Security & Access
Authentication
SSO on every plan, with no upcharge
Let your identity provider decide who works here, so onboarding and offboarding happen in one place instead of one more list to keep in sync. Connect the identity provider you already run, and the first login creates each account with the right group memberships, while removing someone from your directory removes their access here too.
- Enterprise single sign-on, included on every plan
- Exempt a member or domain from SSO when you must, with two-factor still enforced
Identity providerSingle sign-on · okta.northwind.comCONNECTEDPROTOCOLSSOPLAN COSTNO UPCHARGEAUTO-CREATED · FIRST LOGINACCOUNTGROUPSROLEYour directory stays the source of truth
A secure way in for everyone who needs it
Give everyone a secure way to sign in, whether or not they sit in your directory. Passkeys use the biometrics already on a laptop for phishing-resistant sign-in, social login covers the contractors and auditors who aren't in your directory, and email and password stays available with two-factor from an authenticator app for anyone who uses it.
- Passkeys and hardware security keys, with no shared secret to steal or phish
- App-based two-factor with recovery codes on password accounts
HOW PEOPLE SIGN INALL ENABLEDPasskeyNO PASSWORD · PHISHING-RESISTANTSocial loginFOR CONTRACTORS AND AUDITORSEmail and passwordAUTHENTICATOR APP · RECOVERY CODES2FATwo-factor available on every method
Your domain decides who can join
New hires get to work without waiting on an invite, and no one wanders in by guessing your organization name. Verify the email domains that belong to your organization, and anyone signing in from one joins automatically with a default role while everyone outside it stays out.
- Verified-domain allowlist, so a guessed org name gets no one in
- Auto-join with a default role, no invite to chase
ALLOWED EMAIL DOMAINSAUTO-JOIN ONnorthwind.comVERIFIEDeng.northwind.comVERIFIED[email protected]Joined with the default roleMEMBERAnyone outside a verified domain still needs an invite
Included with Every Plan
SSO shouldn't cost extra
No security tax
SSO, 2FA, and passkeys come with every plan, so the control that stops account takeover is on from the start.
One place to revoke access
When your identity provider disables someone, their Openlane access goes with it. Sessions and tokens can also be revoked directly for anything outside the directory.
Evidence for the auditor
Authentication method, 2FA enrollment, and login activity are recorded per user, so access-control evidence is a report instead of a screenshot exercise.










