HankoShell

HankoShell.
Private IAM foundation.

OIDC foundation, identity sources, governance, machine identities, audit and exports come together in an operable surface for critical applications.

Stable facade

Issuer, discovery, JWKS and endpoints stay readable for your applications.

Governance

Organizations, applications, roles, sessions, MFA and policies are managed from a shared surface.

Evidence

Audit, exports, architecture, runbook and reversibility form an operable evidence pack.

HankoShell capabilities

Operational proof, ready for production.

Stable OIDC facade for critical applications
AD, Entra, Okta and Google sources connected to critical applications
SSO, MFA, sessions and security policies
Organizations, applications, roles and themes
SCIM, lifecycle and application entitlements
MCP connector for agents and internal tools
M2M service accounts and secret rotation
PKI, X.509 certificates and SPIFFE identifiers
Vault, master key and recovery backup
Audit log, exports and evidence for IT/security leadership
Migration, directory, config and audit exports
Architecture and controlled network surface pack
Controlled OIDC / OAuth 2.1 flows
Docker Compose or Helm packaging
Operating runbook and HankoShell guidance
Documented reversibility and exports

Existing connectors

HankoShell connects to the identity sources already in place.

Active Directory, Entra ID, Okta, Google Workspace, Auth0, Authentik or Keycloak remain the starting points. HankoShell adds the application surface: roles, tenants, sessions, audit and evidence.

Active Directory

Identity source

Microsoft Entra ID

Identity source

Okta

Identity source

Google Workspace

Identity source

Auth0

IAM backend

Authentik

IAM backend

Keycloak

IAM backend

JSON import

Migration

Above the directory

Directories keep identity. HankoShell controls application access.

Organizations often start with Active Directory, Entra ID, Okta or Google Workspace. HankoShell applies above them to turn those identities into governable access for critical applications.

Source

AD, Entra, Okta, Google

Users, groups and corporate authentication stay in the sources already adopted by the organization.

Control plane

HankoShell mapping and governance

HankoShell maps groups to tenants, roles, application entitlements, session policies, MFA, audit and exports.

Applications

Stable facade for every app

Applications consume HankoShell as a stable OIDC issuer, with a readable access model and operable evidence.

Identity sourcesHankoShellCritical applications

HankoShell surface

From SSO to machine identities.

HankoShell anchors human, application and machine identity in one foundation operated by product, platform and security teams.

Applications

Clean OIDC for every application

SPA/PKCE or confidential clients, redirect URIs, post-logout, SDK manifests, MCP connector and per-app themes accelerate enterprise integration.

People

Governable access every day

MFA, security profiles, active sessions, revocation, users, groups and roles give teams a clear administration surface.

Machines

Machine identity built into the foundation

Service accounts, scopes, secrets, X.509 certificates, SPIFFE identifiers, PKI and rotation cover M2M flows.

Evidence

Defensible operations

Audit log, metrics, directory, config and audit exports, migration and runbooks structure the IT/security evidence pack.

FAQ

Common questions.

What does HankoShell include?

HankoShell brings together an OIDC foundation, access governance, audit, PKI, vault, machine identities, self-hosted packaging, exports and key enterprise capabilities.

How does HankoShell integrate with our existing IAM?

HankoShell sits above existing identity sources such as Active Directory, Entra ID, Okta, Google Workspace, Auth0, Authentik or Keycloak, then exposes a stable OIDC facade to applications.

Do our data stay in our infrastructure?

Yes. HankoShell runs in your infrastructure. Tokens, sessions and logs stay inside your operating perimeter.

Who should evaluate HankoShell?

The best signal comes from the CTO or Head of Platform, IT leader and security leader. HankoShell touches application delivery, operations and security evidence.