# smallstep.com > AI-optimized mirror of smallstep.com containing 50 pages totalling 32,607 words of clean markdown content, structured data, and semantic HTML. Original source: https://smallstep.com. Last updated: 2026-08-04T09:08:02.245Z. Each page is available as HTML (with JSON-LD structured data) and Markdown (text-only, ideal for LLMs and RAG). ## Homepage - [The World's First Device Identity Platform | Smallstep](/content/site-root.html): Secure devices, enforce Zero Trust and simplify cryptography with Smallstep's unified platform for device identity and certificates. (434 words) ## Articles & Blog Posts - [Run step-ca in Docker Container Tutorial | Smallstep](/content/docs/tutorials/docker-tls-certificate-authority/index.html): Run step-ca certificate authority in Docker. Containerized PKI deployment for modern infrastructure environments with easy scalability options. (898 words) - [Secretless TLS client certificates in GitHub Actions](/content/blog/github-actions-oidc-tls-credentials/index.html): With GitHub Actions OIDC tokens and Smallstep Certificate Manager, you can access protected internal resources like cloud services, databases, websites, or Kubernetes clusters using short-lived TLS certificates and no hard-coded secrets! (1,520 words) - [How to Handle Secrets on the Command Line](/content/blog/command-line-secrets/index.html): How to keep secret credentials safe on the command line. (1,472 words) - [Certificate Revocation Management in step-ca | Smallstep](/content/docs/step-ca/revocation/index.html): Implement certificate revocation in step-ca. Support CRL and OCSP for comprehensive certificate lifecycle management and security. (835 words) - [Device Identity Platform™ overview ](/content/platform/index.html): Smallstep guarantees true device identity, preventing credential exfiltration, phishing, and impersonation attacks. (452 words) - [Open Source Security Tools by Smallstep | Smallstep](/content/open-source/index.html): Join Smallstep's open-source community. Contribute to identity and security tools that improve enterprise workflows worldwide. (848 words) - [Device identity is a blind spot in trust models ](/content/platform/category/index.html): If your devices cannot prove they’re genuinely part of your trusted fleet, your Zero Trust model has a critical gap. (290 words) - [Your Device Identity Is Probably a Liability](/content/blog/ncsc-zero-trust-device-identity/index.html): The NCSC requires unique, verifiable device identity for Zero Trust. Most organizations think certificates cover it. Here's why that assumption is a liability. (1,384 words) - [Consult and Expert | Smallstep](/content/webforms/pricing/index.html): Talk to a security expert (189 words) - [Device Identity Platform Data Sheets | Smallstep](/content/data-sheets/index.html): Download technical data sheets for Smallstep's device identity platform. Detailed specifications and deployment guides for enterprises. (136 words) - [Critical Components of Device Identity Platform | Smallstep](/content/platform/critical-components/index.html): Core components powering Smallstep's device identity platform. Understand the architecture securing enterprise infrastructure. (564 words) - [Cloud, On-Prem & Hybrid Device Identity Solutions | Smallstep](/content/deployment-options/index.html): Deploy device identity management your way. Choose from SaaS, hybrid, or on-premise PKI solutions. FIPS-compliant, SOC2 certified. Compare deployment options. (456 words) - [Device Identity Security Platform Overview | Smallstep](/content/platform/device-identity/index.html): Comprehensive device identity platform for modern enterprises. Secure every device with hardware-backed certificates and Zero Trust policies. (505 words) - [step-ca Certificate Authority Overview | Smallstep](/content/docs/step-ca/index.html): Complete documentation for step-ca certificate authority. Deploy and manage your own private CA for enterprise PKI operations. (744 words) - [Device Identity Management Success Stories: Real PKI Results | Smallstep](/content/case-studies/index.html): Fortune 100 companies trust Smallstep for device identity. Read how enterprises achieved 90%+ security improvements with automated PKI. (201 words) - [Configure Certificate Provisioners in step-ca | Smallstep](/content/docs/step-ca/provisioners/index.html): Master step-ca provisioners for flexible certificate issuance. Support multiple authentication methods from OIDC to cloud metadata. (3,641 words) - [Redis TLS — How to get and renew Redis TLS certificates — Practical Zero Trust](/content/practical-zero-trust/redis-tls/index.html): Step-by-step instructions for operationalizing Redis TLS certificates on Linux, Docker, or Kubernetes. (1,095 words, Sep 20, 2021) ## Listings & Categories - [Cryptographic Identity for Financial Infrastructure | Smallstep](/content/platform/category/banking-fintech-service-identity/index.html): Replace API keys with hardware-bound certificates. Reduce third party risk, improve audit defensibility, and secure autonomous financial