awesome-repositories.com
Blog
MCP
awesome-repositories.com

Découvrez les meilleurs dépôts open-source grâce à notre recherche par IA.

ExplorerRecherches sélectionnéesAlternatives open sourceLogiciels auto-hébergésBlogPlan du site
ProjetServeur MCPÀ proposNotre méthodologiePresse
Mentions légalesConfidentialitéConditions d'utilisation
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
apereo avatar

apereo/cas

0
View on GitHub↗
11,347 stars·3,951 forks·Java·Apache-2.0·14 vuesapereo.github.io/cas↗

Cas

This project is an open-source identity provider and single sign-on platform that centralizes user authentication for multiple web applications and services. It functions as a multi-protocol authentication gateway, verifying user identities and issuing tokens through the CAS protocol as well as industry standards including SAML, OAuth2, and OpenID Connect.

The system acts as a federated identity server, allowing authentication to be delegated to external third-party or corporate identity providers. It distinguishes itself through identity attribute governance, which manages which specific user profile data and permissions are released to connected applications while collecting necessary user consent.

The platform covers broad capability areas including enterprise access control, multifactor authentication enforcement via hardware keys or mobile apps, and comprehensive account lifecycle management. It also provides tools for centralized security auditing, system performance monitoring, and the administration of client application registrations.

Features

  • Single Sign-On Solutions - Coordinates access between service providers and identity providers using standard industry protocols to enable single sign-on.
  • User Authentication Systems - Provides a single entry point for verifying user identities using shared databases and directories.
  • Distributed Session Caching - Synchronizes authentication data across multiple server nodes using distributed caches to ensure high availability.
  • Identity - Functions as a unified core that translates identity data between different standards including SAML, OAuth2, and OpenID Connect.
  • Attribute Release Policies - Implements a rule-based engine to control the release of user profile data and permissions to connected applications.
  • Client Registries - Maintains a registry of authorized services and assigns specific authentication policies to each client application.
  • Authentication Gateways - Acts as a security layer that supports diverse verification methods and enforces access policies.
  • Authentication Managers - Provides a centralized system for handling user identity and session persistence across multiple web applications.
  • Consent Management - Controls which user profile attributes are released to applications and manages the user consent process.
  • Attribute-based Access Controls - Implements a system to determine which user profile attributes are released based on defined security policies.
  • Identity Management - Verifies user identities and attributes centrally to ensure consistent access control across all connected applications.
  • Attribute Release Policies - Controls which pieces of identity data are released to service providers and manages the user consent process.
  • Identity Authentication - Verifies user identities through a single point of entry for multiple applications using shared backend stores.
  • Identity Federation Providers - Delegates user authentication to external third-party or corporate identity providers using standardized protocols.
  • Identity Providers - Operates as a centralized service providing unified authentication and authorization via SAML, OAuth2, and OIDC.
  • Identity Servers - Provides a centralized platform for authentication, authorization, and federation services.
  • Authentication Pipelines - Implements a sequential verification chain that intercepts the login flow to require secondary credentials.
  • Multifactor Authentication - Requires a second form of verification via hardware keys, mobile apps, or security services to increase account security.
  • Single Sign-On - Exchanges authentication data using industry standards including SAML, OAuth2, OpenID Connect, and CAS.
  • Enterprise SSO Integrations - Supports industry-standard SSO protocols like CAS, SAML, OAuth2, and OpenID Connect to verify user identities.
  • Attribute Release Policies - Manages the release of specific user profile data and permissions to connected applications.
  • Authentication Backends - Provides a modular driver system to verify identities against various databases, directories, or external APIs.
  • Client Application Registrations - Allows the registration of authorized services and the assignment of specific authentication policies to each client.
  • Dynamic Configuration - Allows system settings and behaviors to be modified in real-time without requiring a server restart.
  • Account Lifecycle Management - Handles the full lifecycle of user accounts, including password resets, notifications, and administrative impersonation.
  • Centralized Identity Management - Consolidates the management of user attributes, password policies, and client registrations in one location.
  • OAuth and Identity Providers - Offloads identity verification to third-party services using standardized identity provider protocols.
  • Attribute Synchronizations - Implements automated processes to synchronize user profile metadata and attributes from external identity providers.
  • Distributed Session Storage - Synchronizes user authentication data across multiple server nodes using distributed session storage to ensure high availability.
  • Identity Federation - Delegates authentication to external providers to allow users to sign in using third-party accounts.
  • Password Management - Handles user password reset requests and enforces password complexity rules.
  • Password Policies - Defines and enforces rules for password complexity, rotation, and mandatory change requirements.
  • Policy-Based Access Control - Restricts resource access based on user roles and attributes using centralized authorization policies.
  • Role-Based Access Control - Manages user permissions and defines access levels based on assigned roles using external authorization engines.
  • Access Control - Provides frameworks and policies for managing resource access through role-based permissions and authorization engines.
  • User Account Management - Provides user-facing tools for managing account security, updating passwords, and handling terms of use.
  • Audit Event Buses - Provides a centralized logging architecture that captures security events and publishes them to external monitoring systems.
  • Administrative Interfaces - Provides web-based dashboards for monitoring system statistics and overseeing client registrations.
  • Centralized Logging Systems - Aggregates security audits and system logs centrally for distribution to downstream monitoring systems.
  • Security Audit Logs - Captures and centralizes authentication logs to track the execution of security policies.
  • System Configuration Management - Offers a dedicated interface for managing system-wide logging, monitoring, and client registration settings.
  • Message Queues - Enterprise-grade single sign-on and authentication service.

