Features

SSO across Capnis websites

Everything capnis.one provides so customers and Capnis websites share one login, consent model, and security policy.

Multi-subject OAuth

Authorize customers and employees on any connected Capnis website with distinct guards, scopes, and policies per OAuth site.

Consent & connected apps

Users approve scopes once; the portal lists every Capnis website they have connected, with per-site revoke.

OAuth site administration

Operators register each Capnis website as a client—redirect URIs, subject types, PKCE, and IP allowlists.

Signed webhooks

HMAC-signed delivery log with retry when tokens are issued or roles change on a Capnis website.

Role sync API

Push user and role updates to connected Capnis websites; map Capnis roles to each site's remote catalog.

Subject import

Import staff and customers from connected Capnis systems with remote ID linking on capnis.one.

Introspection & JWKS

Token introspection, OpenID discovery, and JWKS so Capnis websites validate sessions securely.

Customer portal

One place to manage profile, 2FA, passkeys, sessions, security activity, and connected Capnis websites.

Organization team accounts

Primary customers invite teammates; each gets their own login for the same SSO across Capnis websites.

Connect your Capnis website

Review OIDC endpoints and integration steps to register a Capnis property as an OAuth client.