awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
kanidm avatar

kanidm/kanidm

0
View on GitHub↗
4,595 stars·290 forks·Rust·mpl-2.0·15 viewskanidm.com↗

Kanidm

Kanidm is a centralized identity management server designed to handle authentication, authorization, and directory services across distributed infrastructure. It provides a comprehensive framework for managing human and service accounts, utilizing a schema-driven database to store identity records, group memberships, and system attributes. The platform supports a wide range of authentication methods, including passkeys, passwords, and standard protocols like OAuth2, OIDC, LDAP, and RADIUS.

The system distinguishes itself through a granular access control engine that enforces security policies based on user, group, and resource attributes. It incorporates advanced security features such as privilege access mode enforcement, which requires reauthentication for sensitive operations, and high-privilege group tainting to prevent lateral movement. Administrators can delegate management tasks for specific entries or groups, ensuring that permissions remain tightly scoped while maintaining operational flexibility.

Beyond core identity functions, the platform includes robust tools for system maintenance, including automated backup scheduling, database consistency verification, and multi-node replication to ensure high availability. It also provides deep integration with host operating systems through pluggable authentication modules and supports infrastructure access provisioning by managing SSH keys and POSIX attributes.

The project provides a suite of command-line utilities for administrative tasks, session management, and server configuration. Documentation and installation resources are available to guide the deployment of the server and its associated client tools.