Historique des stars

Graphique de l'historique des stars pour apereo/casGraphique de l'historique des stars pour apereo/cas

Recherche par IA

Explorez plus de dépôts awesome

Décrivez vos besoins en langage naturel — l'IA classe des milliers de projets open source sélectionnés par pertinence.

Start searching with AI

Alternatives open source à Cas

Projets open source similaires, classés selon le nombre de fonctionnalités partagées avec Cas.
  • quantumnous/new-apiAvatar de QuantumNous

    QuantumNous/new-api

    39,722Voir sur GitHub↗

    This project is an AI model API gateway and proxy server designed to provide a unified interface for interacting with diverse artificial intelligence service providers. It functions as a centralized middleware platform that routes, load balances, and translates API requests across multiple models, enabling developers to access text, image, audio, and video generation capabilities through a single, standardized integration. The gateway distinguishes itself through comprehensive administrative and financial controls, including event-driven usage accounting, real-time token consumption tracking,

    Goai-gatewayclaudedeepseek
    Voir sur GitHub↗39,722
  • kanidm/kanidmAvatar de kanidm

    kanidm/kanidm

    4,595Voir sur GitHub↗

    Kanidm is a centralized identity management server designed to handle authentication, authorization, and directory services across distributed infrastructure. It provides a comprehensive framework for managing human and service accounts, utilizing a schema-driven database to store identity records, group memberships, and system attributes. The platform supports a wide range of authentication methods, including passkeys, passwords, and standard protocols like OAuth2, OIDC, LDAP, and RADIUS. The system distinguishes itself through a granular access control engine that enforces security policies

    Rustauthenticationiamidentity
    Voir sur GitHub↗4,595
  • thinkgem/jeesiteAvatar de thinkgem

    thinkgem/jeesite

    8,044Voir sur GitHub↗

    Jeesite is a full-stack low-code development framework designed for building enterprise administrative portals using Spring Boot, MyBatis, and Vue. It functions as a comprehensive platform for creating administrative dashboards with integrated role-based access control and organizational data permission systems. The framework distinguishes itself through a combination of automated CRUD code generation and an integrated RAG platform that connects large language models to enterprise data via vector stores. It further incorporates a BPMN-based workflow engine to automate complex business process

    Vue
    Voir sur GitHub↗8,044
  • bitwarden/clientsAvatar de bitwarden

    bitwarden/clients

    13,114Voir sur GitHub↗

    This project is a comprehensive zero-knowledge security suite designed for enterprise credential management, secrets orchestration, and password management. It provides a secure, end-to-end encrypted vault that allows users to store, synchronize, and manage sensitive information, including passwords, passkeys, and infrastructure secrets, across desktop, mobile, and browser environments. The platform distinguishes itself through a strict zero-knowledge architecture where all encryption and decryption occur locally on the client, ensuring that plaintext data remains inaccessible to the server.

    TypeScriptangularbitwardenbrowser-extension
    Voir sur GitHub↗13,114
Voir les 30 alternatives à Cas→

Questions fréquentes

Que fait apereo/cas ?

This project is an open-source identity provider and single sign-on platform that centralizes user authentication for multiple web applications and services. It functions as a multi-protocol authentication gateway, verifying user identities and issuing tokens through the CAS protocol as well as industry standards including SAML, OAuth2, and OpenID Connect.

Quelles sont les fonctionnalités principales de apereo/cas ?

Les fonctionnalités principales de apereo/cas sont : Single Sign-On Solutions, User Authentication Systems, Distributed Session Caching, Identity, Attribute Release Policies, Client Registries, Authentication Gateways, Authentication Managers.

Quelles sont les alternatives open-source à apereo/cas ?

Les alternatives open-source à apereo/cas incluent : quantumnous/new-api — This project is an AI model API gateway and proxy server designed to provide a unified interface for interacting with… kanidm/kanidm — Kanidm is a centralized identity management server designed to handle authentication, authorization, and directory… thinkgem/jeesite — Jeesite is a full-stack low-code development framework designed for building enterprise administrative portals using… bitwarden/clients — This project is a comprehensive zero-knowledge security suite designed for enterprise credential management, secrets… aws/aws-cdk — The AWS Cloud Development Kit is an infrastructure-as-code framework that enables developers to define and provision… dexidp/dex — Dex is an OpenID Connect provider and identity federation proxy that translates authentication signals from various…