A Unified Authentication and Authorization Platform for Multi-Product SaaS: Design, Implementation, and Evaluation

Main Article Content

Kalyan Inturi

Abstract

The fast practice of SaaS organizations by acquiring companies is causing significant issues of identity fragmentation in authentication flows and user management interfaces. Although this problem is common, there is limited documentation on methodologies of multi-product identity unification. This paper introduces a single authentication and authorization hub that aims at overcoming these issues in acquisitive SaaS systems. It uses the architecture based on a standards-based framework that includes an OIDC service, token-time claim enrichment, central identity storage, and an event-driven replication layer. The solution shows a great pace in integration cycles, a high level of economy due to the use of previous parts, a high level of security due to regular deprovisioning, and a high level of stability during migrations. Although the implementation yields concrete benefits, it also manages to circumvent a number of constraints, such as the vendor coupling risks, past integration challenges, and authorisation model limitations. The reported platform is a viable roadmap to SaaS entities aiming to integrate identity infrastructure among the purchased products without compromising security and operational quality.

Article Details

Section
Articles