Skip to content

Curity

API-driven identity server providing OAuth/OIDC token issuance and fine-grained API security for organizations that need to secure machine-to-machine and mobile/API traffic at scale.

Visit Website ↗ + Add to Compare
50/100Incremental Innovator

Overview

Curity was founded in Stockholm in 2015 with a specific focus: rather than building a general-purpose identity provider, the Curity Identity Server is designed around securing APIs — issuing and validating OAuth2/OIDC tokens, enforcing fine-grained scopes, and integrating tightly with API gateways. This makes it a common choice for banks, telecoms, and other organizations with heavy API traffic and regulatory requirements (such as European PSD2/open banking mandates) around token-based access control.

The company has been quietly funded, with a Series A from Fairpoint Capital in 2019 and additional backing from GRO Capital in 2023, and operates with a relatively small team of around 50 employees, reflecting a profitable, deliberately-paced growth model rather than a venture-fueled land grab.

Curity’s differentiation from broader IAM platforms like Okta or Ping Identity is depth over breadth: it is purpose-built for API and token security rather than covering the full range of workforce SSO, HR-driven provisioning, and consumer identity use cases.

Innovation Matrix Assessment

Innovation Velocity 5/10

A small, steady engineering team has maintained the identity server with regular OAuth/OIDC standards updates, but the company does not show the rapid feature cadence of venture-scaled competitors.

Operational Value 6/10

Specialized OAuth/OIDC token handling reduces the risk of misconfigured API authorization for organizations with heavy machine-to-machine and open-banking traffic.

Market Momentum 4/10

Modest, infrequent funding rounds and limited public market visibility suggest steady but unspectacular commercial momentum relative to category leaders.

Category Disruption 3/10

Implements established OAuth2/OIDC standards well rather than introducing a new identity model.

Real-World Efficacy 6/10

A decade of production deployment in regulated banking and telecom environments, which have stringent audit requirements, is a reasonable real-world efficacy signal even without public breach data.

Enduring Relevance 6/10

API and machine-to-machine token security remains persistently important as API traffic grows and regulatory mandates around open banking and data access expand.

Why CISOs Should Care

For organizations with regulatory obligations around API and open-banking access (particularly in the EU), Curity provides a focused, standards-compliant OAuth/OIDC layer that is easier to audit for token-issuance correctness than adapting a general-purpose IAM suite.

What Makes It Different

Curity is purpose-built around API and token security specifically, rather than being a general workforce or customer identity platform that happens to support OAuth as one of many features.

The Matrix Verdict

50/100 — INCREMENTAL INNOVATOR

A durable, profitably-run identity server vendor with real depth in API/token security and a customer base concentrated in regulated industries, but limited market visibility and disruption relative to broader IAM platforms. A steady Incremental Innovator.

Editorial Note: Claims vs. Verified Findings

Founding, funding, and employee-count figures are drawn from Curity's own company page and third-party aggregator profiles (Tracxn, CB Insights); customer names and deployment scale were not independently verified.

Sources