Skip to content

Kleora documentation

Add hosted sign-in to your application, verify the token on your API, and manage users, workspaces and roles from one console.

Kleora gives your application a sign-in page you do not have to build, and an access token your API can verify on its own. You create an App in the console, point one of our SDKs at it, and your users sign in on a page hosted on that App's own address — branded by you, with email and password, TOTP codes and, on Pro, passkeys.

Every App comes with two environments, sandbox and production, each with its own users, its own signing keys and its own address. Nothing you try in sandbox can reach anybody real.

Start here

  • Quickstart — from an empty project to a working sign-in.
  • Installing an SDK — the five packages we publish, and what each one is for.

What you get

  • Hosted sign-in. Sign-in, sign-up, email verification, password reset, MFA and workspace selection are pages we host and you brand. Your application never sees a password.
  • Standard OAuth 2.1 and OpenID Connect. Authorization code with PKCE, discovery, JWKS, rotating refresh tokens, and the device grant for terminal tools and agents. Everything is published at {issuer}/.well-known/openid-configuration, so a generic OIDC client works just as well as one of ours.
  • Workspaces and roles. Workspaces, invitations and roles scoped to one workspace. Roles and permissions ride in the access token, so your API reads them from the token instead of asking us.
  • A management API. Everything the console does, your own code can do: users, workspaces, clients, roles, API keys and the audit log.

The free plan includes 10,000 monthly active users pooled across every App in your account. Passkeys and a required MFA policy are on Pro and above.