Early-stage · Built in Finland

Identity for your own software, without the enterprise baggage.

Amiri.fi gives developers and small teams one secure account system, optional two-factor, and short-lived tokens that every app, script and service can verify offline.

The problem

Every side project, internal tool and bot reinvents login — badly.

Small teams end up with hard-coded API keys, shared passwords and a different login for every tool. Enterprise identity platforms solve this, but they are expensive, complex and built for companies with a security department.

Scattered credentials

Long-lived keys copied into scripts and config files, never rotated, impossible to revoke cleanly.

Overpriced incumbents

Hosted identity providers price per active user and lock you into their cloud.

Weeks of plumbing

Hashing, sessions, 2FA and token signing done right takes time most builders don't have.

The product

One account. Every program. Secure by default.

A lightweight identity service you can run as a single binary-sized app with one database file — no external services required.

Modern login

Argon2id password hashing, server-side sessions and httpOnly cookies — current best practice out of the box.

Two-factor auth

TOTP 2FA with secrets encrypted at rest. Works with any authenticator app.

API keys → short-lived JWTs

Programs exchange a scoped API key for a 15-minute ES256 token. Leaked tokens expire on their own.

Offline verification

Any service verifies tokens against a public JWKS endpoint — no network call, no single point of failure.

Scopes & revocation

Fine-grained scopes per key and an introspection endpoint when you need instant revocation.

Self-hostable

Run it on your own server behind nginx, keeping user data in your own jurisdiction — GDPR-friendly by design.

How it works

From zero to authenticated in three steps.

  1. Sign in to your dashboardSecure account with optional 2FA.
  2. Create a scoped API keyOne per program, revocable at any time.
  3. Exchange it for a tokenYour program gets a short-lived JWT; services verify it offline.
# exchange an API key for a token
curl -X POST https://amiri.fi/api/v1/token \
  -H "Authorization: Bearer ak_..."

# → response
{
  "access_token": "eyJhbGciOiJFUzI1NiIs...",
  "expires_in": 900,
  "scope": "read:data"
}

# verify anywhere, offline
GET /.well-known/jwks.json
Where we are

Working product today. Platform tomorrow.

The core service is built and running. The startup program would help us turn it into a hosted product for developers and small teams.

LiveCore auth service
ES256Signed, offline-verifiable tokens
1 fileDatabase, zero external services
15 minToken lifetime by default
Now

Core service

Accounts, 2FA, sessions, API keys, JWT issuing and JWKS verification.

Next

Hosted & multi-tenant

Managed version with teams, organisations and self-serve onboarding.

Later

SDKs & SSO

Drop-in SDKs, passkeys and OAuth/OIDC so Amiri.fi becomes the login for everything you build.

Contact

Let's talk.

Interested in Amiri.fi, partnering, or trying the early version? Reach out directly.

hello@amiri.fi