Canopy
Home Features Use Cases Pricing Documentation
Home Features Use Cases Documentation Sign In Get Started

Features

Everything Canopy provides to handle authentication, authorization, and organizational hierarchy as a service.

Hierarchical RBAC

Scope permissions by organizational structure with downward inheritance.

Dynamic Permissions

Define your own permission model. Canopy stores, enforces, and evaluates it at runtime.

Scoped Visibility

Users only see what they're allowed to, scoped automatically based on role assignments in the tree.

Multi-Tenant Isolation

Every account is fully isolated with its own hierarchy, roles, and permission catalog.

OAuth2 & OIDC

Hosted login with PKCE, RS256 JWTs, and JWKS. Your app never needs to handle passwords.

Identity Management

Manage end users, and their access, in one system.

API & Integrations

REST API, API keys, and webhooks: everything you need to integrate Canopy into your application.

Audit Logging

Every security-sensitive action is logged with actor, resource, and full context.

Canopy