systems. (652 words) - [Autonomous Systems & Defense | Smallstep](/content/platform/category/autonomous-systems/index.html): Secure autonomous and industrial systems with hardware-bound device identity. Enforce Zero Trust access, meet NIST and CMMC expectations, and control high-risk environments. (777 words) - [Zero Trust Device Identity: The Missing Half of Security | Smallstep](/content/platform/category/zero-trust/index.html): User MFA isn't enough. Add device identity to complete Zero Trust. Hardware-bound certificates, real-time inventory, automated lifecycle. Works with Linux, Mac, and Windows. (779 words) - [Device Identity for OEM & ODM Manufacturers | Smallstep](/content/platform/category/oem-odm-device-identity/index.html): Replace embedded API keys with hardware-bound certificates. Reduce enterprise procurement friction, improve audit defensibility, and secure OEM & ODM device fleets at scale. (616 words) - [Kubernetes Workload Identity Security & Zero Trust | Smallstep](/content/platform/category/kubernetes-workload-identity/index.html): Secure Kubernetes with short-lived workload identity certificates. Eliminate shared secrets, enforce mTLS, and implement Zero Trust across clusters with Smallstep. (563 words) - [Device Identity for IAM: Secure Okta & Entra ID Login | Smallstep](/content/platform/category/iam/index.html): Add device identity to Okta & Entra ID. Block unverified devices from accessing SaaS apps, SSH, VPNs & cloud consoles. No extra login steps. MDM integration included. (487 words) - [Casino & Gaming Infrastructure Identity | Smallstep](/content/platform/category/casino-gaming-identity/index.html): Secure casino and gaming platforms with cryptographic device identity. Replace API keys with automated certificates for gaming systems, services, and integrations. (566 words) - [Privileged Access Management Platform Overview | Smallstep](/content/platform/category/pam/index.html): Privileged Access Management with device identity verification. Secure high-value accounts with hardware-backed certificates. (570 words) - [Trusted Agent Access (Smallstep + Keycard)](/content/platform/category/keycard-smallstep/index.html): Keycard and Smallstep integration for securing agentic AI in production. Enforce task-scoped authorization with dynamic tokens and short-lived X.509 and SSH certificates backed by hardware device attestation to eliminate static secrets (341 words) - [Manufacturing Machine Identity & Zero Trust Access | Smallstep](/content/platform/category/industrial-machine-identity/index.html): Enforce hardware-bound machine identity across PLCs, IIoT, MES, and factory systems. Reduce ransomware risk, prevent lateral movement, and strengthen IEC 62443–aligned Zero Trust access controls. (631 words) - [Retail Device Identity & Zero Trust | Hardware-Bound Certificates | Smallstep](/content/platform/category/retail-device-identity/index.html): Eliminate shared secrets across retail stores with short-lived, hardware-bound certificates for POS, kiosks, Wi-Fi, and cloud workloads. Enforce Zero Trust device identity, reduce lateral movement, and strengthen PCI-aligned security with automated certificate lifecycle management. (665 words) - [Healthcare Device Identity & Zero Trust Access | Smallstep](/content/platform/category/healthcare-device-identity/index.html): Enforce hardware-bound device identity for healthcare Wi-Fi, VPN, and clinical systems. Reduce ransomware risk and strengthen HIPAA-defensible access controls. (638 words) - [Insurance Device Identity & Zero Trust | Hardware-Bound Certificates | Smallstep](/content/platform/category/insurance-device-identity/index.html): Eliminate shared secrets across insurance infrastructure with short-lived, hardware-bound certificates for underwriting, claims, branch offices, and cloud workloads. Enforce Zero Trust device identity, reduce lateral movement, and align with NAIC, GLBA, and NIST security requirements through automated certificate lifecycle management. (651 words) ## Products - [SaaS Application Security Solutions | Smallstep](/content/product/saas-apps/index.html): Protect SaaS applications with device identity certificates. Enable Zero Trust access to cloud services with hardware attestation. (794 words) - [SSH Certificate Management: Replace Keys with SSO + MFA | Smallstep](/content/product/ssh/index.html): Replace static SSH keys with daily-rotating certificates. Integrate Okta, Google, or Entra ID for MFA. Centralized auditing, emergency access, zero manual key management. (670 words) - [Hardware-backed device identity for Okta SSO | Smallstep](/content/product/solutions/okta/index.html): Smallstep adds hardware-backed device identity to Okta SSO so only verified, company-owned devices can access your most sensitive applications. (604 words) - [Device-Based ZTNA: Secure SaaS & Internal Access | Smallstep](/content/product/ztna/index.html): ZTNA backed by cryptographic device trust. Mutual TLS with hardware attestation secures SaaS apps and networks. No passwords, no prompts. Works on Mac, Windows and Linux. (492 