SSO across Capnis websites
Everything capnis.one provides so customers and Capnis websites share one login, consent model, and security policy.
Multi-subject OAuth
Authorize customers and employees on any connected Capnis website with distinct guards, scopes, and policies per OAuth site.
Consent & connected apps
Users approve scopes once; the portal lists every Capnis website they have connected, with per-site revoke.
OAuth site administration
Operators register each Capnis website as a client—redirect URIs, subject types, PKCE, and IP allowlists.
Signed webhooks
HMAC-signed delivery log with retry when tokens are issued or roles change on a Capnis website.
Role sync API
Push user and role updates to connected Capnis websites; map Capnis roles to each site's remote catalog.
Subject import
Import staff and customers from connected Capnis systems with remote ID linking on capnis.one.
Introspection & JWKS
Token introspection, OpenID discovery, and JWKS so Capnis websites validate sessions securely.
Customer portal
One place to manage profile, 2FA, passkeys, sessions, security activity, and connected Capnis websites.
Organization team accounts
Primary customers invite teammates; each gets their own login for the same SSO across Capnis websites.
Connect your Capnis website
Review OIDC endpoints and integration steps to register a Capnis property as an OAuth client.