Product
Single sign-on for your MSP team
Your technicians sign in to KairosLink with your company identity, with no extra password to remember. Single sign-on runs on OpenID Connect: when someone leaves the MSP and their account is switched off at the identity provider, they stop getting into the panel at that same moment.
Three providers, with no URLs to paste by hand
The providers with automatic discovery are Microsoft Entra ID, Okta and Google Workspace. The form asks only for the part that varies (the tenant identifier on Entra, the domain on Okta) and builds the discovery URL itself. With Google it asks for nothing, because its URL is always the same. Nobody has to edit the middle of a long URL inside a narrow field.
The domain is proven in DNS, and proven again
To enable a domain you have to prove it is yours: you publish a TXT record in DNS and KairosLink verifies it. That proof does not last forever. Every 7 days the record is checked again, and if it is gone, the domain stops allowing sign-ins. A domain that gets sold or a customer that leaves lose access without anyone having to remember to revoke it.
Public email domains can never be claimed. Claiming a domain means taking every sign-in on that domain: if someone claimed gmail.com, they would pull any Gmail user on the platform toward their own identity provider.
Your provider knowing them does not open the door
The identity provider proves who a person is. It does not prove that this person should see the panel that remotely controls every one of your customers' fleets. That second decision is a human one: every new federated access lands in a queue and is approved by someone with the user management permission.
A rejection made by mistake can be undone, because recent rejections stay within reach on the same screen. The menu carries the count of pending requests, so nobody is left waiting for someone to remember to look.
The second factor is read from the token, not assumed
KairosLink reads from the token what the person did to authenticate, and only a closed list of methods counts as a second factor: authenticator app, hardware key, biometrics, SMS and each provider's own variants. A password alone does not count, however proudly the provider reports it.
Accepted signatures are asymmetric only: RS256, RS384, RS512, ES256 and ES384. An unsigned token or a symmetric algorithm is never accepted, and those are the two classic ways to forge a JWT.
Frequently asked questions
What protocol does single sign-on use?
How do I prove the domain is mine?
Can I use a Gmail or Outlook account?
If someone signs in with the identity provider, are they already inside the panel?
Does KairosLink honor my provider's second factor?
What happens if the identity provider goes down?
All modules included. No credit card.