Identity engine

obex

One identity for every app you build.

passkeys

one identity

Sign in once, everywhere.

A single obex session carries scoped permissions across every nominal app, plus linked third-party access like GitHub App installations.

identity session

passkey github app oauth

One obex identity, scoped permissions per app, and linked third-party access — all from a single session.

how it works

From login to linked access, in one flow.

01

User logs in

Passkey, OAuth, or a provider you've wired up.

02

Permissions scoped

Each app gets exactly the access it's granted, nothing more.

03

Identity linked everywhere

The same identity, and its linked resources, carries to every app.

capabilities

Shared across every app

Every nominal product authenticates through obex, so a single identity carries across your whole stack.

Granular permissions

Scope access down to the exact resource and action — no app gets more than it needs.

OAuth, out of the box

Wire up countless login providers with minimal configuration, no bespoke integration work.

Linked identities

Attach third-party resource access — like GitHub App installations — directly to a user identity.

WebAuthn & passkeys

Modern, phishing-resistant authentication is a first-class citizen, not an add-on.

under the hood

Built for teams who audit everything.

Session inspector

See every active session across every app, and revoke any one of them instantly — no waiting on token expiry.

Full audit log

Every permission grant and login is logged and exportable.

Org SSO

SAML and OIDC for teams who need it, without extra config per app.

Scoped API keys

Issue rate-limited, resource-scoped API keys tied to the same identity system as your user logins.

obex faq

Identity, answered.

Ready to develop with obex?

Get access at obex.nominal.es and talk to the team building it.