Black Hat 2026: Book a meeting and enter to win $1k for a Kid's Team, Club, or Program.
Synqly connects your product to the leading identity providers through a single API so you can read user and group data, search audit logs, disable accounts, and expire sessions, regardless of which IdP a customer runs.
Identity is the thread that connects every security incident to a human or a system account. Knowing that an alert fired is far less useful than knowing which user triggered it, what groups they belong to, what their access history looks like, and whether their session is still active.
Synqly’s Identity connector gives your product normalized, bi-directional access to the identity providers your customers use. Read user records, group memberships, and audit logs with a consistent query model. Disable accounts and expire sessions through a unified action API. Attach raw provider events for compliance when customers need the original data, without building separate integrations for each IdP.
Run a single audit log search across Okta, Microsoft Entra ID, Google Workspace, and other connected IdPs to reconstruct what a user did and when, without switching between provider consoles.
When your product detects a compromised account, immediately disable it and expire active sessions across connected identity providers through a single action, regardless of which IdP the customer uses.
Pull current user and group membership data from IdPs on demand to support access review workflows, privilege audits, and least-privilege enforcement.
Overlay user and entitlement context onto security alerts so analysts see who triggered a detection, their role, their group memberships, and their recent activity, all in one place.
Disables a user in the identity system based on user ID.
Reenables a disabled user in the identity system based on user ID.
Logs a user out of all current sessions so they must log in again.
Forces a user to reset their password before they can log in again.
Returns a `Group` object wrapped in an OCSF Entity Management event of type Read from the token-linked identity provider. Depending on the providers offerings, this may include additional group information, such as the roles assigned.
Returns list of `User` objects wrapped in an OCSF Entity Management event of type Read from the token-linked identity provider that are members in the group referenced by ID.
Returns a `User` object wrapped in an OCSF Entity Management event of type Read from the token-linked identity provider. Depending
on the providers offerings, this may include additional user information, such as the user\\\\\\\'s current groups and roles.
Returns the profile picture for a user as binary image data. The Content-Type header indicates the image format (e.g., image/jpeg, image/png).
Returns a list of `Event` objects from the token-linked audit log.
Returns a list of `Group` objects wrapped in the OCSF Entity Management event of type Read from the token-linked identity provider.
Returns identity threat / risk events (for example Microsoft Entra Identity Protection risk detections for users), normalized to OCSF.
Returns rolled-up risky user records (for example Microsoft Entra Identity Protection riskyUsers), each normalized to an OCSF Entity Management Read event.
Returns a list of `User` objects wrapped in the OCSF Entity Management event of type Read from the token-linked identity provider.
Mesh Integration Platform
Unified API platform delivering native integrations for security and IT ops vendors
Embedded for Secure Environments
Enable secure OEM integrations in secure and regulated environments
Bridge for Private Networks
Enable cybersecurity integrations inside private networks and cloud.
Model Context Protocol
Give AI seamless access to the largest ecosystem of security and IT ops providers
[BETA] Synqly Mesh for Enterprise
The assistant your security engineers need.