Tenant issuer hosts
Issuer metadata, login, token issuance, and claims are resolved for the current host.
Architecture
OpenIssuer resolves the issuer from the incoming host, so each tenant can use a distinct authorization domain while sharing the same platform.
Issuer metadata, login, token issuance, and claims are resolved for the current host.
Admins manage organizations, users, roles, OAuth clients, and default organization behavior.
Users can enroll passkeys and complete MFA during the authorization flow.