oauth.work handles who gets in and what they can do: single sign-on for your users, enterprise SSO and SCIM directory sync for your customers' IT teams, passkeys instead of passwords, RBAC and audit logs for their security reviewers, and scoped, revocable authorization for the AI agents acting on everyone's behalf.
We built it because agent access was being improvised — API keys shared between services, no consent step, no record of who did what. Meanwhile the teams selling to enterprises were paying per SSO connection for table stakes. Both were fixable, so we fixed them.
On Cloudflare's global network, so sign-ins happen close to your users wherever they are. The docs cover how it all fits together.