Skip to content

Mideye Documentation

Mideye is an on-premises multi-factor authentication (MFA) server that secures VPNs, servers, remote desktops, and applications. It integrates with your existing infrastructure via RADIUS and REST APIs, and supports multiple authentication methods including SMS OTP, push notifications, TOTP, and hardware tokens.

Key capabilities:

  • On-premises deployment — Run entirely within your infrastructure, or use optional Swedish-hosted services for push and SMS delivery
  • Multiple protocols — RADIUS for network devices, REST APIs for applications
  • Flexible MFA methods — SMS, push, TOTP, hardware tokens, and assisted login
  • Directory integration — Active Directory, LDAP, and local user stores
  • Threat protection — Mideye Shield guards against password spray, brute-force, and MFA fatigue attacks

TopicDescription
Pre-installation ChecklistRequirements and preparation steps
Install on RHEL/Rocky/AlmaRPM-based installation
Install on Debian/UbuntuDEB-based installation
Install on WindowsWindows Server installation
Initial ConfigurationFirst-time setup and configuration


One-time passwords delivered via SMS. Works with Swedish and international providers with multiple connections for redundancy.


Mideye Server(Your Infrastructure)Mideye Switch(European DCs)Mideye Shield(Threat Intel)Mideye Plus(Push Service)MAS(Magic Link)SMS / RCSProvidersYubicloud(YubiKey)Apple Push(APNs)Google Push(FCM) HTTPSHTTPSHTTPSHTTPS

The Mideye Server runs on-premises and communicates with optional European-hosted services:

  • Mideye Switch (European data centers) — Routes SMS/OTP messages and validates hardware tokens
  • Mideye Shield — Threat intelligence and IP reputation
  • Mideye Plus — Push notification service for mobile authentication (via Apple/Google)
  • MAS — Magic Link approval pages

For environments requiring no external dependencies, use TOTP and hardware tokens which operate entirely on-premises.


ModelDescription
On-PremisesFull local deployment. Authentication handled locally with TOTP and hardware tokens. No external network dependencies.
HybridOn-premises server with Swedish-hosted Mideye Switch for SMS/push delivery.
Central APIDirect API integration with Mideye-hosted authentication service for web applications.