Single sign-on

Open-source single sign-on for every app

Connect web apps, internal tools, VPNs and legacy software to one login. Casdoor speaks OAuth 2.0, OpenID Connect, SAML, CAS, LDAP, RADIUS and Kerberos, and adds MFA and single logout on top.

Every protocol your apps speak

OpenID Connect, OAuth 2.0, SAML 2.0 and CAS for web apps; LDAP, RADIUS and Kerberos for legacy software and network gear.

Bring your identity provider

Let people sign in with Entra ID, Okta or ADFS over OIDC or SAML, or with any of 75+ social and enterprise providers.

MFA where it matters

Passkeys, TOTP, SMS, email and RADIUS MFA, required per organization.

Log out everywhere

Back-channel and RP-initiated logout, a session list with device and IP, and limits on concurrent sessions.

What's included

  • OAuth 2.0 and OpenID Connect provider, with PKCE
  • SAML 2.0 IdP with Single Logout and IdP-initiated SSO
  • CAS, LDAP, RADIUS and Kerberos/SPNEGO
  • Upstream OIDC and SAML: Entra ID, Okta, ADFS
  • Hosted, brandable login pages
  • Guides for Grafana, GitLab, Jenkins, Jira and Kubernetes

Included in the free open-source edition and in every Casdoor Cloud plan.

GET door.acme.com/.well-known/openid-configuration
{
  "issuer": "https://door.acme.com",
  "authorization_endpoint": "https://door.acme.com/login/oauth/authorize",
  "token_endpoint": "https://door.acme.com/api/login/oauth/access_token",
  "userinfo_endpoint": "https://door.acme.com/api/userinfo",
  "jwks_uri": "https://door.acme.com/.well-known/jwks"
}

// Most OIDC apps only need this issuer URL, a client ID and a secret.

FAQ

Frequently asked questions

Which protocols can apps use to sign in with Casdoor?
OAuth 2.0 and OpenID Connect, SAML 2.0 and CAS for web and mobile apps, and LDAP, RADIUS and Kerberos for legacy software, VPNs and Wi-Fi.
Can employees keep signing in with Entra ID or Okta?
Yes. Add Entra ID, Okta or ADFS as an upstream OIDC or SAML provider, and Casdoor passes the sign-in through while your apps talk only to Casdoor. Users and groups can also be synced from these directories.