Available for selected product partnerships and engineering engagements.Start a project →
Open-source identity infrastructure

Identity you can verify.
Accounts you can trust.

OpenProof separates proof, identity and access. Passkeys, social sign-in, wallets and enterprise federation can meet one account model without silently merging users by coincidence.

PasskeysWebAuthn / FIDO2 OAuth / OIDCFederation SIWE / SIWFWallet proofs SAML / LDAPSEnterprise
PASSKEY WebAuthn OIDC Federation SIWE Wallet SAML Enterprise
OpenProof
proofidentityaccess
01 / Principle

Proof is evidence. Identity is a decision.

OpenProof keeps protocol verification, account linking and authorization as separate, auditable steps.

01

Verify the proof

Validate signatures, state, nonce, PKCE, issuer, audience and replay boundaries before identity is considered.

02

Link explicitly

A verified subject joins a canonical account through an explicit relationship — never because two providers happen to share an email.

03

Issue controlled access

Sessions and tokens carry the assurance and authorization context the relying application actually needs.

02 / Account model

Different proofs. One explicit account.

Each credential keeps its own provenance and verification rules while the canonical account remains stable.

Proof adaptersindependent inputs
PasskeysWebAuthn · FIDO2
01
ProvidersOAuth · OIDC
02
WalletsSIWE · SIWF · ERC-1271
03
EnterpriseSAML · LDAPS · SCIM
04
Identity core

OpenProof

01Verify 02Link 03Authorize
The rule is intentionally simple: verification proves a credential; an explicit relationship connects that credential to an account.
03 / Surface

One identity surface, without flattening the protocols.

Applications get a consistent account surface while OpenProof preserves the security semantics behind each proof type.

01

Passkeys

WebAuthn · FIDO2 · phishing-resistant authentication

02

OAuth / OIDC

Provider federation with issuer and subject provenance preserved.

03

Wallet identity

SIWE · SIWF · ERC-1271 · signed ownership proofs

04

Enterprise identity

SAML 2.0 · LDAPS · SCIM 2.0 · RBAC

05

Sessions & tokens

Carry assurance and authorization context without collapsing proof provenance.

06

Self-hosted boundary

Keep identity policy, provider credentials and persistence inside infrastructure you control.

04 / Self-hosting

Keep the trust boundary where your infrastructure lives.

OpenProof is designed to sit behind your own HTTPS edge, with your datastore, provider credentials and session policy under your control.

Your trust boundary

Own the origin, secrets and state.

No hosted Genyleap identity service is required. Deploy OpenProof inside the environment you operate and expose only the interfaces your applications need.

Your originChoose the public identity URL. Your secretsKeep provider credentials in your secret boundary. Your datastoreOperate the persistence layer you trust.
Self-hosting guide
Example deploymentHTTPS / private state
ApplicationWeb / API
→
Identity coreOpenProof
→
StatePostgreSQL
OAuth / OIDCWallet proofsSAML / LDAP
Only public interfaces cross the boundary.
05 / Providers

Web2, Web3 and enterprise — side by side.

Provider-specific proof stays provider-specific. The account surface does not need to be.

GoogleOIDC GitHubOAuth XOAuth MicrosoftOIDC AppleOIDC LinkedInOIDC TelegramLogin EthereumSIWE FarcasterSIWF
Open source · Self-hosted

A clearer identity boundary, from proof to access.

Build on a canonical account model without giving up the protocol boundaries that make each proof meaningful.

v1.1OpenProof C++26Core ★ 1GitHub