Features

  • Attribute-Based Access Control - Enforces security by evaluating granular rules against user, group, and resource attributes to determine authorization for specific operations.
  • Access Control - IdentityServer defines access control rules by assigning permissions to users, service accounts, and groups to specify who can perform write operations.
  • Identity and Access Management Servers - Provides a centralized platform for managing identities, credentials, and access policies across infrastructure.
  • Identity Providers - Verifies user identities through multiple protocols including passkeys, passwords, and OAuth2.
  • Identity Synchronization - Extracts and synchronizes user identity data from external sources to maintain consistency across systems.
  • OAuth2 Client Management - Registers and manages OAuth2 client integrations including scopes, redirect URLs, and display names.
  • Role-Based Access Controls - IdentityServer defines granular permissions and security policies to restrict user and service access to specific database entities.
  • Step-up Authentication - IdentityServer allows reauthentication within an existing session to temporarily increase privileges for sensitive operations using the original authentication credential.
  • Session Management - Manages authentication sessions, cookies, and persistent login states to maintain user access.
  • User Account Management - Manages the full lifecycle of human user accounts, including identity attributes and access permissions.
  • OIDC Authentication Integrations - Secures services by implementing standard OAuth2 and OIDC authentication flows and token management.
  • User Group Management - Provides comprehensive tools for creating and managing user groups and their membership attributes.
  • Access Control Engines - Enforces granular permissions and privilege boundaries for users and automated systems.
  • Account Lifecycle Management - Ensures permanent removal of all user data from the system upon account deletion.
  • Authentication Enforcement Policies - IdentityServer configures authentication methods including passkeys and password-plus-TOTP, applying specific security policies to each type of credential.
  • Centralized Identity Management - Consolidates authentication policies across multiple protocols including OIDC, OAuth2, RADIUS, and LDAP.
  • Identity & Key Management - IdentityServer secures identity access by managing passkeys, tokens, and SSH keys within a domain-based key infrastructure for authentication and authorization.
  • Role-Based Access Control - Enforces granular permissions and separation of duties through role-based access control.
  • Credential Management Tools - IdentityServer manages credentials for individuals through onboarding, resets, and self-service operations to maintain secure access control.
  • Service Account Management - Provides full lifecycle management for service account API tokens, including generation and revocation.
  • User Authentication Strategies - Verifies user identities through multi-step authentication processes to issue secure session tokens.
  • User Identity Management - IdentityServer enables users to update their display names at any time through self-service tools to support personal autonomy and safety in changing life circumstances.
  • Data Replication - Synchronizes identity data across multiple server nodes to ensure high availability and consistent access.
  • Database Backups - Preserves database state by creating full volume snapshots of the data directory.
  • Schema-Driven Data Modeling - IdentityServer organizes identity records into a structured database that supports referential integrity, indexing, and automated consistency verification for high performance.
  • Request Processing - Handles the lifecycle of identity management requests through a centralized routing and transformation architecture.
  • Account Recovery - IdentityServer generates credential reset tokens or QR codes to allow users to securely enroll their own credentials during onboarding or recovery.
  • System Integrations - Connects with host operating systems to verify user credentials and resolve identities through standard system-level authentication stacks.
  • Identity Synchronization - IdentityServer establishes a secure binding between an external identity management system and the local instance to enable the import and synchronization of user data.
  • Cryptographic Key Management - Organizes and manages cryptographic keys by provider to support rotation and security domain isolation.
  • Identity Management - Caches network credentials and manages local home directories for system access.
  • Identity Domain Management - IdentityServer configures a dedicated domain name for identity services to prevent security risks like credential phishing and cross-origin cookie conflicts.
  • Identity Provider Backends - Resolves user and group identities across multiple backends with support for offline caching and hardware security.
  • Identity Provider Integrations - Configures system services to resolve user accounts and SSH keys via LDAP protocols.
  • Connection Configurations - Configures LDAP directory connections with bind addresses and TLS certificates for secure communication.
  • Public Clients - Registers public OAuth2 clients using PKCE protocols for secure session handling.
  • Access Policies - IdentityServer restricts the anonymous account from using external authentication protocols to ensure it functions strictly as a limited-access service account.
  • Enforcement Policies - IdentityServer requires reauthentication for sensitive write operations within a session to enhance security through privilege escalation mechanisms.
  • Privileged Access Management - IdentityServer requires users to reauthenticate before accessing high-level permissions, ensuring that elevated privileges remain active only for a short, controlled period.
  • SSH Key Management - Provides command-line tools to manage, validate, and revoke SSH public keys for user accounts.
  • Access Restrictions - Restricts access to sensitive legal name data to protect user privacy and prevent harassment.
  • User Group Management - Allows delegating administrative control over specific user groups to designated managers.
  • Asynchronous Request Processing - Handles identity management operations using a centralized server architecture that routes logic and transforms data for client applications.
  • Password Re-authentication - Verifies sensitive actions by requiring credential re-authentication and tracking escalation metadata.
  • Password and MFA Management - Offers a fast, secure platform for identity management.
  • Automated Backup Systems - Schedules automated database backups and manages retention policies for data snapshots.
