Integrations
No connector zoo
Automentic integrates through open identity standards rather than a catalogue of bespoke connectors. If your identity provider speaks OpenID Connect or SAML 2.0, and the system you want automated has an API, you already have what you need.
The integration surface
Four protocols, not four hundred connectors
A connector catalogue ages badly and quietly breaks. Standards do not. These four carry every integration Automentic makes.
OpenID Connect
Your identity provider stays the source of truth. Agents and their human approvers sign in against it, inheriting your groups and lifecycle rules.
SAML 2.0
For the estate that has not moved to OIDC yet. Federation with older enterprise directories and the systems bolted to them.
SPIFFE / SPIRE
Workload identity for the containers and services your agents actually run as, so identity survives autoscaling and redeploys.
X.509 and mutual TLS
The channel itself. Both ends authenticate, so a system can refuse anything that cannot present a certificate you issued.
Identity providers
Whatever you already run
Because federation happens at the protocol level, there is no per-vendor integration to wait for. Any provider that implements OpenID Connect or SAML 2.0 correctly can be your source of truth on day one — including the ones almost every enterprise already has.
Bring your provider to the demo and we will federate against it live.
Confirm before launch
These are named as examples of standards-compliant providers, not as certified or tested integrations. Before this page goes live, confirm which have actually been validated and reword any that have not.
- Okta and Auth0 — OIDC and SAML 2.0
- Microsoft Entra ID — OIDC, SAML 2.0, SCIM provisioning
- Ping Identity — OIDC and SAML 2.0
- Google Workspace — OIDC and SAML 2.0
- Keycloak and other self-hosted OIDC providers
- Active Directory Federation Services — SAML 2.0
What agents act on
If it has an API, it can be automated and proved
The agent authenticates to the target system with a certificate you issued, over mutual TLS. What it touches is your choice; what it leaves behind is always a signed record.
Finance and ERP
Invoice capture, three-way matching, approvals and postings — the workflows auditors ask about first.
CRM and revenue systems
Record hygiene, enrichment and reconciliation, with every write attributable to an agent and an authoriser.
ITSM and ticketing
Triage, enrichment and closure across service desks, without a shared service account doing the writing.
GRC and audit tooling
Control evidence pushed as it is produced, so a review reads a trail rather than a reconstruction.
SIEM and observability
The immutable audit trail streams into the tooling your security team already watches, in the format they expect.
Your own services
Anything behind an authenticated API. If it can require a client certificate, it can require one from an Automentic agent.
Bring your identity provider
The quickest way to settle an integration question is to federate against your own stack in the demo. Tell us what you run.