Modes
The Orchestrator operates in five modes, each addressing a different identity protocol or deployment pattern.
Modes can run simultaneously on a single Orchestrator instance — deploy one binary that handles OIDC, SAML, and LDAP at the same time.
Interfaces
Two interfaces configure the same Orchestrator — choose the one that fits your workflow.
Both interfaces configure the same underlying Orchestrator — changes made in one are reflected in the other.
Deployment Models
The Orchestrator is designed to run wherever your applications run. Three deployment models cover the most common environments:- Cloud — Orchestrator runs in cloud infrastructure (AWS, Azure, GCP) alongside cloud-native applications. Ideal for teams with fully cloud-based identity stacks.
- On-premises — Orchestrator runs in data centers alongside legacy applications. Critical for enterprises with mainframe, LDAP, or on-prem web applications that cannot migrate to the cloud.
- Hybrid — A mix of cloud and on-premises Orchestrators managed from a single Console. This is the most common model for enterprises modernizing incrementally.
What’s Next
Getting Started
Deploy your first Orchestrator and route an authentication request in minutes.
Modes Reference
Detailed reference documentation for each Orchestrator mode.