Guardian
Protects tenants, applications and access boundaries with a single control plane.
Curupira helps teams manage tenants, applications, users, roles, API keys and audit trails through a secure admin dashboard built for modern SaaS platforms.
248
Tenants
12.9k
Login attempts
1,043
API keys
Audit events
last 24hIn Brazilian folklore, Curupira protects the forest and confuses invaders with misleading trails. In software infrastructure, Curupira protects identity flows, exposes suspicious activity and gives teams a clear audit trail.
Protects tenants, applications and access boundaries with a single control plane.
Every action is traceable through structured audit logs and event history.
Tenants, apps, users and roles organized in one operational dashboard.
As tenants and applications multiply, access spreads across teams with no single place to govern it.
Roles and groups drift across applications, leaving inconsistent access no one can easily review.
Without event and audit logs, teams can't prove what happened or investigate incidents.
Manage identity resources, inspect activity and operate OAuth2 infrastructure from a single dashboard.
Isolate every tenant and its applications so access never crosses where it shouldn't.
Govern redirect URIs and the API key lifecycle so credentials stay controlled, not scattered.
Model roles per application and bundle them into role groups for consistent, repeatable access.
Login attempts, event logs and audit trails give you proof and a fast path to investigate.
Create tenants with at least one application
List and inspect tenant details
Create, list, update and inspect applications
Manage redirect URIs
Regenerate API keys
List users
Inspect user details
Assign roles and groups to users
Create roles linked to applications
Create role groups
Manage member roles
Monitor login attempts
View event logs
View audit logs
Track dashboard stats and monitoring
Every tenant, application, role and audit event in one control plane — with live system health and full traceability.
Overview
Tenants
Applications
Users
Active sessions
Tenants & applications
4 of 248| Tenant | Apps | Users | Status |
|---|---|---|---|
| acme-corp | 8 | 4.2k | active |
| northwind | 4 | 1.1k | active |
| globex | 12 | 9.8k | active |
| initech | 2 | 320 | provisioning |
Activity monitoring
7dRecent audit events
liveLogin attempts
ops@acme.io
198.51.100.7
user_8821
203.0.113.42 · invalid_credentials
admin@northwind
198.51.100.23
API key status
Rust + Axum backend, SQLx persistence, PostgreSQL storage, Nuxt 3 admin dashboard and Docker-based deployment.
OAuth2 flow
Admin operations
Observability
Curupira sits in the path of every OAuth2 request: it authenticates the client, issues a scoped token, checks the caller's roles, and records an audit event — so each access operation is both authorized and traceable.
Client App
requests access
Curupira OAuth2 Server
authenticates
Token issued
scoped & signed
Role checked
least privilege
Audit event stored
evidence kept
From inverted trails to audit trails.
Curupira gives teams the visibility and structure to operate OAuth2 infrastructure with confidence — tenant isolation, role-based access, API key lifecycle and a complete, exportable audit trail behind every change.
Live audit trail
actor → action → target
Role-based access control
Grant least-privilege access per application and shrink the blast radius of any account.
Role group organization
Standardize access with reusable role groups instead of one-off, error-prone grants.
API key lifecycle
Issue, rotate and revoke application keys to keep credentials current and contained.
Login attempt monitoring
See successful, failed and blocked sign-ins to catch abuse early.
Event log visibility
Token issuance, grants and logouts in one stream for continuous oversight.
Audit trail traceability
Immutable actor → action → target records that keep you audit-ready.
Tenant & application isolation
Hard boundaries between tenants reduce cross-tenant exposure.
Operational investigation
Filter, drill down and export to resolve incidents and answer auditors fast.
Standards-based OAuth2 core
Scoped, signed tokens (JWT / JWKS) with refresh-token rotation — built on the OAuth2 spec, not a bespoke scheme.
Every operation a team performs in Curupira leaves a trail — from creating a tenant to exporting the audit log that proves what happened.
Audit evidence
Stack
Curupira is currently offered through a guided enterprise setup, designed for teams that need help structuring tenants, applications, roles, API keys and audit visibility from the beginning.
What's included
Custom enterprise plans available.
Final pricing may vary depending on scope, deployment and support needs.
Personalized onboarding — no self-service checkout.
See Curupira applied to your tenants, applications and audit requirements. Book a 30-minute call, or send us the details and we'll get back to you.
Opens our scheduling page in a new tab.

Bring structure, security and visibility to tenants, applications, roles and audit trails.