Open-source identity platformv4.13.0 released →

Identity for every user, app and AI agent

Casdoor secures how customers, employees and AI agents sign in and what they can access: single sign-on, MFA, passwordless login and fine-grained authorization, on open standards. Run it in your own data center or on a dedicated Casdoor Cloud instance.

Cloud from $25/month with no per-user fees · or self-host for free →

OAuth 2.0 & OIDCSAML 2.0CASLDAP & RADIUSSCIM 2.0WebAuthnMCP
demo.casdoor.com
Casdoor admin console dashboard with user, application and provider totals

Proven in production, on every continent

From start-ups to banks, carmakers and ministries of education, teams run their sign-in on Casdoor, in the cloud or behind their own firewall.

Active login domains
5,000+
with a live Casdoor login page in the last 90 days*
Login page loads a month
1.5M+
across those deployments, September 2026*
Docker pulls
2.2M+
of the official Casdoor images
GitHub stars
14.5k
one of the most-starred open-source IAM projects
75+identity providers
20+official SDKs
23Cloud regions
11UI languages

* Counted from requests to Casdoor's public CDN, July to September 2026. Deployments that host their own assets or run on private networks are not included, so the real numbers are higher.

Solutions

Built for what you're building

Whatever you ship, Casdoor handles identity the same way: standard protocols, one console and SDKs for your stack.

Ship AI agents without giving away the keys

Make Casdoor the authorization server for your MCP servers. AI clients such as Claude, ChatGPT and Cursor discover it, register themselves and get tokens scoped to the tools a user allowed, and every call is logged.

Featured capabilities

OAuth for MCPDynamic client registrationResource indicatorsToken ExchangeDPoP-bound tokensPer-tool permissionsDevice login for CLIs
Read the guide
GET mcp.acme.com/.well-known/oauth-protected-resource
{
  "resource": "https://mcp.acme.com",
  "authorization_servers": ["https://door.acme.com"],
  "scopes_supported": ["tickets:read", "tickets:write"],
  "bearer_methods_supported": ["header"]
}

// The MCP client finds Casdoor here, registers itself (RFC 7591)
// and asks for a token for https://mcp.acme.com (RFC 8707).

Identity for AI agents

Secure the agentic future, on open standards

AI agents now read your tickets, query your data and call your APIs. Casdoor gives every agent a verifiable identity and lets your users decide exactly what it may do, using the same OAuth standards the MCP specification is built on.

Works withClaudeChatGPTCursorVS CodeYour own agents
AI clientCasdoorMCP server
  1. 1
    DiscoverRFC 9728

    The AI client calls your MCP server and finds Casdoor in its protected resource metadata.

  2. 2
    RegisterRFC 7591

    The client registers itself with Casdoor. No API keys to copy around.

  3. 3
    ConsentOAuth 2.1 + PKCE

    The user signs in and approves only the tools and scopes the agent needs.

  4. 4
    ActRFC 8707 · DPoP

    The agent gets a short-lived token for that one server, bound to its key.

An MCP store for your organization

Browse ready-made MCP servers, add the ones your teams need with one click, and manage them next to your applications. Casdoor syncs each server's tools so you can decide exactly which ones agents may call.

demo.casdoor.com/server-store
Casdoor MCP Store listing MCP servers such as Apify, Asana, Atlassian and Cloudflare

MCP server registry

List your MCP servers, sync their tools and decide which tools each application may call.

Find shadow MCP servers

Scan your internal network for MCP servers nobody registered, before an agent finds them.

Delegation, not impersonation

Token Exchange lets an agent act on a user's behalf with a narrower, traceable token.

Every action on record

Agent sign-ins and API calls land in the same audit trail as people, and can stream to your SIEM.

Capabilities

Everything an identity team needs. Nothing to bolt on.

