Protocols and integration

Meet applications where they are. Move them with control.

Atlas supports modern identity protocols, lifecycle interfaces, directory integration, workload identity, and bounded legacy profiles. Compatibility is stated at profile level so each flow has a clear interoperability contract.

Compatibility matrix

Supported surfaces and operational bounds.

Implemented means the profile is present in Atlas. Bounded profile requires exact flow qualification. Deployment-dependent requires external infrastructure or custody.

AreaProfiles and capabilitiesPostureNotes
OpenID ConnectDiscovery, authorization code, PKCE S256, client registration and policy, claims, UserInfo, logout patternsImplementedClient type, redirect, issuer, audience, claim, and signing policy remain explicit.
OAuth 2.xAuthorization code, client credentials, device authorization, refresh, introspection, revocation, token exchange, PAR, DPoPProfile-boundedGrant eligibility and proof-of-possession are configured per client and authorization server.
CIBA and CIMDBounded poll/ping backchannel flows and configured client metadata discovery patternsProfile-boundedRequires explicit client, issuer, authentication, delivery, and operational qualification.
SAML 2.0IdP and SP roles, metadata, signing, encryption, attribute contracts, SSO and logout routingImplementedAlgorithm, binding, NameID, encryption, and certificate profiles are partner-specific.
SAML 1.0 / 1.1Bounded direct inbound and browser/interoperability profilesProfile-boundedUse for controlled migration where the exact legacy profile has been qualified.
WS-Federation / WS-TrustBounded sign-in, metadata, token issue, renew, cancel, and proof-key profilesProfile-boundedQualification records the exact WS-* endpoint, dialect, version, and configuration.
SCIMSCIM 2.0 lifecycle and outbound integration; AIO supports configured inbound SCIM 1.1/2.0 pathsImplementedSchema extensions, filtering, pagination, patch behavior, and authority direction require mapping.
LDAP and AD patternsLDAP, LDAPS, StartTLS, directory source mapping, groups, lifecycle, and adapter patternsDeployment-dependentSchema, referrals, paging, password flows, network and certificate trust must be qualified.
AuthenticationWebAuthn/FIDO2, TOTP, password, push, recovery, certificate and smart-card patternsDeployment-dependentCAC/PIV and hardware-backed assurance require approved readers, middleware, PKI, validation and policy.
Application APIsREST, GraphQL, WebSocket, webhooks, operational evidence exportsImplementedAdministrative APIs require authenticated, authorized tenant context and version discipline.
Workload identitymTLS, TLS 1.3 patterns, SPIFFE/SVID-aligned extension and service identity interfacesDeployment-dependentProduction trust domain, CA custody, rotation, attestation, and mesh integration are external authorities.

Application integration

Choose the smallest dependable integration.

Atlas can front an application, act as its identity provider, provision accounts, translate a bounded legacy profile, or place an agent near the resource. The right pattern minimizes protocol translation and keeps enforcement close to the protected action.

01

Modern web and mobile

OIDC authorization code with PKCE, explicit audiences, short token lifetimes, refresh policy, and application-local authorization where appropriate.

02

Enterprise SaaS

SAML or OIDC for access, SCIM for lifecycle, entitlement mapping, group push, and application-account reconciliation.

03

APIs and services

Client credentials, token exchange, DPoP or mTLS, resource indicators, workload identity, and scoped service policy.

04

Legacy applications

Protocol adapters and bounded federation profiles with exact negative testing, certificate validation, and rollback route.

05

Privileged resources

Approval, vault-backed secret access, session constraints, managed accounts, executable policy, and enhanced evidence.

06

Disconnected resources

Pre-positioned signed policy, bounded offline evidence, locally enforceable decisions, and attributable reconciliation.

Identity and evidence sources

Normalize carefully. Preserve the source.

Source connectors map external objects into Atlas while retaining source identifiers, schema, timestamps, authority, and reconciliation status. One source may own employment status while another owns device posture; normalization preserves those distinct authorities.

Common source patterns

  • LDAP and Microsoft Active Directory
  • SCIM service providers and clients
  • HR and authoritative identity APIs
  • CSV or controlled batch intake
  • PKI, authenticator, and device systems
  • EDR, SIEM, threat, and network telemetry
  • Application and entitlement inventories
  • Federated identity and trust issuers

Vendor migration and coexistence

Prove continuity before changing the route.

Atlas migration workspaces inventory objects, map controls, identify conflicts, reconcile identities, and compare application outcomes. A route moves only for an approved application and cohort.

  • PingFederateValidated demonstration workflows cover inventory, control mapping, application waves, parallel routing, evidence, and rollback against an official PingFederate environment.
  • Okta and Auth0 patternsOIDC/OAuth, SAML, SCIM, applications, groups, roles, and key material can be mapped through source-specific discovery and reconciliation.
  • Oracle and other enterprise IdPsStandards-based applications and identity sources use the same protocol qualification and staged-route model.
Atlas migration application inventory with routes and readiness
Application migration inventoryRoute posture · control mapping · readiness

Interoperability qualification

Test the complete profile.

Before production routing, qualify both positive and negative behavior for the exact vendor version, settings, algorithms, certificates, claims, schema extensions, and operational topology.

Declare the contract

Record protocol version, flow, bindings, endpoints, algorithms, issuer and audience rules, schemas, claims, error semantics, and lifecycle ownership.

Run conformance and abuse cases

Test happy path plus replay, expiry, wrong audience, algorithm downgrade, malformed metadata, key rotation, duplicate operations, and unavailable dependencies.

Capture evidence

Retain configuration digests, test inputs and outputs, exact builds, timestamps, negative results, and reviewer decisions.

Pilot and observe

Route a bounded cohort, compare incumbent and Atlas outcomes, confirm rollback, then approve the next wave.

Qualification record: capture the tested vendor version, configuration, protocol profile, evidence package, operating environment, and applicable authorization state.