Skip to content
Boston Identity

SAML 2.0 · OAuth 2.0 · OIDC · PKI

Identity is all we do.

Workforce and customer IAM for organizations where getting access wrong is expensive.

A SAML 2.0 single sign-on exchangeAn unauthenticated request to a service provider is redirected to an identity provider as an authentication request. The user authenticates, and the identity provider returns a signed assertion, which the service provider validates before granting a session.UseragentServiceproviderIdentityprovidertrust boundary1. GET /appunauthenticated request2. AuthnRequestredirect, SAMLRequest3. Credentials + MFAuser authenticates4. Assertionsigned, POST to ACS
SAML 2.0 web browser SSO profile. The assertion is signed by the identity provider and validated by the service provider before a session exists.

We Provide Essential IAM Services

With more than a decade of experiences in IAM, the team of Boston Identity are confident in advising and implementing IAM Solutions to best fit your needs.

  • Modern IAM Platform

    We focus on modern enterprise-grade IAM platform implementation and integration.

    Selection, architecture and rollout to production. Usually the multi-quarter program the other three hang off.

  • DevOps in Clouds

    We use latest DevOps tech stack to automate and orchestrate your core IAM services in the cloud

    Provisioning, configuration and release automation for identity services. Typically runs alongside a platform build rather than alone.

  • Legacy App Migration

    We help you migrate legacy apps to next-gen IAM platform seamlessly and efficiently.

    Scoped in application waves, with old and new running in parallel. The co-existence period is the part that decides whether it works.

  • SSO & MFA

    We implement various Authentication & Authorization strategies for SSO and MFA

    SAML, OAuth 2.0 and OIDC design and rollout, with MFA policy. Often the first engagement and the fastest to show a result.

Platforms we implement

  • Ping Identity
  • ForgeRock
  • Okta
  • Radiant Logic
  • Keycloak
  • Spring Security SAML

Proof of work

What we have built with AI

We use AI in our own engineering and publish what happens — the results and the trade-offs. Two recent pieces:

  • live tool

    saml-box.com

    IdP on Keycloak · SP on Spring Security SAML · live

    A public test Identity Provider and Service Provider for SAML integration, built as an experiment in AI-assisted development.

  • write-up

    From Human-in-the-Loop to AI-in-the-Loop Debugging

    September 2025

    Using a language model to read logs, suggest fixes and generate code while debugging custom IAM endpoints — and where it falls short.

Inside the boundary

Workforce IAM

Large enterprise mandates access control at scale. Yet, with the rising trend of hybrid workforce and cloud services, next-gen workforce IAM solutions are becoming increasingly more critical.

  • Enhance Work Efficiency
  • Authorize with Flexible Policy
  • Handle Legacy Applications
  • Monitor Continuously

Across the boundary

Customer IAM

In contrary to workforce IAM, CIAM requires enterprises to securely capture customer identity and profile data, while managing their access to applications and services.

  • Empower a Frictionless Customer Experience
  • Strengthen Security While Preserving Usability
  • Emphasize Extreme Data Protection
  • Deliver Ultra Performance Beyond Scale

Tell us what your identity program has to do next.

We will tell you what it takes, in writing, before anyone signs anything.

Start a conversation