Casdoor is one server with one console. Every capability below is included, in Casdoor Cloud and in the free open-source edition.

demo.casdoor.com/applications/built-in/app-built-in
Casdoor admin console: editing an application, with tabs for authentication, OIDC/OAuth, SAML, providers, UI customization and security

Authentication

  • Hosted, brandable login and sign-up pages
  • Passkeys (WebAuthn), Face ID and magic links
  • TOTP, SMS, email and RADIUS MFA, required per organization
  • 75+ social and enterprise identity providers
  • reCAPTCHA, hCaptcha, Turnstile and GeeTest
  • Password policies with history checks

Single sign-on & protocols

  • OAuth 2.0 and OpenID Connect provider, with PKCE
  • SAML 2.0 IdP with Single Logout and IdP-initiated SSO
  • CAS, LDAP, RADIUS and Kerberos/SPNEGO
  • Upstream OIDC and SAML: Entra ID, Okta, ADFS
  • Device flow, Token Exchange, DPoP, JWT client auth
  • Back-channel and RP-initiated logout

Authorization

  • Casbin models: ACL, RBAC, ABAC or your own
  • Roles, groups and per-resource permissions
  • Single and batch enforce APIs
  • Permissions that expire automatically
  • See which role or group granted each permission
  • Per-tool permissions for MCP servers

Users & directory

  • Organizations with their own users, apps and branding
  • Group trees, invitations and bulk import or export
  • SCIM 2.0 provisioning API
  • Sync from Active Directory, Entra ID, Google Workspace and Okta
  • Keycloak, AWS IAM, SCIM, WeCom, DingTalk, Lark and database syncers
  • Self-service account pages and impersonation for support

Extend & integrate

  • REST API and Swagger docs for every object
  • 20+ official SDKs for web, backend, mobile and desktop
  • Webhooks for sign-ins, sign-ups and changes
  • Custom HTML and CSS on login pages
  • Built-in payments, plans and subscriptions
  • Email, SMS, storage and notification providers

Operations

  • Audit records, forwarded to Syslog and your SIEM
  • Session list with device and IP, and session limits
  • Retention settings for records and tokens
  • MySQL, PostgreSQL and other databases
  • Docker, Helm chart and Redis Cluster for HA
  • 11 interface languages

What's new

Shipping every week, in the open

Casdoor releases continuously. Here's what landed over the past year, all of it available in Cloud and self-hosted.

Full changelog
ConsoleSep 2026

A rebuilt admin console

A faster, cleaner console with a command palette, bulk actions, two-column forms and tables where you choose the columns.

Sep 2026

Authentication

Magic link sign-in

Users sign in from a one-time link in their inbox, with no password to remember or reset.

Sep 2026

Compliance

Audit logs to your SIEM

A new Audit provider forwards sign-in and admin records to Syslog, with retention set per organization.

Sep 2026

Sessions

Exclusive sign-in and session limits

Cap concurrent sessions per user, across one app or a whole organization, and see the device, IP and last activity of each.

Aug–Sep 2026

Enterprise SSO

SAML Single Logout and IdP-initiated SSO

Sign users out of every SAML app at once, and let them start from an identity provider portal.

Aug 2026

Authorization

Time-limited, explainable permissions

Permissions can expire on their own, and the console shows which role or group granted each one.

Mar–Apr 2026

Protocols

Kerberos, DPoP and device login

Windows desktop SSO with Kerberos/SPNEGO, proof-of-possession tokens and the OAuth device flow for TVs and CLIs.

Jan–Apr 2026

AI agents

MCP authorization and agent registry

Casdoor protects MCP servers, registers AI clients dynamically, exchanges tokens and finds MCP servers on your network.

Security & trust

Security you can verify, not just read about

Identity is the front door to your business. Casdoor is built in the open, so your security team can check exactly how it works instead of trusting a badge.

Found a vulnerability? Please report it privately to admin@casdoor.org.

Open source and auditable

Every line of Casdoor is public on GitHub under Apache-2.0. Review it, scan it or fork it.

Single-tenant by design

Each Casdoor Cloud subscription gets its own Casdoor instance and its own database. No shared tenants.

