Native Guard
A FAPI-aligned OIDC / OAuth 2.1 authorization server. Managed alternative to self-hosted Keycloak with the regulatory perimeter built in. Multi-tenant, multi-realm, native AOT runtime.
- PAR · JARM · mTLS · DPoP · PKCE
- Private Key JWT client auth
- PS256 / ES256 signing · JWKS rotation
- Dynamic Client Registration (DCR)
- Bot defense via Turnstile per realm