Home > Identity platforms

OpenText Identity Manager and Key2XS: the key system your Identity Vault was missing

OpenText Identity Manager, known for most of its life as NetIQ Identity Manager, keeps an entire landscape synchronized from one authoritative source. Key2XS connects to it over SCIM 2.0 and makes physical keys one more connected system, so the same events that reshape accounts also reshape access to iLOQ cylinders, ASSA ABLOY CLIQ keys and ABLOY PULSE locks.

Request a demo

What OpenText Identity Manager is

OpenText Identity Manager is an enterprise identity management platform with a long history. It was built by Novell, carried forward as NetIQ Identity Manager, moved to Micro Focus, and became part of OpenText when OpenText acquired Micro Focus in 2023. Organizations running it have often built their identity landscape around it for a decade or more, and the architecture reflects that: it is an integration engine as much as a directory.

The parts that matter for access decisions:

The engine is designed so that everything connected stays in step. Physical keys have simply never been one of the connected things.

Every system is connected to your Identity Vault. Except the keys.

The event-driven engine keeps directories, HR systems and applications synchronized, and when something changes at the source, every connected system follows. Physical keys are the exception. They are managed in a separate key administration, issued by a different department, and untouched by the events that govern everything else.

Under NIS2 and the CER Directive, critical entities must govern access to premises with the same rigor as access to information systems. An identity architecture that stops at the digital boundary leaves that requirement unmet.

How Key2XS connects to Identity Manager

Key2XS connects through the SCIM 2.0 universal server rather than a bespoke driver. Identity Manager treats it as one more standards-based endpoint, which means no new driver to develop, no change to the Identity Vault schema, and no re-architecture of what already works.

ProtocolSCIM 2.0 (RFC 7643 and RFC 7644)
AuthenticationBearer token, Basic Auth or OAuth 2.0 client credentials
DirectionInbound: identities and entitlements into Key2XS
SynchronizationReal-time, driven by SCIM push

Connect, map, orchestrate, prove

  1. Connect. Identity Manager pushes identity and entitlement events to Key2XS over SCIM 2.0, and Key2XS connects to each key system over its own API. A standard integration is live in under two hours, with no changes to your existing drivers or Identity Vault.
  2. Map. Roles and resources are mapped to key rights and lock groups. A role like “Ward Nurse, Location East” can correspond to exactly the wards, medicine rooms and storage spaces that role requires.
  3. Orchestrate. When an assignment is created, changed or removed, the SCIM push reaches Key2XS in real-time and the matching key rights are applied. The leaver event that disables accounts now also closes doors.
  4. Prove. Every key right traces back to an identity, a role and a moment in time, in one tamper-evident audit trail.

What moves between OpenText Identity Manager and Key2XS

From OpenText Identity Manager To your key systems via Key2XS
Identities (joiners, movers, leavers) Key holders created, updated or deactivated
Role and resource assignments Key rights and access to lock groups
Deactivations and contract end dates Immediate withdrawal of key rights
Assignment history Documented authorization behind every key

One source of truth, every key system

The point of connecting Identity Manager to Key2XS is not a single lock brand. Identity Manager becomes the one place where physical access is decided, and Key2XS carries that decision to whichever key systems your sites actually run. Most organizations have more than one: a digital locking system at the head office, electronic keys on the network, mechanical high-security cylinders on the perimeter.

Key system under governance How Key2XS drives it
iLOQ S5 and S50
Self-powered digital cylinders (S5) and Bluetooth/NFC phone keys (S50).
REST API. Key holders, key rights and key validity provisioned per person, with 29 independent sync operations.
ASSA ABLOY eCLIQ
Electronic cylinders, padlocks and programmable keys.
SOAP API through CLIQ Web Manager, secured with mutual TLS. Full lifecycle, event-driven and batch.
ASSA ABLOY PROTEC2 CLIQ
High-security locking combining rotating disc technology with electronic identification.
SOAP API through CLIQ Web Manager, secured with mutual TLS. Full lifecycle, event-driven and batch.
ASSA ABLOY CLIQ Remote
Remote key updates through wall programmers, desktop units or the CLIQ Connect Bluetooth app, so keys never have to come back to a desk.
SOAP API through CLIQ Web Manager, secured with mutual TLS. Validity windows refreshed in the field.
ABLOY PULSE
Self-sustaining locks that harvest their energy from key insertion. No batteries, no wiring.
SOAP API through CLIQ Web Manager, secured with mutual TLS. Full lifecycle, event-driven and batch.

Key2XS is certified by ASSA ABLOY for its locking system integrations. One mapping in Identity Manager can therefore span brands: a single role or group grants the iLOQ cylinders in one building and the eCLIQ padlocks on a remote site, revoked together the moment Identity Manager says so.

The same holds on the identity side. Key2XS also connects to SailPoint Identity Security Cloud, SailPoint, Microsoft Entra ID, Okta and One Identity Manager, and to any system that can speak SCIM 2.0, so a landscape with more than one identity platform still resolves to one physical access model. See the integrations overview for the full picture.

Built for critical environments

Key2XS is used where physical access affects public safety, service continuity or regulatory compliance: utilities, government, transport, healthcare and industry.

Why not build a driver yourself?

The driver model makes custom connections possible in principle, and a locking system is just another endpoint. In practice a homegrown bridge means specialized development against an API per key system brand, an audit layer you design yourself, and years of maintenance across upgrades on every side. Key2XS delivers this as a maintained platform:

Frequently asked questions

OpenText Identity Manager and Key2XS, answered.

See Identity Manager governing your keys

Get a guided walkthrough of how identity events, roles and physical keys come together in one auditable flow.