ForgeRock is a privately held identity and access management (IAM) vendor headquartered in San Francisco, founded in 2010 in Norway by former Sun Microsystems employees after Oracle’s acquisition, aiming to keep Sun’s identity products from being phased out. The company built a unified, open source–based IAM stack and shipped the complete ForgeRock Identity Platform by 2013. It has grown into a globally present IAM provider with offices across the USA, UK, Germany, France, Norway, Singapore, and Australia, and positions itself as distinct from “suites” assembled through acquisitions by offering a genuinely unified platform for managing many identity types—people, devices, applications, and smart things.
ForgeRock’s platform strategy responds to digital transformation pressures that strain loosely coupled enterprise IAM infrastructures, especially around multiple identity types, IoT interaction, and privacy/consent. Its next-generation “Identity Relationship Management” approach extends IAM concepts to internet scale, supports new partner/consumer/device communication channels, and embeds user-managed access to raise trust beyond compliance. Built on open standards and open source licensing, the platform is modular but integrated, with shared services (common interfaces, GUI, APIs, scripting, logging, auditing) underpinning core products: Access Management (OpenAM), Identity Management (OpenIDM), User-Managed Access (OpenUMA), Directory Services (OpenDJ), and Identity Gateway (OpenIG).
ForgeRock Identity Gateway (commercialized from OpenIG) is positioned as business-critical for extending authentication and authorization beyond the corporate perimeter, including to legacy applications lacking modern identity standards. As a reverse HTTP proxy, it inspects and transforms requests to enforce centralized policies without deploying agents or rewriting apps. It supports SSO, SAMLv2, OAuth 2.0, OpenID Connect, token translation (via Secure Token Service), throttling, basic message transformations, IoT-scale scenarios, and password capture/replay for legacy integration—while notably lacking advanced threat detection and mitigation expected of a full enterprise API gateway.
See All Locations
See All Locations