Experimental MVP — Not for production use
EU-Sovereign Identity

Passwordless identity
for the modern workforce

Totem ID is an open-source identity provider built for European organizations. Passkey-first authentication, SSO, provisioning, and lifecycle management — without passwords, without vendor lock-in.

Vibe-Coded MVP — Do Not Use in Production

Totem ID is an experimental project built as a proof of concept. The entire codebase was vibe coded — written collaboratively with AI in rapid prototyping sessions. It has not been audited, makes no security guarantees, and should never be used to protect real user accounts or sensitive data. Treat this as a tech demo and learning exercise, not a production-ready identity provider.

What's inside

A full-featured IdP stack, built from scratch

Passkey-First Auth

WebAuthn passkeys as the primary credential. Magic links as fallback. No passwords stored, ever.

SAML & OIDC SSO

Full identity provider for both SAML 2.0 and OpenID Connect. Federate with any SP out of the box.

SCIM Provisioning

Automated user and group sync via SCIM 2.0. Connect to HR systems and directories for JML flows.

Conditional Access

Policy engine for location, device, time, and risk-based access rules. Block or require step-up per app.

Lifecycle Workflows

Visual workflow engine for joiners, movers, and leavers. Auto-provision on hire, deprovision on exit.

Access Graph

Visualize who has access to what. Blast radius analysis, delegation chains, and group dependency maps.

Built with
Fastify React Drizzle ORM PostgreSQL Redis WebAuthn TypeScript Tailwind CSS