awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
kawhii avatar

kawhii/sso

0
View on GitHub↗
936 stars·422 forks·Java·MIT·16 viewskawhii.github.io/sso↗

Sso

This project is a centralized identity and access management platform that functions as a single source of truth for user authentication. It enables organizations to manage user sessions and enforce security policies across multiple connected client applications through a unified service.

The platform distinguishes itself by utilizing the Central Authentication Service protocol to facilitate secure identity exchange. It provides a dedicated management interface for registering client applications and defining specific access permissions, while also supporting integration with external social and professional identity providers for third-party sign-in capabilities.

The system includes comprehensive tools for operational oversight, such as a real-time dashboard for monitoring service health and performance metrics. It also offers extensive configuration management, allowing administrators to distribute environment variables and service settings from a central location to ensure consistent behavior across distributed components.

The software supports flexible deployment options, including packaging as a standalone executable archive or as a containerized service. It also provides options for customizing the visual branding of the authentication interface to meet specific organizational requirements.

Features

  • CAS Integrations - Functions as a centralized authentication platform that manages user sessions and service access using the CAS protocol.
  • Identity Providers - Acts as a centralized identity provider to manage user authentication and session state across multiple connected applications.
  • API Security Policy Enforcement - Secures user access and registration processes by applying custom validation logic, password encryption, and multi-factor verification methods.
  • Credential Encryption - Applies cryptographic hashing to passwords stored in database backends to ensure sensitive authentication data remains protected.
  • Identity and Access Management - Acts as a security framework that authenticates users and enforces access policies across multiple connected client applications.
  • User Account Security Controls - Protects sensitive user information by applying cryptographic hashing to passwords stored in relational databases.
  • User Authentications - Provides a unified single sign-on service to validate credentials and maintain active sessions across multiple applications.
  • Centralized Configuration Management - Centralizes service settings and environment variables to ensure consistent behavior across the platform.
  • Executable Packaging - Bundles the application and its dependencies into a self-contained executable archive for simplified deployment.
  • Containerized Service Deployments - Packages authentication and configuration components into standard container images for rapid and consistent deployment.
  • Centralized Configuration Storage - Distributes environment variables and service settings from a central location to ensure consistent behavior across distributed components.
  • Client Authentications - Connects security frameworks and client applications to the central identity provider for secure data exchange.
  • Password Hashing Utilities - Secures user credentials by applying cryptographic hashing algorithms before storage in database backends.
  • Access Control - Controls which applications are authorized to interact with the authentication server by defining and registering client access permissions.
  • AI Service Access Policies - Configures client integrations and access policies within a centralized identity ecosystem using a dedicated interface.
  • Request Rate Limiting - Protects system resources by monitoring traffic and enforcing request rate limits to prevent service abuse.
  • Social Authentication Providers - Supports user sign-in via external social and professional identity providers.
  • Third-Party Identity Integrations - Integrates external identity providers to facilitate secure third-party user authentication.
  • User Account Management - Manages user credentials, login sessions, and security settings through a centralized interface.
  • Environment Variable Managers - Maintains consistent environment variables and service parameters in a dedicated location for uniform system behavior.
  • Externalized Configurations - Decouples system settings from application code to enable consistent environment definitions across distributed components.
  • Service Configuration Management - Distributes application settings from a central service to ensure all components operate with consistent parameters.
  • Standardized Protocol-Based Integrations - Facilitates secure identity exchange between the authentication server and clients using established industry protocols.
  • System Health Monitoring - Tracks operational status and performance metrics of authentication services to ensure continuous system reliability and availability.
  • System Health Dashboards - Provides a real-time operational interface that tracks the health, performance metrics, and availability of authentication services.
  • Standalone Server Executables - Enables deployment as a standalone executable that runs independently without external servlet containers.

Star history

Star history chart for kawhii/ssoStar history chart for kawhii/sso

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with Sso

These projects share indexed features with Sso. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • teamhanko/hankoteamhanko avatar

    teamhanko/hanko

    8,801View on GitHub↗

    Hanko is an open-source identity provider and customer identity and access management system. It serves as a passkey authentication service and an OAuth and SAML SSO gateway, allowing applications to authenticate users and issue tokens via standard identity protocols. The project distinguishes itself through a strong focus on passwordless access using WebAuthn-based passkeys and email-based passcodes. It provides framework-agnostic authentication interfaces as customizable web components that can be embedded directly into web applications to handle login, registration, and profile management.

    Go2faauthenticationciam
    View on GitHub↗8,801
  • goauthentik/authentikgoauthentik avatar

    goauthentik/authentik

    22,035View on GitHub↗

    Authentik is a centralized identity and access management platform designed to serve as a unified authentication authority. It enables enterprise single sign-on across diverse applications and services, providing a cloud-native identity provider that manages user sessions and security protocols from a single location. The platform distinguishes itself through a policy-driven flow engine and a visual orchestration interface. This allows administrators to design complex, custom authentication workflows by chaining modular verification stages and conditional logic. These workflows can be further

    Pythonauthenticationauthentikauthorization
    View on GitHub↗22,035
  • kanidm/kanidmkanidm avatar

    kanidm/kanidm

    4,595View on GitHub↗

    Kanidm is a centralized identity management server designed to handle authentication, authorization, and directory services across distributed infrastructure. It provides a comprehensive framework for managing human and service accounts, utilizing a schema-driven database to store identity records, group memberships, and system attributes. The platform supports a wide range of authentication methods, including passkeys, passwords, and standard protocols like OAuth2, OIDC, LDAP, and RADIUS. The system distinguishes itself through a granular access control engine that enforces security policies

    Rustauthenticationiamidentity
    View on GitHub↗4,595
  • pennersr/django-allauthpennersr avatar

    pennersr/django-allauth

    10,342View on GitHub↗

    django-allauth is a comprehensive authentication framework for Django applications that manages user registration, account ownership verification, and secure login processes. It provides a system for handling the entire user account lifecycle, including the ability to define custom signup fields and implement identity verification. The project distinguishes itself by providing a suite of OAuth and SAML integrations for social account authentication and the capability to act as an OpenID Connect identity provider. It further supports decoupled architectures through a token-based headless authe

    Pythonaccountsauthenticationdjango
    View on GitHub↗10,342
Compare all 30 related projects→

Frequently asked questions

What does kawhii/sso do?

This project is a centralized identity and access management platform that functions as a single source of truth for user authentication. It enables organizations to manage user sessions and enforce security policies across multiple connected client applications through a unified service.

What are the main features of kawhii/sso?

The main features of kawhii/sso are: CAS Integrations, Identity Providers, API Security Policy Enforcement, Credential Encryption, Identity and Access Management, User Account Security Controls, User Authentications, Centralized Configuration Management.

Which projects share features with kawhii/sso?

Projects with overlapping indexed features include: teamhanko/hanko — Hanko is an open-source identity provider and customer identity and access management system. It serves as a passkey… goauthentik/authentik — Authentik is a centralized identity and access management platform designed to serve as a unified authentication… kanidm/kanidm — Kanidm is a centralized identity management server designed to handle authentication, authorization, and directory… pennersr/django-allauth — django-allauth is a comprehensive authentication framework for Django applications that manages user registration,… systemd/systemd — systemd is a comprehensive system and service manager for Linux that orchestrates the entire operating system… symfony/security — This project is a comprehensive security framework for PHP applications, providing a modular system for verifying user…

Curated searches featuring Sso

Hand-picked collections where Sso appears.
  • Directory administration tools