---
title: "LASSX authentication"
description: "This public website has no OAuth or public API. Production LASSX uses the customer IdP (SSO/SAML) on hardware they host."
canonical: https://lassx.io/auth.md
last-updated: 2026-08-23
---

# Authentication

## Public website (this host)

The marketing site and labeled demo are **zero-auth** for browsing. There is **no public REST API**, OAuth authorization server, or MCP server on lassx.io / lassx.grok.me.

Agents should **not** look for:

- `/.well-known/oauth-authorization-server`
- `/.well-known/oauth-protected-resource`
- `/api` bearer tokens

Use documentation instead: [/llms.txt](https://lassx.io/llms.txt), [/docs](https://lassx.io/docs).

The interactive demo (`/demo/ask`) is a product preview with sample data. Do not upload real CUI.

## Production appliance (customer-hosted)

Production LASSX authenticates people against **the customer's identity provider** (SSO / SAML) with org and workspace RBAC. That IdP lives on the customer's network. It is not a LASSX multi-tenant login on this domain.

Pilot and procurement: [sales@lassx.io](mailto:sales@lassx.io)

- Identity guide: https://lassx.io/product/identity-sso-rbac
