Gravitee Access Management by Gravitee.io is a fully-featured standalone Identity and Access Management solution designed to secure and control enterprise data. It supports various factors for multi-factor authentication (MFA) to protect user account access, including email, one-time-password, biometric factors, recovery codes, and more. Gravitee Access Management enables security teams to use a variety of authentication factors, intelligent conditioning, and risk-based logic to build multi-factor authentication flows. It supports W3C Web Authentication (WebAuthn), allowing users to authenticate without a password using U2F Tokens from Yubico and Feitian. Gravitee Access Management can be integrated with the Gravitee Unified API Management platform, including the Gravitee API Gateway and API Monitoring and Alerting solution, to enforce API-level security standards. It allows centralized management of federated third-party identity providers and the creation of custom identity providers. Gravitee Access Management can be used as an OAuth2 authorization resource by your API Gateway, enhancing the process of credential checking during API requests. It supports flow design for various stages, enabling the execution of policies during the OnRequest step of selected stages. Gravitee Access Management also provides risk-based MFA, using conditional logic and data monitoring to enforce specific authentication factors for high-risk users based on device location, IP reputation score, and geolocation velocity.