  • Backup & Recovery - Provides command-line utilities for manual database backup and point-in-time restoration.
  • Replication Protocols - Coordinates state and configuration updates across distributed nodes using a central authority.
  • Replication Strategies - Maintains data consistency across distributed server instances by synchronizing state through periodic updates and conflict resolution strategies.
  • Account Management - IdentityServer categorizes identity entities into person accounts for humans and service accounts for automated systems, each with distinct authentication properties.
  • Anonymous Authentication - IdentityServer authenticates stateless clients without credentials using a special anonymous method to establish a session for limited read access.
  • Authentication Service Integrations - Integrates remote authentication by modifying pluggable authentication modules to evaluate login requests.
  • Client Credentials - Facilitates the request of short-term security credentials for authenticated machines.
  • Directory Services - Maintains a hierarchical database of identity records, group memberships, and system attributes.
  • Device and Connection Authorization - Authorizes device sessions through verification workflows to grant hardware-specific permissions.
  • Session and Credential Management - IdentityServer invalidates all active sessions associated with a specific credential immediately upon its removal from the system.
  • Identity Synchronization Services - Integrates external identity sources and maintains consistent user data across network nodes.
  • LDAP Services - Provides a read-only directory interface for legacy applications to search and bind to identity data.
  • Password Management - Maintains a blacklist of compromised passwords to prevent insecure credential selection.
  • Secrets and Credential Management - Generates and manages RADIUS secrets to enable network authentication via MSCHAPv2 or EAP-TLS.
  • Reuse Detection - Detects unauthorized refresh token reuse to invalidate sessions and enforce re-authentication.
  • LDAP Authentication - Supports legacy authentication by providing standard directory interfaces like LDAP and RADIUS.
  • Conflict Resolution Strategies - Resolves data inconsistencies during replication using reconciliation strategies to ensure uniform state.
  • Data Replication Strategies - Balances data consistency and availability by managing a network of read-write and read-only server replicas.
  • Database Indexing Tools - IdentityServer recreates all database indexes based on current schema definitions to optimize query performance after schema changes or missing index logs.
  • Protocol Gateways - Exposes identity data through standard network interfaces like LDAP and RADIUS to support integration with existing enterprise applications and services.
  • Hierarchical Grouping - IdentityServer organizes accounts into groups to simplify privilege assignment, supporting nested hierarchies to manage permissions across large systems efficiently.
  • Validity Policies - Enforces specific start and expiry timestamps for account authentication.
  • Deletion Access Controls - Governs the authorization logic for deleting data objects based on scope and conditions.
  • Dynamic Access Groups - Manages dynamic group memberships based on automated filter queries for flexible organization.
  • Session Management Policies - Applies distinct expiry policies and permission scopes to service accounts and individual user sessions.
  • Enrollment Management - Registers machines using auditable join tokens to embed security policies during enrollment.
  • Redirect Validation - Supports native application redirect URLs while enforcing mandatory PKCE security.
  • Group-Based - Simplifies security administration by defining access rules using group-based targets.
  • Identity Attribute Overrides - IdentityServer grants local edit permissions for specific synchronised attributes to override the default authority held by the external identity provider.
  • Instance Configuration Managers - IdentityServer switches between multiple server instances by defining separate configurations and selecting the active instance via environment variables or flags.
  • Tracing Configuration - IdentityServer configures trace exports by setting server configuration options to send observability data to a remote collector via network protocols.
  • Branding Customization - Enables white-labeling of the identity server by customizing site names and logos.
  • Linux Authentication - IdentityServer integrates with host operating systems to verify user credentials and resolve identities through standard system-level authentication stacks.
  • Differential Synchronization - Updates data between nodes using incremental differential updates to minimize bandwidth usage.
  • Schema-Driven Storage - Organizes identity records into a structured database that supports referential integrity and automated consistency verification for high performance.
  • Soft Deletion Mechanisms - IdentityServer manages deleted entries by listing, inspecting, and reviving them from the recycle bin to recover from accidental deletions.
  • Command Line Administration Tools - Provides command-line utilities for managing server installations and administrative tasks.
  • Container Deployment - Deploys RADIUS services via containers with pre-configured cryptographic certificates and authentication rules.
  • Security Profiles - Defines security profiles that enforce restrictive access rules on database records.
  • Group Membership Management - Supports hierarchical group structures where membership in child groups propagates to parent groups.
  • Access Provisioning - Automates the distribution of SSH keys and POSIX attributes for infrastructure access.
  • Consent Bypasses - Bypasses interactive user consent screens for trusted enterprise OAuth2 clients.
  • Constraint Resolution - Automatically selects the strictest security constraints when multiple policies conflict.
  • Device-Bound Restrictions - Requires cryptographic device credentials alongside user login to restrict Unix access.
  • Identity Token Services - Provides asynchronous, typed interfaces for managing authentication and token retrieval.
  • Token Invalidation - Ensures session security by automatically invalidating inactive or expired refresh tokens.
  • Entity Delegations - IdentityServer permits the delegation of management for specific entries to designated users, granting write access to individual entities without providing broad permissions.
  • Debug Logging Management - Enables targeted debug logging and operation tracking to correlate client-side failures with server-side execution.

