Skip to main content
Home > MyID Product Family > Integrations

The open platform for high-assurance credential management.

MyID CMS is the open platform for PKI and credential management - built on open standards and open APIs (REST, SCEP, OAuth2 / OIDC, FIDO2 and LDAP) so you can issue and manage high-assurance PKI credentials across a broad range of supported certificate authorities, HSMs, directories, smart cards, tokens and card printers. Best-of-breed, not locked in. Available in Enterprise and FIPS 201 / PIV editions.

Certificate Authorities

Supported CA connectors

Certificate Authority

DigiCert ONE

REST connector for DigiCert ONE via DigiCert Trust Lifecycle Manager: certificate issuance and full lifecycle

Certificate Authority

Entrust CA Gateway

Entrust issuance via the CA Gateway REST interface. Multiple simultaneous Entrust authorities

Certificate Authority

Entrust JASTK

Entrust CA integration via the JASTK toolkit for established Entrust PKI estates.

Certificate Authority

Microsoft ADCS

Microsoft Windows CA (Active Directory Certificate Services) with certificate templates, key archival and recovery, and multiple-forest support.

Certificate Authority

PrimeKey EJBCA

EJBCA Enterprise integration over secure web services, tested with EJBCA 9.4.2.

Certificate Authority

Post-Quantum Cryptography

MyID CMS has been tested with the ML-DSA and ML-KEM post-quantum algorithms via PrimeKey EJBCA (9.4 or later). Currently software certificates only, issued through the MyID Operator Client.

Certificate Authority

Custom / other CA

Custom CA connectors for bespoke environments (managed in MyID as a Generic CA), plus SCEP enrolment. Talk to us about additional CAs.

Hardware Security Modules

Supported HSMs

HSM

Entrust nShield

nShield Connect and nShield Solo for key generation and cryptographic operations. Supports FIPS 140-2 Level 3 and FIPS 140-3 modes.

HSM

Thales Luna

Luna Network HSM (A- and S-Series), Luna Cloud HSM (DPoD) and Thales TCT Luna T-Series.

Identity Platforms

Directories & Identity Providers

Directory

Microsoft Active Directory

The core identity source for most deployments. Reads user and group attributes and writes certificate and smart-card logon data back to AD. Multi-forest and multi-domain.

Identity Provider

Microsoft Entra ID

Entra ID as directory, identity provider and FIDO2 passkey server: passkey issuance and synchronisation, plus certificate synchronisation.

Directory

LDAP

Integrate LDAPv3-compliant directories alongside or instead of Active Directory. Additional configuration applies for non-AD directories.

OIDC / SAML

Federated sign-in

Operator and self-service sign-in via OAuth2 / OpenID Connect and AD FS. Documented IdPs include Entra ID and Okta.

Devices

Smart Cards & USB Tokens

Smart Card & FIDO2

Yubico / YubiKey

PKI (PIV applet) and FIDO2 on a single key. YubiKey 5 series including v5.7 FIPS; multiple form factors.

Smart Card

IDEMIA

IDEMIA smart cards - PIV and enterprise profiles with RSA / ECC keys and minidriver support.

USB Token

Thales / SafeNet

SafeNet eToken family, including eToken 5300 and eToken Fusion NFC PIV, via SafeNet Authentication Client.

Smart Card

Thales TCT

Thales Trusted Cyber Technologies smart cards for US federal supply-chain requirements.

USB Token

Swissbit

Swissbit iShield Key 2 Pro tokens (including FIPS and MIFARE variants): PKI and FIDO2 credential lifecycle.

Smart Card

Giesecke+Devrient

G+D smart cards for PIV and enterprise credential profiles.

Smart Card

Athena

Athena smart cards with minidriver and interoperability support.

Smart Card

Egofy

Egofy smart cards, including FIDO and v3.0 card support.

Virtual

Microsoft Virtual Smart Cards

TPM-backed virtual smart cards - high-assurance credentials with no physical token.

Passwordless

Windows Hello for Business

Manage Windows Hello for Business credentials through MyID.

FIDO2

FIDO2 Passkeys

FIDO2 / WebAuthn passkeys with enterprise attestation, including Entra passkey import.

Issuance Hardware

Card Printers

Card Printer

Entrust / Datacard

XPS card printers - Datacard SD and CD series, CE840, CR805 retransfer, CL900 laser and Entrust Sigma DS1/DS2/DS3.

Card Printer

HID Fargo

Direct-to-card DTC4500e and high-definition HDP5000 and HDP6600.

Card Printer

Matica / EDIsecure

EDIsecure XID series (XID 8300 / 8100 / 8600), EXPRESSO, MOCA S3100 and MC series retransfer printers.

Card Printer

IDP

IDP Smart-51 and Smart-81 card printers.

Readers

Card readers & contactless

PC/SC-compatible readers; contactless support for ISO 14443 A/B and ISO 15693. Tested over local USB to confirm contactless readers with Intercede.

Automation

APIs & Programmatic Integration

REST API

MyID Core API

Primary REST API for issuance, lifecycle and integration with HR, IGA and ITSM platforms.

Authentication

OAuth2 / OpenID Connect

Standards-based authentication for API and client access.

Protocols

SCEP

SCEP enrolment for certificate issuance, with the REST-based MyID Core API for programmatic device operations.

API

Notifications Listener API

Issuer status callbacks for derived-credential workflows.

Frequently Asked Questions

Common questions

Everything you need to know. Can't find the answer? Contact our team →

Yes. Active Directory is the core identity source, MyID reads user attributes and group membership, writes certificate and smart-card logon data back to AD, and enforces group-based credential policy across multi-forest and multi-domain environments. Entra ID is supported as a directory, identity provider and FIDO2 passkey server, and generic LDAP v3 directories are also supported.

MyID CMS has supported connectors for DigiCert ONE, Entrust (CA Gateway and JASTK), Microsoft Windows CA (ADCS) and PrimeKey EJBCA, and can drive multiple CAs from a single instance. A generic CA connector and SCEP cover bespoke environments, and further CAs are available on request. Older connectors (Entrust via the Administration Toolkit for C, Symantec/DigiCert MPKI and UniCERT) reached end of sale at MyID CMS 2026.1: they cannot be added to new installations, though customers upgrading existing systems can continue to use them

Yes. MyID CMS 2026.1 has been tested with the ML-DSA and ML-KEM post-quantum algorithms through the PrimeKey EJBCA certificate authority (version 9.4 or later). Support currently covers software certificates only: ML-DSA keys can be issued to a software local store or as a .pfx file, and ML-KEM keys as a .pfx file, through the MyID Operator Client. Issuance to smart cards, tokens or mobile devices is not currently supported, and client PCs require Windows 11 24H2 with the post-quantum cryptography updates.

MyID CMS supports Entrust nShield (Connect and Solo) and Thales Luna HSMs, including Luna Cloud HSM (DPoD) and Thales TCT Luna T-Series, running in FIPS 140-2 Level 3 mode or FIPS 140-3 provisional mode.

MyID issues credentials to smart cards and USB tokens from Yubico, IDEMIA, Thales / SafeNet, Thales TCT, Swissbit, Giesecke+Devrient, Athena and Egofy, plus Microsoft virtual smart cards, Windows Hello for Business and FIDO2 passkeys. Tested card printer families include Entrust / Datacard, HID Fargo, Matica / EDIsecure and IDP. Contact us to confirm specific models for your environment.

Need help with an integration?

Our solutions architects can scope a custom integration, advise on infrastructure choices, or help you map MyID into your existing identity and security stack.