one identity
Sign in once, everywhere.
A single obex session carries scoped permissions across every nominal app, plus linked third-party access like GitHub App installations.
identity session
One obex identity, scoped permissions per app, and linked third-party access — all from a single session.
how it works
From login to linked access, in one flow.
01
User logs in
Passkey, OAuth, or a provider you've wired up.
02
Permissions scoped
Each app gets exactly the access it's granted, nothing more.
03
Identity linked everywhere
The same identity, and its linked resources, carries to every app.
capabilities
under the hood
Built for teams who audit everything.
Session inspector
See every active session across every app, and revoke any one of them instantly — no waiting on token expiry.
Full audit log
Every permission grant and login is logged and exportable.
Org SSO
SAML and OIDC for teams who need it, without extra config per app.
Scoped API keys
Issue rate-limited, resource-scoped API keys tied to the same identity system as your user logins.
obex faq
Identity, answered.
Ready to develop with obex?
Get access at obex.nominal.es and talk to the team building it.