Lamassu IoT Platform
Manage PKI and digital identities for your devices from a single platform.
Lamassu IoT centralizes the issuance, distribution, renewal and revocation of X.509 identities for connected devices. You can build a private PKI, protect its keys and automate the enrollment of a fleet without losing visibility into every certificate.
Start here
Get started
Create a CA, issue a certificate and register your first device.
How Lamassu works
Build the mental model of authorities, keys, identities and validation.
Architecture at a glance
Lamassu runs as a set of services on Kubernetes, backed by PostgreSQL, RabbitMQ and an OIDC provider. Hover a component to trace its connections, or see the platform architecture chapter for the low-level, per-service view.
Core capabilities
Build your trust hierarchy
Create root and intermediate authorities or import an existing PKI. Define which authority can issue each identity and keep the full chain of trust.
Protect cryptographic keys
Generate and safeguard keys using software engines, PKCS#11 HSMs or cloud services. Lamassu decouples operations from the physical location of the key.
Issue and control certificates
Issue certificates from the console or from a CSR, check their status and revoke them when they stop being trustworthy.
Automate device identities
Define enrollment policies with a Device Management Service (DMS) and let devices request or renew their identity through EST.
Publish validation status
Offer online validation through OCSP and distribute CRLs for consumers that need to check certificates offline.
React to events
Subscribe to lifecycle changes and send notifications by email, Microsoft Teams or webhooks.
Choose your path
I administer the PKI
Configure engines, authorities, issuance and validation.
I integrate a device
Configure the DMS and use EST to obtain an identity.
I operate the platform
Deploy Lamassu and prepare its dependencies.
I integrate another system
Connect Lamassu with AWS IoT Core and other destinations.