Where Authcha fits.
Three networks we built Authcha for. Most customers start with one of these and grow into the others.
Jump to: ISPs and telcos, Enterprise campus, Government and PSU
ISPs and telcos
Admin access to thousands of routers and switches, from many vendors, by a NOC that works in shifts.
Network operations teams at ISPs, telcos and data-centre operators.
The problem
- Shared local accounts on core and aggregation gear, with no second factor.
- A mixed fleet: some devices handle RADIUS challenges, some don't.
- NOC shifts need read-only access; a few senior engineers need full access; scripts need their own accounts.
- When something breaks at 3 a.m., nobody can say who logged in to what.
How Authcha handles it
- Every device login needs a password and a one-time code on WhatsApp, Telegram, SMS or email.
- Challenge, phrase-OTP or password-only is chosen per device, group or vendor, so older boxes stay reachable without lowering the bar for everything else.
- Read-write, read-only, automation and looking-glass roles map to each vendor's privilege attributes, and each role is accepted only from its own jump servers.
- Live auth, OTP event history and the audit trail answer who, what, where and when.
Features involved
Enterprise campus
Laptops, phones, printers, cameras and visitors on one network, each in the right VLAN.
IT and network teams running offices, campuses, hospitals and factories.
The problem
- Anything plugged into a wall port gets on the network.
- IP phones, printers and cameras can't run 802.1X.
- Guest Wi-Fi runs on a shared password that everybody knows.
- RADIUS, NAC and posture come from three vendors, with three consoles and three user stores.
How Authcha handles it
- Laptops authenticate with 802.1X (EAP-TTLS) against the same user store as your engineers, or sync it from LDAP or FreeIPA.
- Devices without a supplicant are allowed by MAC and placed by device class: VLAN, QoS, bandwidth, session timeout and quota.
- DHCP fingerprint rules suggest a class for unknown devices; an operator confirms.
- Reception issues guest vouchers, an admin approves, and guests redeem on the captive portal.
- Admins sign in with your identity provider over OIDC.
Features involved
Government and PSU
On-premises, air-gap friendly and ready for an audit.
Ministries, public-sector undertakings, utilities and other regulated operators.
The problem
- Cloud-hosted identity services aren't allowed, and many management networks have no internet access.
- Log retention rules, such as CERT-In's 180 days, have to be met and demonstrated.
- Auditors ask for proof that backups can actually be restored.
- A lapsed support contract must never lock engineers out of the network.
How Authcha handles it
- Single-tenant and on-premises: your hardware, your database, nothing shared.
- The license is a signed file checked offline. No license server, no telemetry.
- Audit retention defaults to 180 days and can be set to your own rule, or to keep everything.
- A weekly restore drill records a pass or fail for each backup.
- License expiry pauses new provisioning only; authentication keeps working.
- TOTP for every admin, separation of duties for guest access, and posture checks that quarantine non-compliant laptops.
Features involved
Log in to a working Authcha instance.
The public sandbox has sample devices, users, vouchers and live auth traffic. Use it as an admin, a read-only NOC engineer or a front-desk sponsor.