RFC 8628 OIDC Device Flow RADIUS Bridge Multi-Tenant Biometric-Backed Self-Hosted

Replace Cisco DUO.
Keep your data.

Full-featured biometric identity provider. Runs on a Raspberry Pi. No per-seat fee. No cloud dependency. No Cisco.

3-Year Total Cost of Ownership

DUO charges per seat, per month, every year. STEADYWATCH™ is a one-time enterprise license on hardware you own.

Organization Size Cisco DUO Essentials Cisco DUO Advantage STEADYWATCH™
100 users $10,800 $21,600 License + ~$100 hardware
500 users $54,000 $108,000 License + ~$200 hardware
2,000 users $216,000 $432,000 License + ~$500 hardware
10,000 users $1,080,000 $2,160,000 License + ~$1,000 hardware

DUO pricing based on publicly available Cisco rates Q1 2026. Contact Quantum V^ LLC for STEADYWATCH™ enterprise licensing terms.

Feature Parity

STEADYWATCH™ reached full DUO functional parity on April 9, 2026.

Capability Cisco DUO STEADYWATCH™
OIDC / OAuth2 (RFC 8628 Device Flow)
Push MFA / Biometric approval
TOTP (time-based one-time password)
RADIUS bridge
JWKS / JWT token issuance
Admin console
Multi-tenant isolation
Self-hosted / on-premises
No per-seat monthly fee
No cloud dependency
Quantum-backed biometric credential
Runs on Raspberry Pi

Platform Capabilities

Five implementation phases, all live in production.

OIDC Identity Provider

  • RFC 8628 Device Authorization Grant
  • JWKS endpoint + JWT issuance
  • OpenID Connect discovery
  • Biometric-backed approval flow
  • Custom claims (biometric factor, confidence, prime)

RADIUS Bridge

  • Translates RADIUS Access-Request → OIDC
  • Works with any RADIUS-capable infrastructure
  • VPN, network access, legacy systems
  • No infrastructure changes required
  • Live on UDP 1812

Multi-Tenant Architecture

  • Full tenant isolation per organization
  • API key per tenant for client registration
  • Single deployment, unlimited tenants
  • MSSP-ready — zero marginal cost per tenant
  • Admin console with tenant management

Deployment

  • Docker Compose — 7 containers
  • Runs on Raspberry Pi 5 (8GB)
  • Or any Linux VM on existing infra
  • No Kubernetes, no cloud bill
  • HA option: two Pi units, active-passive

Live Demo

This is a real RFC 8628 Device Authorization request hitting production infrastructure — not a mockup.

Try the Device Flow

Click below to start a real OIDC Device Authorization request. You'll get a user code to approve on a second device — the same flow enterprises use to authenticate users via TV apps, CLIs, and IoT devices.

Ready to replace DUO?

Enterprise licensing, MSSP partnerships, and SHQKD premium available. Contact Quantum V^ LLC for terms.