# Typical Use Cases for Logto: A Complete Guide to Authentication Scenarios

> Discover Logto's typical use cases in SaaS, AI, and agent platforms. Learn how to implement secure, scalable authentication with ease. Get your complete guide now!

- Repository: [Logto/logto](https://github.com/logto-io/logto)
- Tags: use-cases
- Published: 2026-07-06

---

**Logto is an open-source identity infrastructure designed for SaaS, AI applications, and agent-based platforms that require scalable, secure authentication with built-in multi-tenancy and enterprise SSO support.**

Understanding the typical use cases for Logto helps developers choose the right architecture for their identity management needs. As implemented in the `logto-io/logto` repository, this modern auth platform provides specialized capabilities ranging from multi-tenant data models to Model Context Protocol support. Whether you are building a B2B SaaS product or integrating AI agents, Logto offers specific features tailored to these demanding scenarios.

## Multi-Tenant SaaS Applications

Logto excels in **multi-tenant SaaS environments** where each customer requires isolated user pools and distinct access controls. According to the source code documentation in the main [`README.md`](https://github.com/logto-io/logto/blob/main/README.md), the platform provides built-in multi-tenancy, enterprise SSO, and RBAC (Role-Based Access Control) out of the box without requiring custom workarounds.

### Isolated User Pools and RBAC

The architecture allows you to enforce **RBAC rules per organization**, ensuring that users within one tenant cannot access resources belonging to another. This is particularly valuable for B2B applications where enterprise customers demand strict data segregation and custom role definitions.

## AI-Driven and Agent-Based Platforms

Modern AI applications require authentication patterns that treat services as first-class citizens. Logto addresses this through **Model Context Protocol support**, enabling AI agents to participate directly in authentication flows.

### Model Context Protocol Support

As documented in the feature list, Logto supports agent-based architectures where AI services must call protected resources. This allows autonomous agents to obtain and use client-credential tokens through the Management API, ensuring secure machine-to-machine communication without human intervention.

## Custom Sign-In Experiences

Developers often need to customize the authentication interface while maintaining security standards. Logto provides a **tunnel CLI** that enables local development of custom UIs while proxying to Logto Cloud for end-to-end testing.

### Local Development with Tunnel CLI

Located in [`packages/tunnel/README.md`](https://github.com/logto-io/logto/blob/main/packages/tunnel/README.md), the tunnel functionality creates a secure bridge between your local development environment and Logto Cloud:

```bash

# Install the tunnel CLI

pnpm i -g @logto/tunnel

# Start a tunnel forwarding your local UI to Logto Cloud

logto tunnel start --endpoint https://<tenant-id>.logto.app/

```

This preserves session cookies while allowing you to iterate on custom sign-in flows locally.

## Enterprise Identity Integration

Logto simplifies integration with existing corporate identity infrastructures through **30+ pre-built connectors** for IdPs including Google, Facebook, and Azure AD. Each connector defines a `usageType` field specifying its purpose in the user journey.

### Social and Enterprise Connectors

The connector system supports four distinct usage types: `Register`, `SignIn`, `ForgotPassword`, and `Generic`. For example, configuring a Twilio SMS connector for password reset workflows requires specifying the appropriate `usageType` as shown in [`packages/connectors/connector-twilio-sms/README.md`](https://github.com/logto-io/logto/blob/main/packages/connectors/connector-twilio-sms/README.md):

```json
{
  "type": "sms",
  "provider": "twilio",
  "usageType": "ForgotPassword",
  "config": {
    "accountSid": "ACxxxxxxxxxxxx",
    "authToken": "your-auth-token",
    "from": "+1234567890"
  }
}

```

## API-First Services and Machine-to-Machine Communication

For backend services and automated systems, Logto offers the **`@logto/api` TypeScript SDK** with type-safe access to the Management API. This supports both client-credential flows and custom token logic essential for service-to-service authentication.

### Management API SDK

The SDK quick-start in [`packages/api/README.md`](https://github.com/logto-io/logto/blob/main/packages/api/README.md) demonstrates how to programmatically manage users:

```typescript
import { createManagementApi } from '@logto/api/management';

const { apiClient } = createManagementApi('your-tenant-id', {
  clientId: 'your-client-id',
  clientSecret: 'your-client-secret',
});

await apiClient.GET('/api/users').then((res) => {
  console.log('All users:', res.data);
});

```

This enables automated user provisioning, audit logging, and real-time access control updates without manual dashboard interaction.

## Self-Hosted and Rapid Prototyping

All core services in [`packages/core/README.md`](https://github.com/logto-io/logto/blob/main/packages/core/README.md) are open source and exposable via Docker Compose or Node.js, complete with OpenAPI specifications for extensions. For immediate experimentation, the repository provides one-click GitPod launches and starter scripts that spin up complete instances in seconds.

## Summary

- **Multi-tenant SaaS**: Built-in data isolation and per-organization RBAC eliminate architectural complexity for B2B applications.
- **AI and agent platforms**: Model Context Protocol support enables secure authentication for autonomous services.
- **Custom UI development**: The `logto tunnel` CLI bridges local custom sign-in pages with Logto Cloud for seamless testing.
- **Enterprise integration**: 30+ connectors with configurable `usageType` fields handle social login, SSO, and password recovery workflows.
- **Programmatic management**: The `@logto/api` SDK provides type-safe Management API access for automation and M2M scenarios.

## Frequently Asked Questions

### What types of applications is Logto best suited for?

Logto is optimized for multi-tenant SaaS products, AI-driven applications, and platforms requiring enterprise-grade authentication. Its architecture specifically supports scenarios requiring isolated user pools, complex role hierarchies, and integration with external identity providers.

### How does Logto support multi-tenancy?

The platform implements a native multi-tenant data model where each organization maintains isolated user pools and independent RBAC configurations. This is implemented in the core backend without requiring database-level separation or custom tenant logic in application code.

### Can I use Logto for AI agent authentication?

Yes, Logto supports Model Context Protocol and agent-based architectures, allowing AI services to authenticate as first-class citizens using client-credential flows. This enables secure API access for autonomous agents requiring protected resource calls.

### Is Logto suitable for enterprise SSO requirements?

Absolutely. Logto provides enterprise SSO connectors for Azure AD, OIDC, and SAML providers, alongside social connectors for consumer-facing applications. The connector system supports distinct `usageType` configurations to handle complex enterprise identity journeys including just-in-time provisioning.