The open platform for high-assurance credential management.
MyID CMS is the open platform for PKI and credential management - built on open standards and open APIs (REST, SCEP, OAuth2 / OIDC, FIDO2 and LDAP) so you can issue and manage high-assurance PKI credentials across a broad range of supported certificate authorities, HSMs, directories, smart cards, tokens and card printers. Best-of-breed, not locked in. Available in Enterprise and FIPS 201 / PIV editions.

Supported CA connectors
DigiCert ONE
REST connector for DigiCert ONE via DigiCert Trust Lifecycle Manager: certificate issuance and full lifecycle
Entrust CA Gateway
Entrust issuance via the CA Gateway REST interface. Multiple simultaneous Entrust authorities
Entrust JASTK
Entrust CA integration via the JASTK toolkit for established Entrust PKI estates.
Microsoft ADCS
Microsoft Windows CA (Active Directory Certificate Services) with certificate templates, key archival and recovery, and multiple-forest support.
PrimeKey EJBCA
EJBCA Enterprise integration over secure web services, tested with EJBCA 9.4.2.
Post-Quantum Cryptography
MyID CMS has been tested with the ML-DSA and ML-KEM post-quantum algorithms via PrimeKey EJBCA (9.4 or later). Currently software certificates only, issued through the MyID Operator Client.
Custom / other CA
Custom CA connectors for bespoke environments (managed in MyID as a Generic CA), plus SCEP enrolment. Talk to us about additional CAs.
Supported HSMs
Entrust nShield
nShield Connect and nShield Solo for key generation and cryptographic operations. Supports FIPS 140-2 Level 3 and FIPS 140-3 modes.
Thales Luna
Luna Network HSM (A- and S-Series), Luna Cloud HSM (DPoD) and Thales TCT Luna T-Series.
Directories & Identity Providers
Microsoft Active Directory
The core identity source for most deployments. Reads user and group attributes and writes certificate and smart-card logon data back to AD. Multi-forest and multi-domain.
Microsoft Entra ID
Entra ID as directory, identity provider and FIDO2 passkey server: passkey issuance and synchronisation, plus certificate synchronisation.
LDAP
Integrate LDAPv3-compliant directories alongside or instead of Active Directory. Additional configuration applies for non-AD directories.
Federated sign-in
Operator and self-service sign-in via OAuth2 / OpenID Connect and AD FS. Documented IdPs include Entra ID and Okta.
Smart Cards & USB Tokens
Yubico / YubiKey
PKI (PIV applet) and FIDO2 on a single key. YubiKey 5 series including v5.7 FIPS; multiple form factors.
IDEMIA
IDEMIA smart cards - PIV and enterprise profiles with RSA / ECC keys and minidriver support.
Thales / SafeNet
SafeNet eToken family, including eToken 5300 and eToken Fusion NFC PIV, via SafeNet Authentication Client.
Thales TCT
Thales Trusted Cyber Technologies smart cards for US federal supply-chain requirements.
Swissbit
Swissbit iShield Key 2 Pro tokens (including FIPS and MIFARE variants): PKI and FIDO2 credential lifecycle.
Giesecke+Devrient
G+D smart cards for PIV and enterprise credential profiles.
Athena
Athena smart cards with minidriver and interoperability support.
Egofy
Egofy smart cards, including FIDO and v3.0 card support.
Microsoft Virtual Smart Cards
TPM-backed virtual smart cards - high-assurance credentials with no physical token.
Windows Hello for Business
Manage Windows Hello for Business credentials through MyID.
FIDO2 Passkeys
FIDO2 / WebAuthn passkeys with enterprise attestation, including Entra passkey import.
Card Printers
Entrust / Datacard
XPS card printers - Datacard SD and CD series, CE840, CR805 retransfer, CL900 laser and Entrust Sigma DS1/DS2/DS3.
HID Fargo
Direct-to-card DTC4500e and high-definition HDP5000 and HDP6600.
Matica / EDIsecure
EDIsecure XID series (XID 8300 / 8100 / 8600), EXPRESSO, MOCA S3100 and MC series retransfer printers.
IDP
IDP Smart-51 and Smart-81 card printers.
Card readers & contactless
PC/SC-compatible readers; contactless support for ISO 14443 A/B and ISO 15693. Tested over local USB to confirm contactless readers with Intercede.
APIs & Programmatic Integration
MyID Core API
Primary REST API for issuance, lifecycle and integration with HR, IGA and ITSM platforms.
OAuth2 / OpenID Connect
Standards-based authentication for API and client access.
SCEP
SCEP enrolment for certificate issuance, with the REST-based MyID Core API for programmatic device operations.
Notifications Listener API
Issuer status callbacks for derived-credential workflows.
Common questions
Everything you need to know. Can't find the answer? Contact our team →
Yes. Active Directory is the core identity source, MyID reads user attributes and group membership, writes certificate and smart-card logon data back to AD, and enforces group-based credential policy across multi-forest and multi-domain environments. Entra ID is supported as a directory, identity provider and FIDO2 passkey server, and generic LDAP v3 directories are also supported.
MyID CMS has supported connectors for DigiCert ONE, Entrust (CA Gateway and JASTK), Microsoft Windows CA (ADCS) and PrimeKey EJBCA, and can drive multiple CAs from a single instance. A generic CA connector and SCEP cover bespoke environments, and further CAs are available on request. Older connectors (Entrust via the Administration Toolkit for C, Symantec/DigiCert MPKI and UniCERT) reached end of sale at MyID CMS 2026.1: they cannot be added to new installations, though customers upgrading existing systems can continue to use them
Yes. MyID CMS 2026.1 has been tested with the ML-DSA and ML-KEM post-quantum algorithms through the PrimeKey EJBCA certificate authority (version 9.4 or later). Support currently covers software certificates only: ML-DSA keys can be issued to a software local store or as a .pfx file, and ML-KEM keys as a .pfx file, through the MyID Operator Client. Issuance to smart cards, tokens or mobile devices is not currently supported, and client PCs require Windows 11 24H2 with the post-quantum cryptography updates.
MyID CMS supports Entrust nShield (Connect and Solo) and Thales Luna HSMs, including Luna Cloud HSM (DPoD) and Thales TCT Luna T-Series, running in FIPS 140-2 Level 3 mode or FIPS 140-3 provisional mode.
MyID issues credentials to smart cards and USB tokens from Yubico, IDEMIA, Thales / SafeNet, Thales TCT, Swissbit, Giesecke+Devrient, Athena and Egofy, plus Microsoft virtual smart cards, Windows Hello for Business and FIDO2 passkeys. Tested card printer families include Entrust / Datacard, HID Fargo, Matica / EDIsecure and IDP. Contact us to confirm specific models for your environment.