Companies Block

Orgs, roles, invites, isolation.
Decided.

Battle-tested multi-tenant infrastructure for B2B apps. Open source, Apache 2.0, built on the same foundation as every other block.

claude plugin marketplace add https://github.com/23blocks-OS/ai-agents

claude plugin install company-block

Your agent now knows this API. Prefer hands-on? REST + SDK docs →

What's inside

Organizations

Unlimited, custom branding

Memberships

Departments, groups, hierarchies

Roles

Granular, per resource

Invitations

Email, domain auto-join

Multi-tenancy

Full data isolation

SSO

SAML and OIDC, per org

Domains

Verified, exclusive per org

Billing

Per-organization subscriptions

Already debugged

The mistakes were made, fixed, and shipped past — before you got here.

  • Tenant isolation enforced at the query layer, not left to application code.

  • Conflicting role grants merge deny-first, never silently the most permissive.

  • Invite and domain auto-join collisions reconcile to one membership, not duplicates.

  • Removing the last owner is blocked until a successor is assigned. No orphaned orgs.

Use this instead of

WorkOSyour hand-rolled orgs table

Better together

The user your Auth Block signs in is the exact user this block resolves into an organization and role — no directory to sync. Org created → Auth Block scopes the token to it → Products Block unlocks per-tenant billing. Zero glue code.

Tenancy is a load-bearing wall.

Stay in the loop

Get product updates, engineering posts, and new block announcements delivered to your inbox.

No spam. Unsubscribe anytime. Privacy policy.