Skip to content

Sign-in options

Requires a license with the saml, scim or device-fingerprint feature for those options. Passwords, magic links, OAuth sign-in, MFA and captcha are free, and OAuth sign-in and MFA have paid parts named in the tables. See pricing.

Every way of signing in ends the same way: the person holds a LyEve session token, the same one a password sign-in gets, and your services verify it the same way (see validate tokens). What differs is who checks the person's identity, and what extra checks stand in front of it. Most instances combine several options: a way in, a second factor, and something that slows down attackers.

OptionBest forFree or licensePage
PasswordEvery instance. The first super admin always signs in this way.FreeQuickstart, and password reset for a forgotten one
Magic linkOccasional editors who would rather click an emailed link than keep a password.FreeMagic link sign-in
OAuth and OpenID ConnectTeams on Google Workspace, Okta, Azure AD, Keycloak or any OIDC provider.Free with one provider. More providers, the Okta and Azure AD templates and role mapping need oauth-proOAuth sign-in
SAMLCompanies whose identity provider speaks SAML 2.0, with a provider per tenant.Requires samlSAML single sign-on
OptionBest forFree or licensePage
SCIM provisioningCreating, updating and removing accounts from Azure AD, Okta or another directory before anyone signs in. Pair it with SAML.Requires scimSCIM provisioning
OptionBest forFree or licensePage
Multi-factor auth and passkeysA second step after the password, or a passkey with no password at all.Free. Enrolling a passkey needs mfa-proMulti-factor authentication
Trusted devicesAsking for the second factor only when a sign-in looks risky, and blocking brute force on every sign-in route.Requires device-fingerprintTrusted devices
CaptchaA challenge after a few failed password sign-ins.FreeCaptcha

Every install also allows 5 password sign-in attempts per address every 15 minutes, and refuses an account's password sign-in after 5 failures within 15 minutes. See rate limiting.

  • A small team with no identity provider: passwords, with MFA for admins and captcha on.
  • A team that already lives in Google Workspace, Okta or Azure AD: OAuth sign-in, and keep one password super admin for when the provider is down. The Okta and Azure AD templates need oauth-pro.
  • An enterprise customer with a SAML directory: SAML for sign-in and SCIM for accounts.
  • Editors who sign in once a month: magic links.

Programs do not sign in. A site or app uses an API key, and a script on the Admin API uses an admin token. See which credential do I need.