OAuth2 infrastructure guarded by design

Identity infrastructure for multi-tenant applications

Curupira helps teams manage tenants, applications, users, roles, API keys and audit trails through a secure admin dashboard built for modern SaaS platforms.

0
Tenants
0.0k
Active users
0.0M
Audit events / day
curupira · control planehealthy

248

Tenants

12.9k

Login attempts

1,043

API keys

Audit events

last 24h
tenant_createdacme-corp
api_key_regeneratedbilling-api
login_attempt_faileduser_8821
  • Multi-tenant ready
  • Full audit visibility
  • Standards-based OAuth2
  • Self-hosted or managed
  • Rust backend

From forest guardian to identity guardian

In Brazilian folklore, Curupira protects the forest and confuses invaders with misleading trails. In software infrastructure, Curupira protects identity flows, exposes suspicious activity and gives teams a clear audit trail.

Guardian

Protects tenants, applications and access boundaries with a single control plane.

Inverted trails

Every action is traceable through structured audit logs and event history.

Forest ecosystem

Tenants, apps, users and roles organized in one operational dashboard.

Authentication becomes operationally complex as your platform grows.

Fragmented access governance

As tenants and applications multiply, access spreads across teams with no single place to govern it.

Unreviewable permissions

Roles and groups drift across applications, leaving inconsistent access no one can easily review.

No evidence for audits

Without event and audit logs, teams can't prove what happened or investigate incidents.

Centralized access operations for modern teams

Manage identity resources, inspect activity and operate OAuth2 infrastructure from a single dashboard.

Clear operational boundaries

Isolate every tenant and its applications so access never crosses where it shouldn't.

acme-corpnorthwindglobex

Application & credential control

Govern redirect URIs and the API key lifecycle so credentials stay controlled, not scattered.

web-appmobile-apiinternal-tool

Reusable access models

Model roles per application and bundle them into role groups for consistent, repeatable access.

adminbillingviewer

Evidence for every change

Login attempts, event logs and audit trails give you proof and a fast path to investigate.

eventloginaudit

Everything your team needs to operate access

15 core capabilities

Create tenants with at least one application

List and inspect tenant details

Create, list, update and inspect applications

Manage redirect URIs

Regenerate API keys

List users

Inspect user details

Assign roles and groups to users

Create roles linked to applications

Create role groups

Manage member roles

Monitor login attempts

View event logs

View audit logs

Track dashboard stats and monitoring

Operate identity from a real admin dashboard

Every tenant, application, role and audit event in one control plane — with live system health and full traceability.

Overview

System health

Database: HealthyOAuth2 service: OperationalAudit logging: Active

Tenants

248+12

Applications

612+28

Users

18.4k+4.1%

Active sessions

1,204+62

Tenants & applications

4 of 248
TenantAppsUsersStatus
acme-corp84.2kactive
northwind41.1kactive
globex129.8kactive
initech2320provisioning

Activity monitoring

7d

Recent audit events

live
admin@curupira.iotenant_createdacme-corp
success12:04:18
admin@curupira.ioapplication_createdweb-app
success12:03:51
ops@acme.iorole_assignedfinance-api
success12:03:09
systemapi_key_regeneratedbilling-app
warning12:02:44
unknown-iplogin_attempt_failedtenant-admin
failed12:02:30
admin@curupira.ioredirect_uri_updatedweb-app
warning12:01:57
admin@curupira.iorole_group_createdplatform-admins
success12:01:12
security@acme.ioaudit_log_exportedtenant:acme-corp
success12:00:38
admin@curupira.iotenant_createdacme-corp
success12:04:18
admin@curupira.ioapplication_createdweb-app
success12:03:51
ops@acme.iorole_assignedfinance-api
success12:03:09
systemapi_key_regeneratedbilling-app
warning12:02:44
unknown-iplogin_attempt_failedtenant-admin
failed12:02:30
admin@curupira.ioredirect_uri_updatedweb-app
warning12:01:57
admin@curupira.iorole_group_createdplatform-admins
success12:01:12
security@acme.ioaudit_log_exportedtenant:acme-corp
success12:00:38

Login attempts

ops@acme.io

198.51.100.7

success

user_8821

203.0.113.42 · invalid_credentials

failed

admin@northwind

198.51.100.23

success

API key status

billing-apiregenerated
web-appactive
legacy-apirevoked

Built on a clear, observable architecture

Rust + Axum backend, SQLx persistence, PostgreSQL storage, Nuxt 3 admin dashboard and Docker-based deployment.

OAuth2 flow

Client Applications
Curupira OAuth2 Server
PostgreSQL

Admin operations

Admin Dashboard
Curupira API
Tenants / Apps / Users / Roles

Observability

Logs & Audit Events
Monitoring Dashboard
Investigation Trail
RustAxumSQLxPostgreSQLVue 3NuxtTypeScriptTailwind CSSDockerPlaywright
How it works

Every access request is authorized — and leaves evidence

Curupira sits in the path of every OAuth2 request: it authenticates the client, issues a scoped token, checks the caller's roles, and records an audit event — so each access operation is both authorized and traceable.

