Authentication your users won't notice

A small hosted identity API for web and mobile apps. Drop-in sign-in links, OAuth 2.0 / OIDC, and audit logs — without running your own user database.

Read the docs

Passwordless by default

Email and WebAuthn passkeys out of the box. No password resets, no credential stuffing.

OAuth 2.0 & OIDC

Standards-compliant authorization server with PKCE, refresh tokens and scoped access.

Audit trail

Every sign-in, token grant and settings change is recorded and exportable via API.

Quick start

Exchange a sign-in link for a session token in one request.

POST /v1/token HTTP/1.1
Host: api.sirauth.com
Content-Type: application/json

{ "grant_type": "urn:sirauth:email-link", "link_id": "sl_9f2a..." }

# → 200 OK
{
  "access_token": "sat_2Kq8...",
  "token_type": "Bearer",
  "expires_in": 3600,
  "scope": "openid profile"
}

Pricing

Billed monthly, cancel anytime.

PlanMonthly active usersPrice
Hobbyup to 5,000Free
Proup to 50,000$29 / month
Businessunlimited, SSO + SLAContact us

System status

All systems operational

ComponentStatus
Authentication APIOperational
Email deliveryOperational
DashboardOperational
Uptime (90 days)99.98%
API continuously up for—