{
 "categories": [
  "identity",
  "enterprise"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-09-28",
   "fact": "homepage",
   "note": "The public OneLogin hostname was requested. This pass received an empty access response and no product description. Identity below uses the developer documentation.",
   "source": "https://www.onelogin.com/",
   "tier": "declared"
  },
  {
   "date": "2026-09-28",
   "fact": "vendor",
   "note": "The developer overview is published as OneLogin API documentation. The page footer reads OneLogin, Inc., 2015-2026.",
   "source": "https://developers.onelogin.com/api-docs/2/getting-started/dev-overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-28",
   "fact": "status",
   "note": "The current developer docs present Version 2 of the OneLogin API and a free-trial link.",
   "source": "https://developers.onelogin.com/api-docs/2/getting-started/dev-overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-28",
   "fact": "deployment",
   "note": "The API host is the customer subdomain at <subdomain>.onelogin.com, which the page says is the same address used to log in to OneLogin.",
   "source": "https://developers.onelogin.com/api-docs/2/getting-started/dev-overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-28",
   "fact": "platforms",
   "note": "Administrators log in and call the API on the OneLogin web host. No desktop edition was described on the opened page.",
   "source": "https://developers.onelogin.com/api-docs/2/getting-started/dev-overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-28",
   "fact": "license",
   "note": "The developer site offers a free trial. The opened page does not describe a permanent free edition.",
   "source": "https://developers.onelogin.com/api-docs/2/getting-started/dev-overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-28",
   "fact": "modalities.api.exists",
   "note": "OneLogin documents a REST API that uses JSON, search, pagination, sorting, and filtering, secured by OAuth 2.0.",
   "source": "https://developers.onelogin.com/api-docs/2/getting-started/dev-overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-28",
   "fact": "modalities.api.kinds[0]",
   "note": "The overview says the API is based on RESTful principles and provides JSON messages.",
   "source": "https://developers.onelogin.com/api-docs/2/getting-started/dev-overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-28",
   "fact": "modalities.api.auth[0]",
   "note": "POST /auth/oauth2/v2/token with grant_type client_credentials returns an access token. The documented response token_type is bearer. The token lasts 10 hours.",
   "source": "https://developers.onelogin.com/api-docs/2/oauth20-tokens/generate-tokens-2/",
   "tier": "declared"
  },
  {
   "date": "2026-09-28",
   "fact": "modalities.api.coverage",
   "note": "The version 2 reference opened with the overview lists users, roles, groups, apps, MFA, events, and reports. Some calls can wait in a job queue for up to five minutes. Coverage of every admin screen is not stated.",
   "source": "https://developers.onelogin.com/api-docs/2/getting-started/dev-overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-28",
   "fact": "modalities.api.docs",
   "note": "Opened the OneLogin version 2 developer overview.",
   "source": "https://developers.onelogin.com/api-docs/2/getting-started/dev-overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-28",
   "fact": "modalities.sdk.exists",
   "note": "OneLogin documents client SDKs and says it officially supports a listed set of languages.",
   "source": "https://developers.onelogin.com/api-docs/2/getting-started/client-sdks",
   "tier": "declared"
  },
  {
   "date": "2026-09-28",
   "fact": "modalities.sdk.official",
   "note": "The page says OneLogin officially supports the listed language SDKs and treats other clients as third party.",
   "source": "https://developers.onelogin.com/api-docs/2/getting-started/client-sdks",
   "tier": "declared"
  },
  {
   "date": "2026-09-28",
   "fact": "modalities.sdk.languages",
   "note": "The official list is OneLogin for Java, Ruby, Python, and PHP.",
   "source": "https://developers.onelogin.com/api-docs/2/getting-started/client-sdks",
   "tier": "declared"
  },
  {
   "date": "2026-09-28",
   "fact": "modalities.mcp.first_party",
   "note": "The OneLogin GitHub organization publishes onelogin-mcp and the npm package @onelogin/onelogin-mcp. The README links the OneLogin API documentation.",
   "source": "https://github.com/onelogin/onelogin-mcp",
   "tier": "declared"
  },
  {
   "date": "2026-09-28",
   "fact": "modalities.mcp.verdict",
   "note": "The README describes a local stdio server configured with ONELOGIN_URL plus an OAuth2 client id and secret. It says the server provides 156 tools.",
   "source": "https://github.com/onelogin/onelogin-mcp",
   "tier": "declared"
  },
  {
   "date": "2026-09-28",
   "fact": "modalities.data_access.export[0]",
   "note": "The API provides JSON messages.",
   "source": "https://developers.onelogin.com/api-docs/2/getting-started/dev-overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-28",
   "fact": "modalities.rpa.drivability",
   "note": "The marketing homepage did not render a usable console on this pass, and no UI probe was run.",
   "source": "https://www.onelogin.com/",
