Sign-in options
Requires a license with the
saml,scimordevice-fingerprintfeature for those options. Passwords, magic links, OAuth sign-in, MFA and captcha are free, and OAuth sign-in and MFA have paid parts named in the tables. See pricing.
Every way of signing in ends the same way: the person holds a LyEve session token, the same one a password sign-in gets, and your services verify it the same way (see validate tokens). What differs is who checks the person's identity, and what extra checks stand in front of it. Most instances combine several options: a way in, a second factor, and something that slows down attackers.
Ways in
Section titled “Ways in”| Option | Best for | Free or license | Page |
|---|---|---|---|
| Password | Every instance. The first super admin always signs in this way. | Free | Quickstart, and password reset for a forgotten one |
| Magic link | Occasional editors who would rather click an emailed link than keep a password. | Free | Magic link sign-in |
| OAuth and OpenID Connect | Teams on Google Workspace, Okta, Azure AD, Keycloak or any OIDC provider. | Free with one provider. More providers, the Okta and Azure AD templates and role mapping need oauth-pro | OAuth sign-in |
| SAML | Companies whose identity provider speaks SAML 2.0, with a provider per tenant. | Requires saml | SAML single sign-on |
Accounts from your directory
Section titled “Accounts from your directory”| Option | Best for | Free or license | Page |
|---|---|---|---|
| SCIM provisioning | Creating, updating and removing accounts from Azure AD, Okta or another directory before anyone signs in. Pair it with SAML. | Requires scim | SCIM provisioning |
Extra checks at sign-in
Section titled “Extra checks at sign-in”| Option | Best for | Free or license | Page |
|---|---|---|---|
| Multi-factor auth and passkeys | A second step after the password, or a passkey with no password at all. | Free. Enrolling a passkey needs mfa-pro | Multi-factor authentication |
| Trusted devices | Asking for the second factor only when a sign-in looks risky, and blocking brute force on every sign-in route. | Requires device-fingerprint | Trusted devices |
| Captcha | A challenge after a few failed password sign-ins. | Free | Captcha |
Every install also allows 5 password sign-in attempts per address every 15 minutes, and refuses an account's password sign-in after 5 failures within 15 minutes. See rate limiting.
Choose
Section titled “Choose”- A small team with no identity provider: passwords, with MFA for admins and captcha on.
- A team that already lives in Google Workspace, Okta or Azure AD:
OAuth sign-in, and keep one password super
admin for when the provider is down. The Okta and Azure AD templates need
oauth-pro. - An enterprise customer with a SAML directory: SAML for sign-in and SCIM for accounts.
- Editors who sign in once a month: magic links.
Programs do not sign in. A site or app uses an API key, and a script on the Admin API uses an admin token. See which credential do I need.