Data residency

Choose from 23 Cloud regions, or self-host when data must never leave your network.

Phishing-resistant MFA

Passkeys, TOTP and one-time codes, required for a whole organization when you need it.

Abuse protection

Captchas on login and sign-up, rate-limited one-time codes, IP allowlists and session limits.

Keys you control

Tokens signed with your own certificates, configurable lifetimes, DPoP binding and instant revocation.

Complete audit trail

Sign-ins and admin API calls are recorded and can be forwarded to Syslog, your SIEM or a webhook.

HTTPS everywhere

Cloud instances are served over HTTPS with managed certificates, including on custom domains.

Built on open standards

OAuth 2.0 · RFC 6749OpenID ConnectSAML 2.0PKCE · RFC 7636JWT client auth · RFC 7523Dynamic registration · RFC 7591/7592Device flow · RFC 8628Token Exchange · RFC 8693Resource Indicators · RFC 8707DPoP · RFC 9449Issuer identification · RFC 9207Protected Resource Metadata · RFC 9728SCIM 2.0WebAuthn

Developer quickstart

From zero to login in 3 steps

No identity code to write or maintain. Configure Casdoor once and connect every app to it.

01

Get a Casdoor server

Subscribe to Casdoor Cloud and get your own instance at yourcompany.casdoor.com, or start one yourself with Docker.

docker run -p 8000:8000 casbin/casdoor-all-in-one

Cloud instances are set up for you after checkout

02

Create an application

In the admin console, add an application, set its redirect URL, pick the login methods and providers, and brand the login page.

redirectUris: ["https://app.acme.com/callback"]
providers: ["Google", "GitHub", "SAML"]

Everything is configured in the web console

03

Connect your app

Use one of the official SDKs, or any standard OIDC, SAML or CAS client library you already have.

npm install casdoor-js-sdk
window.location.href = sdk.getSigninUrl();

Standard protocols, no lock-in

Read the documentation

Guides · SDK references · Sample apps on GitHub

Casdoor Cloud pricing

Simple pricing. No per-user fees.

Every plan is a dedicated, fully managed Casdoor instance. Pay a flat price, not per monthly active user.

Starter

For small teams getting started with a hosted Casdoor.

$25/ month

Get Starter
  • Dedicated Casdoor instance and database
  • OAuth 2.0, OIDC, SAML, CAS, LDAP and SCIM
  • Your own subdomain at casdoor.com
  • Hosted in Singapore or Japan
  • Automatic Casdoor upgrades
  • No per-user or per-MAU fees
  • Support via tickets
Most popular

Professional

For growing start-ups that need their own login domain.

$59/ month

Get Professional
  • Everything in Starter
  • Custom domain with managed TLS certificate
  • Choose from 23 regions and switch any time
  • 8x5 technical support

Enterprise

For companies running Casdoor in production.

$149/ month

Get Enterprise
  • Everything in Professional
  • Priority 8x5 technical support
  • Help with onboarding and migration
  • Custom terms and invoicing on request

Casdoor for large organizations

Need on-premises deployment, migration help or custom terms?

We help teams plan self-hosted and private-cloud deployments, migrate users from other identity platforms, design authorization models and agree contracts and invoicing that fit your procurement process.

Contact sales

Prefer to run it yourself? Casdoor is free and open source — self-hosting guide.

Prices in USD. Casdoor Cloud is operated by Casbin Inc. See our Terms of Service and Refund Policy.

Cloud or self-hosted

Same Casdoor. You choose who runs it.

