Defender for the agent era
Obelisk is the identity & security plane for everything you build — passkey-first login, one OIDC provider, tamper-evident receipts, and a single live security Rating. Security you can prove, not just promise. The circle closes as you're protected.
What it is
Every project points at one login. Every access leaves a signed receipt. Every posture rolls up into one number you can act on. Obelisk is passkey-first, secret-free for relying parties, and built so you can never be locked out — the security layer a network of products can actually stand on.
Phishing-resistant WebAuthn by default. No passwords to steal, phish, or leak — the credential never leaves the device.
A standards-compliant OpenID Connect provider AND a SAML 2.0 IdP — PKCE, JWKS, refresh-rotation, plus RSA-signed SAML assertions for legacy SPs. Every app points at one login; zero project-side secrets.
A single 0–100 security score from 1,000+ live signals, with confidence and trend. Your logo literally renders it — hue is your band, lit segments are your coverage.
Every login, token, grant, and access leaves a signed, chained receipt. Observe nothing without a trace — the audit can't be quietly rewritten.
A dual-store resilient backend, break-glass recovery, and encrypted offline backup — plus integrity-verified disaster-recovery backups taken off-box to Cloudflare R2 daily and a self-healing health watchdog. Lose the whole box and you're back in ~15 minutes; you cannot be locked out of your own keys.
Access tokens can be bound to the client's own key (RFC 9449): every call must carry a fresh on-device proof, so a stolen token without the private key is inert. Built for agent workloads, where bearer-token theft is the dominant threat.
Built for the quantum-resistant future — node-native crypto, no custom primitives, a documented PQC migration path baked into canon.
A real-time risk engine that watches every login and action, scores it across 11 dimensions — device, location, velocity, blast radius, secret proximity — and decides: allow, step up, or deny. Adaptive security that judges every passage, never just watches.
One passkey-first front door for every tool your team uses. Federate Cloudflare, 1Password, and Microsoft Entra over OIDC, and GitHub, Google Workspace, AWS, Slack, Atlassian and more over the SAML 2.0 IdP — every sign-in inherits the same phishing resistance.
Drop a “Secured by Obelisk Gate” login card onto any site with one script tag. It's served live from obeliskgate.com, so it can't be forged, auto-updates itself, and shows the site's live Obelisk Rating.
Bring a business or a website and get its own Obelisk Rating. Register an organization, invite a team, measure and raise your posture — live today.
The Obelisk Rating
A single 0–100 score from 1,000+ live signal points — never-lockout, database integrity, OIDC health, threat coverage, access control, and more — each with a confidence weight and a trend. The mark renders it: the ring's hue is your band, its lit segments are your coverage. The circle closes as you're protected.
Why it's trusted
For teams & businesses
Register a business or a website and give it its own Obelisk Rating. Invite a team under one organization, manage members, and raise your score with concrete, prioritized levers. Dev-first and enterprise-ready — live today.
Try it now — a live TLS + security-header scan of any public site. Nothing stored.
Passkey-first, password-free, and trusted across every product. Your identity, protected by Obelisk.
Create your passkey →