   "tier": "declared"
  },
  {
   "date": "2026-09-28",
   "fact": "modalities.agent_docs.llms_txt",
   "note": "https://developers.onelogin.com/llms.txt returned 404. https://www.onelogin.com/llms.txt did not return a document. An llms.txt guide is not established.",
   "source": "https://developers.onelogin.com/llms.txt",
   "tier": "declared"
  },
  {
   "date": "2026-09-28",
   "fact": "verdict.scores.api",
   "note": "The version 2 API is a documented JSON admin API with client-credentials tokens that last 10 hours and are bound to the creating user. Score 7.",
   "source": "https://developers.onelogin.com/api-docs/2/oauth20-tokens/generate-tokens-2/",
   "tier": "declared"
  },
  {
   "date": "2026-09-28",
   "fact": "verdict.scores.mcp",
   "note": "The official MCP server is maintained and broad, and it runs only as a local process with client credentials. Score 7.",
   "source": "https://github.com/onelogin/onelogin-mcp",
   "tier": "declared"
  },
  {
   "date": "2026-09-28",
   "fact": "freshness.watch[0].url",
   "note": "Opened the OneLogin version 2 developer overview.",
   "source": "https://developers.onelogin.com/api-docs/2/getting-started/dev-overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-28",
   "fact": "freshness.watch[1].url",
   "note": "Opened the Generate Tokens page, including client credentials and the 10-hour access token.",
   "source": "https://developers.onelogin.com/api-docs/2/oauth20-tokens/generate-tokens-2/",
   "tier": "declared"
  },
  {
   "date": "2026-09-28",
   "fact": "freshness.watch[2].url",
   "note": "Opened the OneLogin MCP README, including install, credentials, and the tool inventory.",
   "source": "https://github.com/onelogin/onelogin-mcp",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-09-28",
  "volatility": "medium",
  "watch": [
   {
    "type": "docs",
    "url": "https://developers.onelogin.com/api-docs/2/getting-started/dev-overview"
   },
   {
    "type": "docs",
    "url": "https://developers.onelogin.com/api-docs/2/oauth20-tokens/generate-tokens-2/"
   },
   {
    "type": "docs",
    "url": "https://github.com/onelogin/onelogin-mcp"
   }
  ]
 },
 "homepage": "https://www.onelogin.com/",
 "id": "onelogin",
 "license": "commercial",
 "modalities": {
  "agent_docs": {
   "llms_txt": "unknown"
  },
  "api": {
   "auth": [
    "oauth2-client-credentials"
   ],
   "coverage": "partial",
   "docs": "https://developers.onelogin.com/api-docs/2/getting-started/dev-overview",
   "exists": true,
   "kinds": [
    "rest"
   ]
  },
  "cli": {
   "exists": "unknown"
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "json"
   ],
   "import": []
  },
  "extensibility": {
   "scripting": [],
   "webhooks": "unknown"
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": true,
   "third_party": [],
   "verdict": "official"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. The public marketing homepage did not return product content on this pass. The resource API and the local MCP server cover user, app, and MFA administration without a measured browser path.\n",
   "ui_stack": [],
   "vendor_support": []
  },
  "sdk": {
   "exists": true,
   "languages": [
    "java",
    "ruby",
    "python",
    "php"
   ],
   "official": true
  }
 },
 "name": "OneLogin",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "okta",
   "auth0",
   "jumpcloud",
   "microsoft-entra-id"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "OneLogin",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 7,
   "cli": null,
   "computer_use": null,
   "integrations": null,
   "mcp": 7,
   "overall": 7,
   "rpa": null
  },
  "summary": "OneLogin is automatable today through its resource API. This record is OneLogin workforce identity administration. Okta, Auth0, and JumpCloud are separate products. The marketing site https://www.onelogin.com/ did not return product content on this pass, so product facts here come from the OneLogin developer docs and the OneLogin GitHub organization. The API is JSON over HTTPS on https://<subdomain>.onelogin.com, which is also the login host. Version 2 is the current generation named in the docs. A client id and client secret obtain an access token from /auth/oauth2/v2/token with grant_type client_credentials. The token response uses token_type bearer. OneLogin says the access token lasts 10 hours and that the same client pair returns the same token set until it expires or is revoked. Credentials are tied to the user who created them. Deleting that user makes those credentials fail. The opened reference lists users, roles, groups, apps, MFA, events, and reports. Official SDKs are Java, Ruby, Python, and PHP. The OneLogin organization publishes @onelogin/onelogin-mcp. It runs locally over stdio with ONELOGIN_URL, ONELOGIN_CLIENT_ID, and ONELOGIN_CLIENT_SECRET. The README says it provides 156 tools for users, roles, apps, MFA, sessions, and related admin APIs. It is not a hosted URL. A product CLI, webhook catalog, and connector catalogs were not established. https://developers.onelogin.com/llms.txt returned 404, and the marketing llms.txt URL did not return a document, so an llms.txt guide is not established. Computer-use viability is unassessed. The API and the local MCP both score 7. The API is the best path because it does not require the local MCP process.\n"
 }
}