OAuth 2.1 · OpenID Connect · WebAuthn

Zero passwords.
Zero compromise.

BlackWall is a production-grade authorisation server where passwords simply don't exist. Hardware keys, passkeys and platform authenticators, combined with fully standards-compliant OAuth 2.1 and OpenID Connect, give your applications authentication infrastructure that cannot be phished, breached or guessed.

WebAuthn OAuth 2.1 OpenID Connect SAML 2.0 SCIM 2.0 Ed25519 licensing Tamper-evident audit Multi-tenant
The control plane

One console for identity,
entitlement and evidence

Most companies buy an identity provider, a licensing system and an audit tool, then spend a year making them agree with one another. BlackWall ships all three against a single tenancy model, so a user, the software they are entitled to, and the record of what they did are the same story told once.

The BlackWall administrator dashboard showing registered users, projects and OAuth clients, success and failure outcome profiles over today, seven and thirty days, CSRF pressure, approval SLA, a recent audit event stream, and a build and security status panel reporting the running version, commit and last successful vulnerability scan.
The administrator dashboard. Outcome trends, CSRF pressure, approval latency and release provenance on one screen — the questions an auditor actually asks, answered without a query.
0
Passwords stored

No password column, no reset flow, no credential-stuffing surface.

10
Privilege rungs per project

Named, ordered tiers that travel inside the token as claims.

5
Federation surfaces

OIDC, OAuth 2.1, SAML 2.0, SCIM 2.0 and signed webhooks.

100%
Actions audited

Every mutation, flow and assertion, hash-chained row by row.

Software licensing

Sell your software.
Prove the entitlement.

Licensing is usually a spreadsheet, a shared secret and an argument at renewal time. BlackWall turns an entitlement into a cryptographic object: signed with Ed25519, bound to exact hostnames, scoped to named features, and revocable the moment a contract ends.

  • Bound to reality — up to 32 exact hostnames or IP literals. Wildcards are rejected, not tolerated.
  • Tamper-proof — edit any claim and the signature fails. There is nothing to negotiate.
  • Revocable — an authoritative verifier answers in real time, so cancellation takes effect immediately.
  • Renewal aware — reminders are queued at 30, 14, 7, 2 and 1 days before expiry.
How licensing works
The project licences screen showing a signing service with an active Ed25519 key, a renewal reminder schedule with delivery history, and a register of issued licences listing entity, bound hostnames, licensed features, instance limits, issue and expiry dates, and revoke controls.
The licence register: signing key, reminder history, and every issued entitlement with its bound hostnames, features and expiry — plus one-click revocation.
Audit & assurance

Evidence you can
hand to an auditor

An audit log that anyone with database access can quietly edit is not evidence — it is a formality. BlackWall chains every row into the one before it, so altering a single historical entry invalidates every entry that follows and the tampering announces itself.

  • Hash-chained rows — each entry commits to its predecessor under a serialising lock.
  • Signed checkpoints — the tip of the log is signed and published, so truncation is detectable too.
  • Correlation IDs — trace one end-user request across every service it touched.
  • Full coverage — admin mutations, OAuth flows and WebAuthn assertions alike.
How assurance works
The audit log screen listing events by timestamp with event type, outcome, actor, project, target, source IP address and correlation identifier, with filters across the top and paginated results.
Every event carries its actor, target, source address and correlation ID — filterable, paginated, and exportable with an HMAC-signed manifest.
Cryptbin — secure sharing

Share a secret.
Never the plaintext.

Cryptbin is end-to-end encrypted sharing built directly into the platform. Your browser generates the key and keeps it in the URL fragment — the part browsers never send to a server. BlackWall stores ciphertext it cannot read.

AES-256-GCM Client-side keys WebAuthn gated Auto-expiry
How Cryptbin works
The Cryptbin creation screen offering a choice of text or file content, with size limits, expiry options and a create button, ready to encrypt in the browser.
Text or file, encrypted locally before upload. Handy for API keys, incident logs and onboarding credentials that should never sit in a chat history.
Who it's for

Built for teams who have to
prove it, not just say it

Software vendors

Authenticate customers and license the product they bought from the same platform, with revocation that actually takes effect.

Regulated businesses

Tamper-evident audit, approval workflows and release provenance — the evidence an assessor asks for, produced as a by-product of normal use.

Platform teams

One identity surface for many products, isolated per project, with privilege levels that arrive inside the token instead of a bespoke lookup.

Security-first startups

Start with no passwords at all. There is no migration to phishing-resistant auth later, because there was never anything to migrate.

Stand up passwordless identity for your business.

Create an organisation, enrol your first authenticator, and issue a token from a real OAuth 2.1 flow — without a password existing anywhere in the process.