Dinesh Jinjala

04A multi-tenant Pharma Manufacturing Analytics SaaS

Multi-Tenant SSO & Identity

Lead developer

I rebuilt the platform's sign-in as one multi-tenant service. Each client signs in its own way (OIDC, SAML 2.0, LDAP or password), and every path ends in the same audited session. It handles GxP e-signature re-authentication and single sign-on into connected analytics tools. I also built a SAML identity provider with passkey sign-in.

2.65 s → 0.44 s
password sign-in, ~6× faster
4
sign-in methods, chosen per client
Passkeys
in the SAML identity provider

Python / FastAPI / SAML 2.0 / OIDC / WebAuthn

Problem

The platform serves 10+ enterprise pharma clients, and each one signs in differently. One service had to support all of them, keep every client separate, and meet GxP rules for electronic signatures.

Approach

  • I rebuilt authentication as a multi-tenant service: every request is resolved to its client, and each client is isolated.
  • Each client chooses OIDC, SAML 2.0, LDAP or password, and every method ends in the same token, session and audit steps.
  • Every e-signature asks the user to sign in again, as GxP rules require.
  • Connected analytics tools trust platform sign-in, so users log in once.
  • I built a SAML 2.0 identity provider with passkey sign-in, so the platform can be the identity source for other applications.

Architecture

  1. Client request
  2. Tenant resolver
  3. OIDC / SAML / LDAP / password
  4. E-signature re-auth
  5. Token issuer
  6. Connected apps

Outcome

Every client signs in its own way through one service with one audit trail. I cut password sign-in from 2.65 s to 0.44 s by re-tuning the hashing for the production environment, without weakening it.

What I learnedMeasure security costs where the code actually runs.

Building something like this?

Tell me about it