Self-hostedCasdoor Cloud
PriceFree (Apache-2.0)From $25/month, flat
SoftwareOpen-source CasdoorThe same open-source Casdoor
Who runs and upgrades itYour teamWe do
RegionYour servers or cloud account23 regions to choose from (Starter: Singapore or Japan)
DomainAny domain you ownyourcompany.casdoor.com, or your own domain on Professional and Enterprise
DatabaseYour MySQL, PostgreSQL or other databaseA dedicated database per instance
SupportCommunity on GitHub and DiscordTickets or 8x5 support, depending on plan
Switch laterMove to Cloud with our helpExport your data and self-host any time

Casdoor Cloud regions

North America

US WestUS EastCanadaMexico

South America

BrazilArgentina

Europe

United KingdomEU (Germany)EU (Norway)EU (Finland)Turkey

Oceania

AustraliaNew Zealand

Middle East

IsraelSaudi ArabiaUnited Arab Emirates

East Asia

JapanSouth Korea

Southeast Asia

SingaporeIndonesiaMalaysiaVietnam

South Asia

India

Starter plans run in Singapore or Japan. Professional and Enterprise plans can use any region and switch later.

FAQ

Frequently asked questions

How is Casdoor different from Auth0, Okta or Keycloak?
Casdoor is open source (Apache-2.0), so you can self-host it for free or use our managed Cloud, and switch between the two. Cloud plans have a flat price with no per-user or per-MAU fees. It speaks more protocols than most alternatives (OAuth 2.0, OIDC, SAML, CAS, LDAP, RADIUS, SCIM), and ships with Casbin for fine-grained authorization instead of leaving permissions to your code.
Can Casdoor secure AI agents and MCP servers?
Yes. Casdoor can act as the OAuth authorization server for your MCP servers: it publishes the metadata MCP clients look for, lets AI clients register themselves (RFC 7591), issues tokens scoped to one server (RFC 8707) and to the tools a user approved, and supports Token Exchange and DPoP. You can also keep a registry of your MCP servers, sync their tools and scan your network for unregistered ones.
Can we migrate from Okta, Keycloak or Active Directory?
Yes. Casdoor has syncers that import users and groups from Active Directory, LDAP, Entra ID, Google Workspace, Okta, Keycloak, AWS IAM, SCIM directories and databases. Because Casdoor speaks OIDC, SAML and CAS, most apps only need a new issuer URL and client credentials. We can help plan larger migrations.
What's the difference between Casbin and Casdoor?
Casbin is an authorization library that you embed in your code to enforce access-control models such as ACL, RBAC and ABAC. Casdoor is a complete identity server with a web console: login, single sign-on, MFA, users and organizations. Casdoor uses Casbin for its permission features.
What's the difference between Casdoor Cloud and the open-source version?
It's the same Casdoor. With Cloud, we host a dedicated instance and database for you, keep Casdoor upgraded, manage HTTPS certificates and give you support. With the open-source version, you run and maintain it yourself.
Which regions can I choose?
You can choose from 23 regions: North America (US West, US East, Canada, Mexico); South America (Brazil, Argentina); Europe (United Kingdom, EU (Germany), EU (Norway), EU (Finland), Turkey); Oceania (Australia, New Zealand); Middle East (Israel, Saudi Arabia, United Arab Emirates); East Asia (Japan, South Korea); Southeast Asia (Singapore, Indonesia, Malaysia, Vietnam); South Asia (India). Starter plans run in Singapore or Japan; Professional and Enterprise plans can use any region and switch later. If your data must stay in a specific country, contact us before you subscribe.
Do you have SOC 2 or ISO 27001 certification?
Casdoor Cloud does not hold SOC 2 or ISO 27001 certification today. Because Casdoor is open source, teams with strict compliance requirements usually self-host it inside their own certified environment, where they control the infrastructure and data.
Can I move from Cloud to a self-hosted deployment later?
Yes. Your instance runs open-source Casdoor, so your data can be exported and imported into your own deployment. Contact us and we'll help with the migration.
How do billing and cancellation work?
Plans are billed monthly or annually through our payment partner Gumroad. You can cancel at any time and your instance stays active until the end of the period you paid for. Payments are non-refundable.
Do you offer consulting, for example on designing authorization?
Yes. We can help you design authorization models, integrate Casdoor with your apps or plan a self-hosted deployment. Contact us for a quote.