Star history

Star history chart for kanidm/kanidmStar history chart for kanidm/kanidm

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to Kanidm

Similar open-source projects, ranked by how many features they share with Kanidm.
  • casdoor/casdoorcasdoor avatar

    casdoor/casdoor

    13,814View on GitHub↗

    Casdoor is a centralized identity and access management platform that functions as an OAuth 2.0 authorization server. It provides a comprehensive suite of services for managing user identities, authentication sessions, and access policies across both web and machine-to-machine applications. Built with a decoupled frontend-backend architecture in Go, the platform supports high-concurrency environments and offers a web-based management interface for administrative tasks. The platform distinguishes itself through its extensive support for federated identity management, allowing integration with

    Goai-gatewayauthauthentication
    View on GitHub↗13,814
  • octelium/octeliumoctelium avatar

    octelium/octelium

    3,371View on GitHub↗

    Octelium is a zero-trust network access platform and identity-aware proxy designed to secure private HTTP, SSH, and SQL resources. It functions as a secure gateway that validates human and workload identities using OIDC, SAML, and FIDO2 passkeys before granting access to internal applications and SaaS APIs. The system is distinguished by its secretless access broker, which injects credentials—such as API keys, passwords, and AWS Sigv4 signatures—at the gateway level so users can access databases and cloud resources without managing secrets. It further specializes in AI gateway administration,

    Goabacai-gatewayapi-gateway
    View on GitHub↗3,371
  • apereo/casapereo avatar

    apereo/cas

    11,347View on GitHub↗

    This project is an open-source identity provider and single sign-on platform that centralizes user authentication for multiple web applications and services. It functions as a multi-protocol authentication gateway, verifying user identities and issuing tokens through the CAS protocol as well as industry standards including SAML, OAuth2, and OpenID Connect. The system acts as a federated identity server, allowing authentication to be delegated to external third-party or corporate identity providers. It distinguishes itself through identity attribute governance, which manages which specific use

    Javaauthenticationauthorizationaws
    View on GitHub↗11,347
  • maiot-io/zenmlmaiot-io avatar

    maiot-io/zenml

    5,452View on GitHub↗

    ZenML is an extensible machine learning orchestration framework designed to manage the end-to-end lifecycle of data pipelines and AI agent workflows. It functions as a durable orchestrator that executes machine learning tasks as directed acyclic graphs, ensuring that every step is containerized for consistent performance across local, cloud, and hybrid infrastructure. By decoupling pipeline code from underlying compute and storage backends, the platform allows developers to define infrastructure-agnostic stacks that remain portable across diverse environments. The project distinguishes itself

    Python
    View on GitHub↗5,452
See all 30 alternatives to Kanidm→

Frequently asked questions

What does kanidm/kanidm do?

Kanidm is a centralized identity management server designed to handle authentication, authorization, and directory services across distributed infrastructure. It provides a comprehensive framework for managing human and service accounts, utilizing a schema-driven database to store identity records, group memberships, and system attributes. The platform supports a wide range of authentication methods, including passkeys, passwords, and standard protocols like OAuth2, OIDC,…

What are the main features of kanidm/kanidm?

The main features of kanidm/kanidm are: Attribute-Based Access Control, Access Control, Identity and Access Management Servers, Identity Providers, Identity Synchronization, OAuth2 Client Management, Role-Based Access Controls, Step-up Authentication.

What are some open-source alternatives to kanidm/kanidm?

Open-source alternatives to kanidm/kanidm include: casdoor/casdoor — Casdoor is a centralized identity and access management platform that functions as an OAuth 2.0 authorization server.… octelium/octelium — Octelium is a zero-trust network access platform and identity-aware proxy designed to secure private HTTP, SSH, and… apereo/cas — This project is an open-source identity provider and single sign-on platform that centralizes user authentication for… maiot-io/zenml — ZenML is an extensible machine learning orchestration framework designed to manage the end-to-end lifecycle of data… teamhanko/hanko — Hanko is an open-source identity provider and customer identity and access management system. It serves as a passkey… gam-team/gam — GAM is a command-line tool for administering Google Workspace and Cloud Identity. It translates command-line arguments…