DigitID
DigitID is a secure, developer ready identity and authorization platform for applications, APIs, services, and workloads. It combines federated application identity with SPIFFE and SPIRE workload identity to cover non human identity management end to end, providing authentication, workload attestation, short lived credentials, federation, and consistent authorization patterns across Kubernetes and cloud environments.
DigitID standardizes application and workload identity using managed Keycloak and SPIFFE SPIRE capabilities, including OIDC, OAuth 2.0, SAML federation, application identities, workload attestation, SPIFFE IDs, X.509 and JWT SVIDs, trust domain federation, and identity federation across clusters. It brings human facing application identity and non human workload identity under one identity API and declarative onboarding model, integrating with API gateways, Kubernetes, Cilium, applications, and policy enforcement points for authorization.
The operating challenge
Application and workload identity becomes fragmented when OAuth clients, service accounts, Kubernetes identities, machine credentials, workload authentication, authorization policies, and cross-environment trust are implemented independently by individual teams.
What the product provides
DigitID runs Keycloak and SPIFFE SPIRE as managed services underneath a single identity API, so application identity, meaning users and OAuth clients and SAML federation, and workload identity, meaning SPIFFE IDs and SVIDs and attestation, are provisioned and rotated the same way instead of as two disconnected systems.
How teams consume DigitID
Teams request application or workload identities through platform APIs or declarative Kubernetes resources, without touching Keycloak or SPIRE directly. DigitID handles credential issuance, rotation, federation, and the wiring into gateway and policy enforcement points.
How adoption starts
Start with representative applications and Kubernetes workloads, establish identity naming and SPIFFE trust-domain standards, onboard OIDC clients and workload identities, integrate authorization enforcement, and expand federation across clusters and environments incrementally.
Who it is for
Platform and security teams that need reusable workload, service, or application identity patterns across distributed systems and platform environments.
When not to use it
When the requirement is limited to straightforward end-user authentication already handled effectively by an existing identity provider.