words) - [Device Identity for ChromeOS | Smallstep](/content/product/solutions/chromeos/index.html): Turn every ChromeOS laptop into a hardware-attested, non-phishable device identity. Smallstep binds certificates to the TPM so only trusted Chromebooks can access Wi-Fi, VPN, SaaS, and internal apps. (452 words) - [Workload Security: Replace API Keys with Certificates | Smallstep](/content/product/team/workload-security/index.html): Replace static API keys with short-lived, automatically renewed workload certificates. Policy-controlled issuance across Kubernetes, cloud, and on-prem. (625 words) - [Certificate-Based Wi-Fi: WPA3 Enterprise with EAP-TLS | Smallstep](/content/product/wifi/index.html): Deploy certificate-based Wi-Fi with EAP-TLS. Prevent MAC spoofing, evil twin attacks, and password breaches. Fully-managed CA & RADIUS. Zero-touch deployment via MDM. (442 words) - [Eliminate Device Spoofing with Hardware-attested Fleet Management | Smallstep](/content/product/solutions/fleet/index.html): Secure Fleet devices with hardware-attested identity. Smallstep binds credentials to each device's TPM or Secure Enclave, blocks unmanaged endpoints, and automates certificates for Wi-Fi, VPN, SSO, and internal apps. No passwords, no spoofing, no loopholes. (374 words) - [AI & MCP Security with Device Identity Certificates | smallstep](/content/product/ai-and-mcp/index.html): Secure AI agents and MCP toolchains with cryptographic identity. Replace API keys with short-lived, hardware-backed certificates and mTLS for verifiable access to tools, APIs, and data. (545 words) - [VPN Device Identity: Replace Passwords with Certificates | Smallstep](/content/product/vpn/index.html): Replace VPN passwords with hardware-bound certificates. TPM/Secure Enclave backed, short-lived, phishing-proof. Works with Cisco, Palo Alto, and Zscaler. Zero-touch deployment. (540 words) - [Enterprise IT Device Identity Solutions | Smallstep](/content/product/team/enterprise-it/index.html): Complete device identity platform for Enterprise IT teams. Secure endpoints, automate certificates, and enforce Zero Trust policies. (443 words) - [Mac Device Identity for Jamf: Hardware-Bound Certificates | Smallstep](/content/product/solutions/mac-jamf/index.html): Verify every Mac is company-owned before issuing certificates. Integrate Jamf with hardware attestation, eliminate SCEP passwords, automate certificate lifecycle management. (502 words) - [DevOps Device Identity Solutions Platform | Smallstep](/content/product/team/devops/index.html): Secure DevOps workflows with Smallstep. Automate trust and integrate device identity across DevOps pipelines for enhanced security. (611 words) - [Step-CA Pro – Enterprise-Grade Certificate Authority & Automated PKI | Smallstep](/content/product/step-ca-pro/index.html): Step-CA Pro delivers enterprise-ready certificate management with high availability, active revocation, HSM/KMS integration, rich APIs, and seamless automation. Built on Smallstep’s trusted open-source foundation, it helps you upgrade your PKI with full control, compliance, and scale. (271 words) - [Linux Device Management: MDM Support for Enterprise IT | Smallstep](/content/product/solutions/linux/index.html): Enable Linux without compromising security. Device enrollment, inventory management, and certificate-based auth for Wi-Fi, VPN, Okta. No more IT policy exceptions. (431 words) - [Windows Intune Security Solutions Platform | Smallstep](/content/product/solutions/windows-intune/index.html): Secure Windows devices with Intune and Smallstep integration. Deploy certificates for enterprise endpoint protection at scale. (463 words) - [The difference between Okta Device Trust and Device Identity | Smallstep](/content/product/solutions/device-trust-vs-device-identity/index.html): Boost Okta security with hardware-backed, device-attested credentials. Compare Smallstep’s high-assurance device identity with Okta Device Trust, including platform coverage, security posture, and SSO integration. Get stronger proof that only trusted, corporate-owned devices can access your sensitive apps. (459 words) - [Prevent AI misuse or data exfiltration with Keycard + Smallstep | Smallstep](/content/product/solutions/keycard/index.html): Enable the development and integration of AI Agents and MCP Servers with strong, multi-layered identity– without sacrificing security. Ensure only authorized users on verified devices can leverage these tools—preventing AI misuse or data exfiltration. (145 words) ## About Pages - [About Smallstep: Our Team and Mission | Smallstep](/content/about/index.html): Meet the security experts building modern device identity. Learn how we're revolutionizing enterprise PKI with automated certificate management. (144 words) ## Resources - [Full Page Index](/index.html): Browse all cached pages with rich metadata - [About This Cache](/about.html): Methodology, technical details, and usage guidelines - [XML Sitemap](/sitemap.xml): Machine-readable sitemap for crawler discovery - [Robots.txt](/robots.txt): Crawler directives