Client App

requests access

Curupira OAuth2 Server

authenticates

Token issued

scoped & signed

Role checked

least privilege

Audit event stored

evidence kept

Security & audit

Every action leaves a traceable footprint

From inverted trails to audit trails.

Curupira gives teams the visibility and structure to operate OAuth2 infrastructure with confidence — tenant isolation, role-based access, API key lifecycle and a complete, exportable audit trail behind every change.

Live audit trail

actor → action → target

streaming
successwarningfailed
admin@curupira.iotenant_createdacme-corp
success12:04:18
admin@curupira.ioapplication_createdweb-app
success12:03:51
ops@acme.iorole_assignedfinance-api
success12:03:09
systemapi_key_regeneratedbilling-app
warning12:02:44
unknown-iplogin_attempt_failedtenant-admin
failed12:02:30
admin@curupira.ioredirect_uri_updatedweb-app
warning12:01:57
admin@curupira.iorole_group_createdplatform-admins
success12:01:12
security@acme.ioaudit_log_exportedtenant:acme-corp
success12:00:38
admin@curupira.iotenant_createdacme-corp
success12:04:18
admin@curupira.ioapplication_createdweb-app
success12:03:51
ops@acme.iorole_assignedfinance-api
success12:03:09
systemapi_key_regeneratedbilling-app
warning12:02:44
unknown-iplogin_attempt_failedtenant-admin
failed12:02:30
admin@curupira.ioredirect_uri_updatedweb-app
warning12:01:57
admin@curupira.iorole_group_createdplatform-admins
success12:01:12
security@acme.ioaudit_log_exportedtenant:acme-corp
success12:00:38

Role-based access control

Grant least-privilege access per application and shrink the blast radius of any account.

Role group organization

Standardize access with reusable role groups instead of one-off, error-prone grants.

API key lifecycle

Issue, rotate and revoke application keys to keep credentials current and contained.

Login attempt monitoring

See successful, failed and blocked sign-ins to catch abuse early.

Event log visibility

Token issuance, grants and logouts in one stream for continuous oversight.

Audit trail traceability

Immutable actor → action → target records that keep you audit-ready.

Tenant & application isolation

Hard boundaries between tenants reduce cross-tenant exposure.

Operational investigation

Filter, drill down and export to resolve incidents and answer auditors fast.

Standards-based OAuth2 core

Scoped, signed tokens (JWT / JWKS) with refresh-token rotation — built on the OAuth2 spec, not a bespoke scheme.

Access lifecycle

Follow an access operation from request to evidence

Every operation a team performs in Curupira leaves a trail — from creating a tenant to exporting the audit log that proves what happened.

  1. Tenant created
  2. Application registered
  3. Role assigned
  4. Login monitored
  5. Audit stored
  6. Review evidence

Audit evidence

  • admin@curupira.io → tenant_created → acme-corp
  • admin@curupira.io → application_created → web-app
  • ops@acme.io → role_assigned → finance-api
  • unknown-ip → login_attempt_failed → tenant-admin
  • system → audit_event_written → audit_log
  • security@acme.io → audit_log_exported → tenant:acme-corp

Built for developers and platform teams

  • TypeScript-friendly dashboard
  • Rust backend
  • PostgreSQL persistence
  • Docker deployment
  • Integration and E2E tests
  • Clear operational boundaries

Stack

  • Rust
  • Axum
  • SQLx
  • PostgreSQL
  • Vue 3
  • Nuxt
  • TypeScript
  • Tailwind CSS
  • Docker
  • Playwright
curupira — bash
$docker compose up
✓ Curupira OAuth2 server running
✓ PostgreSQL connected
✓ Dashboard available
✓ Audit logs enabled
$

Connect identity operations across your platform

SaaS applications
Internal tools
Admin dashboards
APIs
PostgreSQL
Monitoring
CI/CD
Docker environments
SaaS applications
Internal tools
Admin dashboards
APIs
PostgreSQL
Monitoring
CI/CD
Docker environments
Enterprise onboarding

Enterprise onboarding for secure identity operations

Curupira is currently offered through a guided enterprise setup, designed for teams that need help structuring tenants, applications, roles, API keys and audit visibility from the beginning.

What's included

  • Initial architecture review
  • Tenant and application setup guidance
  • Role and role group modeling
  • Audit trail configuration
  • Self-hosted (Docker) or managed deployment guidance
  • Security and access review
  • Personalized onboarding support
Guided enterprise setup
Starting at€1,000+/ year

Custom enterprise plans available.

Final pricing may vary depending on scope, deployment and support needs.

Personalized onboarding — no self-service checkout.

Talk to our team

Book a demo or talk to our team

See Curupira applied to your tenants, applications and audit requirements. Book a 30-minute call, or send us the details and we'll get back to you.

Book a 30-min call

Opens our scheduling page in a new tab.

or send us the details

Deployment preference

This opens your email client with the details pre-filled — nothing is sent automatically.

Curupira

Guard your identity infrastructure with Curupira.

Bring structure, security and visibility to tenants, applications, roles and audit trails.