis ecosystem
OAuth 2.0
OpenID Connect
One account
Trusted across the Capnis ecosystem

SSO for the whole Capnis ecosystem

Unify every Capnis website behind one trusted identity—customers and employees sign in here once, then access any connected Capnis property.

Authorize & consent

When a Capnis website needs a signed-in user, it redirects here for OAuth authorization, scope-based consent, and connected-app management with PKCE for public clients.

OAuth PKCE Consent

Customer & employee subjects

Separate subject types per Capnis website, role mappings per OAuth site, and tokens tailored to each connected property.

RBAC Subjects

Webhooks & role sync

Keep roles aligned across Capnis websites with signed webhooks and push sync when profiles or permissions change.

Webhooks Sync

Subject import

Import staff and customers from connected Capnis systems so capnis.one stays aligned with your organization source of truth.

Import Sync

Customer onboarding

Register once on capnis.one—business profile, billing details, and optional provisioning to connected Capnis systems when enabled.

Onboarding

Organization teams

Primary accounts add team logins for colleagues; each member uses the same Capnis SSO across every website your organization uses.

Teams Sub-accounts
Platform highlights

Built for every Capnis website

OIDC discovery

Standard OpenID Connect discovery and JWKS for token validation on connected Capnis websites.

One sign-in hub

Customers and employees authenticate once at capnis.one instead of separate logins per site.

Per-site RBAC

Role mappings and scopes tailored to each Capnis website that trusts this authorization server.

Customer portal

Connected Capnis websites

Signed-in users manage which Capnis websites have access to their account—view scopes, revoke consent, and review security activity from one portal.

Open portal
  • Per-site consent and revoke
  • MFA, passkeys, and active sessions
  • Security activity timeline
  • Organization team members (when provisioned)

Sign in to Capnis websites with one account

Create a customer account on capnis.one, then use the same sign-in across connected Capnis websites.