Casdoor
Casdoor is an open source identity and access management platform you can self-host — an Auth0 and Okta alternative that delivers single sign-on, OAuth 2.0, OIDC, SAML, and social login through a UI-first admin console.
What is Casdoor?
Casdoor is an open source identity and access management (IAM) and single sign-on server that handles login, user management, and authorization for your apps. Written in Go with a React admin console, it is a full identity provider — it stores your user directory, issues tokens, and exposes OAuth 2.0, OIDC, SAML, CAS, LDAP, and SCIM from one place.
What is Casdoor best for?
Casdoor is best for teams that want a self-hosted SSO server they can configure through a web UI rather than config files or Terraform. Its UI-first admin console lets you set up organizations, applications, providers, and access rules without redeploying, which suits small platform teams unifying several apps behind one login and organizations that need SAML and social login on a light footprint.
What can Casdoor do?
- Multi-protocol SSO — OAuth 2.0, OIDC, SAML 2.0, CAS, LDAP, and SCIM 2.0 from a single server, so legacy and modern apps share one user base.
- 100+ social and enterprise providers — Google, GitHub, Apple, LinkedIn, WeChat, plus email and SMS one-time codes out of the box.
- Passwordless and MFA — WebAuthn/passkeys, TOTP, and face-based biometric login.
- Multi-tenancy — independent organizations with per-org branding, users, and providers.
- Access control — role-based and attribute-based rules (RBAC/ABAC) powered by the Casbin engine.
- UI-first administration — manage users, apps, roles, and audit logs from the React console; every action also has a REST API.
- Deploy anywhere — Docker all-in-one, Docker Compose, or Kubernetes via Helm, backed by MySQL, PostgreSQL, SQLite, or SQL Server.
Where does Casdoor fall short?
Machine-to-machine authentication is less complete than in Keycloak: independent comparisons rate Casdoor as covering fewer client-credentials and service-account scenarios, so backend-only token flows can need more manual wiring.
Its documentation and community are also smaller than Keycloak’s or Authentik’s, so you will find fewer third-party guides and worked examples when you hit an edge case. And recent releases lean heavily into AI-agent and MCP features — useful if you want them, but added surface area to understand if all you need is plain SSO.
Is Casdoor free?
Yes — Casdoor is free and open source under the Apache 2.0 license, and self-hosting the full server costs nothing for the software. There is no open-core paywall on core IAM features; you run it on your own database and infrastructure. Commercial and enterprise support is offered separately for teams that want it, with pricing arranged directly.
What does Casdoor replace?
Casdoor is a self-hostable stand-in for hosted identity providers — an Auth0 alternative, an Okta alternative, a Microsoft Entra ID alternative, and an Amazon Cognito alternative. It covers the same core ground — SSO, social and enterprise login, MFA, and user management — while keeping your user data and deployment under your control. Among open source options it competes most directly with Keycloak, Authentik, and Zitadel.
FAQ
Is Casdoor open source? Yes. The full server is on GitHub under the Apache 2.0 license, one of the most permissive open source licenses, with no paywalled core features.
Can I self-host Casdoor for free? Yes. Self-hosting is free under Apache 2.0. You provide the infrastructure — Casdoor plus a database such as MySQL, PostgreSQL, or SQLite — via Docker, Docker Compose, or Kubernetes, and pay only for hosting.
Is Casdoor a good Auth0 alternative? For teams that want to own their identity data and configure SSO through a web UI, yes — it delivers OAuth 2.0, OIDC, SAML, social login, and MFA. Auth0 still leads on breadth of prebuilt integrations, marketplace extensions, and fully managed operations.
What do I need to run Casdoor? A supported database (MySQL, PostgreSQL, SQLite, or SQL Server) and a container runtime such as Docker or Kubernetes. Redis is optional and only needed for multi-instance deployments.