Modern web and mobile
OIDC authorization code with PKCE, explicit audiences, short token lifetimes, refresh policy, and application-local authorization where appropriate.
Protocols and integration
Atlas supports modern identity protocols, lifecycle interfaces, directory integration, workload identity, and bounded legacy profiles. Compatibility is stated at profile level so each flow has a clear interoperability contract.
Compatibility matrix
Implemented means the profile is present in Atlas. Bounded profile requires exact flow qualification. Deployment-dependent requires external infrastructure or custody.
| Area | Profiles and capabilities | Posture | Notes |
|---|---|---|---|
| OpenID Connect | Discovery, authorization code, PKCE S256, client registration and policy, claims, UserInfo, logout patterns | Implemented | Client type, redirect, issuer, audience, claim, and signing policy remain explicit. |
| OAuth 2.x | Authorization code, client credentials, device authorization, refresh, introspection, revocation, token exchange, PAR, DPoP | Profile-bounded | Grant eligibility and proof-of-possession are configured per client and authorization server. |
| CIBA and CIMD | Bounded poll/ping backchannel flows and configured client metadata discovery patterns | Profile-bounded | Requires explicit client, issuer, authentication, delivery, and operational qualification. |
| SAML 2.0 | IdP and SP roles, metadata, signing, encryption, attribute contracts, SSO and logout routing | Implemented | Algorithm, binding, NameID, encryption, and certificate profiles are partner-specific. |
| SAML 1.0 / 1.1 | Bounded direct inbound and browser/interoperability profiles | Profile-bounded | Use for controlled migration where the exact legacy profile has been qualified. |
| WS-Federation / WS-Trust | Bounded sign-in, metadata, token issue, renew, cancel, and proof-key profiles | Profile-bounded | Qualification records the exact WS-* endpoint, dialect, version, and configuration. |
| SCIM | SCIM 2.0 lifecycle and outbound integration; AIO supports configured inbound SCIM 1.1/2.0 paths | Implemented | Schema extensions, filtering, pagination, patch behavior, and authority direction require mapping. |
| LDAP and AD patterns | LDAP, LDAPS, StartTLS, directory source mapping, groups, lifecycle, and adapter patterns | Deployment-dependent | Schema, referrals, paging, password flows, network and certificate trust must be qualified. |
| Authentication | WebAuthn/FIDO2, TOTP, password, push, recovery, certificate and smart-card patterns | Deployment-dependent | CAC/PIV and hardware-backed assurance require approved readers, middleware, PKI, validation and policy. |
| Application APIs | REST, GraphQL, WebSocket, webhooks, operational evidence exports | Implemented | Administrative APIs require authenticated, authorized tenant context and version discipline. |
| Workload identity | mTLS, TLS 1.3 patterns, SPIFFE/SVID-aligned extension and service identity interfaces | Deployment-dependent | Production trust domain, CA custody, rotation, attestation, and mesh integration are external authorities. |
Application integration
Atlas can front an application, act as its identity provider, provision accounts, translate a bounded legacy profile, or place an agent near the resource. The right pattern minimizes protocol translation and keeps enforcement close to the protected action.
OIDC authorization code with PKCE, explicit audiences, short token lifetimes, refresh policy, and application-local authorization where appropriate.
SAML or OIDC for access, SCIM for lifecycle, entitlement mapping, group push, and application-account reconciliation.
Client credentials, token exchange, DPoP or mTLS, resource indicators, workload identity, and scoped service policy.
Protocol adapters and bounded federation profiles with exact negative testing, certificate validation, and rollback route.
Approval, vault-backed secret access, session constraints, managed accounts, executable policy, and enhanced evidence.
Pre-positioned signed policy, bounded offline evidence, locally enforceable decisions, and attributable reconciliation.
Identity and evidence sources
Source connectors map external objects into Atlas while retaining source identifiers, schema, timestamps, authority, and reconciliation status. One source may own employment status while another owns device posture; normalization preserves those distinct authorities.
Vendor migration and coexistence
Atlas migration workspaces inventory objects, map controls, identify conflicts, reconcile identities, and compare application outcomes. A route moves only for an approved application and cohort.

Interoperability qualification
Before production routing, qualify both positive and negative behavior for the exact vendor version, settings, algorithms, certificates, claims, schema extensions, and operational topology.
Record protocol version, flow, bindings, endpoints, algorithms, issuer and audience rules, schemas, claims, error semantics, and lifecycle ownership.
Test happy path plus replay, expiry, wrong audience, algorithm downgrade, malformed metadata, key rotation, duplicate operations, and unavailable dependencies.
Retain configuration digests, test inputs and outputs, exact builds, timestamps, negative results, and reviewer decisions.
Route a bounded cohort, compare incumbent and Atlas outcomes, confirm rollback, then approve the next wave.