Skip to content

Synq is pre-launch. Early access is by request. Ask for early access

Customer identity for businesses

Branded sign-in for every product you ship.

Synq is an OpenID Connect issuer for your business. Each of your brands gets its own issuer, its own users and its own sign-in, and your engineers stop writing and maintaining auth code.

The problem

Sign-in is the first thing users see.

Build it badly and you lose people at the front door. Build it yourself and you spend a quarter on something that isn’t your product, then keep paying for it: OAuth integrations, token rotation, consent screens, abuse and audits. Synq takes that off your team’s hands, on the open standards your engineers already know.

How it works

Your own issuer, in three steps.

  1. Create a brand

    Your org gets a brand with its own issuer at https://<your-slug>.auth.synq.build, its own users and its own signing keys.

  2. Register your apps and APIs

    Tell Synq each app’s type and exact redirect URIs, and each API’s scopes. App secrets are shown once and stored only as hashes.

  3. Point any OpenID Connect library at it

    Your library reads the rest from the discovery document: ID tokens, access tokens for your APIs, and refresh tokens that rotate.

Every brand’s discovery document
GET https://acme.auth.synq.build/.well-known/openid-configuration

{
  "issuer": "https://acme.auth.synq.build",
  "authorization_endpoint": "https://acme.auth.synq.build/auth",
  "token_endpoint": "https://acme.auth.synq.build/token",
  "userinfo_endpoint": "https://acme.auth.synq.build/userinfo",
  "jwks_uri": "https://acme.auth.synq.build/jwks",
  "code_challenge_methods_supported": ["S256"]
}

Capabilities

An identity layer, not a login widget.

Built means it is in Synq’s code and tested today. Building means it is part of Synq’s first release and not finished yet.

Built

An issuer for every brand

Each brand gets its own OpenID Connect issuer, its own user pool and its own signing keys. Users of one brand never mix with another.

Built

Every kind of app

Web apps, single-page apps, native apps, machine-to-machine services, CLIs and AI agents through the device flow, and MCP hosts that register themselves.

Built

Tokens for your own APIs

Register your APIs and their scopes. Apps get short-lived JWT access tokens meant for one API, and refresh tokens that rotate on every use.

Built

A management API

Orgs, brands, apps, APIs, users, members and roles, all through a documented /v1 API with scoped API keys, idempotent writes and cursor pagination.

Built

Webhooks and an audit log

Every change is recorded in your audit log and can be sent to your systems as a signed webhook, retried until it arrives.

Building

A sign-in page that looks like yours

Hosted sign-in pages themed per brand, with your own OAuth credentials, so Google and Apple show your name on their consent screens.

Email and password today. Wallets, social accounts and passkeys next.

Every plan will get every sign-in method, and you choose which ones each brand offers.

  • Email and password(Built)
  • Email codes and magic links(Building)
  • Passkeys(Building)
  • Solana wallets(Building)
  • Google(Building)
  • Microsoft(Building)
  • Discord(Building)
  • Apple(Building)
  • X(Building)
  • Facebook(Building)
  • Telegram(Building)
  • Matrica(Building)

Security

Tenants never see each other.

Synq holds your users and signs the tokens your apps trust. The rules that keep that safe are in the code and in its tests, not in a policy document.

  • Postgres itself refuses a reference from one tenant’s data into another’s.
  • PKCE on every request, exact redirect URIs, single-use codes and rotating refresh tokens.
  • App secrets, API keys and passwords are stored only as hashes; signing keys are encrypted.
  • Logs and traces never hold a token, a code, a cookie, a password or a key.

Pricing

Free to start, priced by users.

Four plans, from a first product to a portfolio of brands. Your users never pay; businesses pay by plan and monthly active users. These are the prices Synq plans to launch with.

  • Starter

    $0

    For a first product and a first thousand users.

  • Pro

    $39 a month

    For a product in production that has outgrown the defaults.

  • Scale

    $199 a month

    For several brands and a large user base.

  • Enterprise

    Custom

    For volume, contracts and requirements of your own.

FAQ

What businesses ask first.

Can I use Synq today?
Not on your own yet. Synq is pre-launch: the issuer, apps, APIs, the management API, webhooks and the audit log are built and tested, and the rest of the first release is being built now. Ask for early access and tell us what you are building.
Is Synq a login widget?
No. Synq is a full OpenID Connect issuer, one per brand. Anything that speaks OpenID Connect or OAuth 2.0 can use it: websites, mobile apps, backend services, CLIs and AI agents. There is no proprietary SDK to live inside; Synq’s own SDKs will be conveniences on top of the standards.
Which sign-in methods does Synq have?
Email and password is built. Email codes and magic links, passkeys, Solana wallets, Google, Microsoft, Discord, Apple, X, Facebook, Telegram and Matrica are being built for the first release. Every plan will get every method.
Do my users pay anything?
No. People who sign in to your apps never pay for Synq. Businesses pay by plan and by monthly active users.
Will my users see Synq’s name?
Your sign-in pages carry your brand. At launch, pages on Starter and Pro also show a small “Powered by Synq”, which Scale and Enterprise remove. With your own OAuth credentials, on Pro and up, Google and Apple show your company’s name on their consent screens instead of ours.
Can AI agents and CLIs sign in?
Yes. Agent and CLI apps sign people in with the device flow, and every token and audit record names both the person and the agent acting for them. MCP hosts can sign your users in without being registered first.
Where does Synq keep data?
In the United States: Synq’s servers and database run on DigitalOcean in New York. The subprocessors page lists every other service that handles data for Synq.

Ready for sign-in that feels like yours?

Tell us what you are building and which sign-in methods you need.