Single Sign-on (Brokering)
kiLM delegates login to your IdP over OIDC or SAML 2.0. Users click "Sign in with your provider", authenticate and pass MFA there, and land in kiLM — no kiLM-side password ever exists.
Identity & single sign-on
kiLM federates to your existing identity provider and directory — OpenID Connect, SAML 2.0, SCIM 2.0, and LDAP / Active Directory — so people keep one corporate login and your admins keep one source of truth. There is no separate kiLM password to manage.
Single sign-on brokers your IdP for login; directory federation imports users and groups from LDAP/AD. Use either, or both.
kiLM delegates login to your IdP over OIDC or SAML 2.0. Users click "Sign in with your provider", authenticate and pass MFA there, and land in kiLM — no kiLM-side password ever exists.
kiLM connects read-only to your LDAP or Active Directory, imports user accounts, and re-syncs on a schedule so joiners and leavers flow through automatically.
Map an upstream group, claim, or attribute to a kiLM role. Membership re-evaluates on every login, so access follows your directory — not a spreadsheet.
One-click wizards for the major providers, plus generic OpenID Connect and SAML 2.0 for everything else.
Guided setup: register kiLM, paste your tenant and client credentials, and endpoints are discovered automatically.
Dedicated presets for Okta and Google Workspace with the same single-form configuration.
Generic connectors cover ADFS, Ping, OneLogin, Auth0, Authentik, Zitadel, Keycloak and more — by discovery URL (OIDC) or metadata URL / pasted XML (SAML, which works air-gapped).
LDAP v3 over LDAPS, read-only, with per-directory defaults you can override attribute by attribute.
Defaults tuned for AD (sAMAccountName / objectGUID / member groups) — the common enterprise case, configured in one form.
inetOrgPerson / uid / entryUUID defaults for OpenLDAP and other RFC 2307 directories.
A profile for Red Hat Directory Server, 389 Directory Server, and FreeIPA. Any attribute can be overridden when your schema differs.
Your IdP pushes user create, update, and deactivate to kiLM in real time over the SCIM 2.0 standard (RFC 7643 / 7644) — no waiting for the next directory sync or login.
Entra ID, Okta, and any SCIM 2.0 IdP push account create, update, and deactivate the moment they happen, so deprovisioning is instant rather than at next sync or login.
A full SCIM 2.0 Users endpoint — create, replace, patch, deactivate, filtered list and ServiceProviderConfig — backed by the same identity store as SSO. SCIM groups map to kiLM roles per IdP.
Each IdP authenticates with its own bearer token, shown once and stored only as a SHA-256 hash. SCIM stays disabled until you switch it on, and a drift check flags any divergence between your IdP and kiLM.
Your identity system stays the source of truth; kiLM follows it.
Bind an IdP group/claim or an LDAP group to a kiLM role. Elevated (admin / executive) roles require an explicit acknowledgement before they can be auto-granted from an upstream group.
Multi-factor happens in your identity provider, so your existing MFA policy applies. kiLM also supports per-role MFA enforcement and admin-initiated session revocation.
Disable or remove someone at the source: SSO blocks their next login immediately, and scheduled LDAP re-sync (daily / weekly) reflects directory changes automatically.
Who can see what is enforced everywhere kiLM reads. Identity from your IdP maps to a kiLM role; every chunk of data carries a sensitivity class; and retrieval, chat and tools honour both — deny-by-default, least-privilege, fully audited.
A user’s kiLM role comes from your identity provider’s groups, claims or LDAP groups — never a local copy that can drift. Roles carry entitlements; access is deny-by-default and least-privilege.
Every chunk carries a classification — public, internal, confidential, restricted or secret — that follows the data across vector, lexical, graph and visual retrieval. A chunk a user’s role can’t see is never surfaced or cited.
When kiLM ingests from SharePoint, PLM, drives and other systems, it captures the source’s access-control lists, so the permissions your systems of record already enforce carry into kiLM and apply at query time.
Governance, access control and audit are part of retrieval itself, not a wrapper around it. The chat agent refuses to surface anything a role can’t see, and answers are grounded only in permissioned evidence, returned with citations.
Elevated (admin / executive) roles require an explicit acknowledgement before they auto-grant; per-functionality entitlements stay off until enabled; and every tool, connector and MCP call is ACL-checked per caller.
Every access decision and MCP invocation is written to an audit trail. A daily reconciliation cross-checks the source-of-truth classification against every retrieval store and fires a high-severity finding on any drift — resolvable in one click.
Identity integration honours your network Model — see Deployment Patterns.
On-prem IdPs (ADFS, on-prem Keycloak) and LDAP / AD are intranet-only and work fully air-gapped — no outbound connection required at run time.
Cloud providers such as Entra, Okta, and Google are reached through your approved egress; under a sealed air-gap profile they are deliberately blocked.
Running kiLM as a managed single-tenant instance? The same identity options apply on your chosen cloud.
Planned identity enhancements — not yet generally available.
Back-channel logout so signing out of your IdP also ends any active kiLM sessions — distinct from admin-initiated session revocation, which is available today.
Tell us which IdP or directory you run and we will confirm the integration path in your quote.
Tell us about your use case. We review every request and a member of our team will be in touch within one business day.