casdoor/casdoor

▲ 10 stars today★ 14,546⑂ 1,840

An open-source Agent-first Identity and Access Management (IAM) /LLM MCP & agent gateway and auth server with web UI supporting OpenClaw, MCP, OAuth, OIDC, SAML, CAS, LDAP, SCIM, WebAuthn, TOTP, MFA

About casdoor/casdoor

casdoor/casdoor is an open-source project on GitHub, mainly written in Go. An open-source Agent-first Identity and Access Management (IAM) /LLM MCP & agent gateway and auth server with web UI supporting OpenClaw, MCP, OAuth, OIDC It currently holds 14,546 stars and 1,840 forks with 0 open issues, and was last pushed on an unknown date (repository created unknown).

Project Overview

AI Homed tracks it on the Today's Trending board, currently at rank #58 with 10 new stars today.

GitHub Repository Details

Repository casdoor/casdoor · default branch - · size 0 KB · watchers 0 · source: GitHub REST API and repository README

README

https://github.com/casdoor/casdoor/blob/HEAD/Casdoor

An open-source, self-hosted identity and access management platform

Casdoor is a single sign-on (SSO) and authentication server with a web console.
It speaks OAuth 2.0, OIDC, SAML 2.0, CAS, LDAP, SCIM 2.0, WebAuthn, TOTP/MFA and MCP,
and connects to Google Workspace, Microsoft Entra ID (Azure AD), GitHub and many other identity providers.

Website · Documentation · Live demo · Casdoor Cloud · Discord

https://github.com/casdoor/casdoor/blob/HEAD/Release https://github.com/casdoor/casdoor/blob/HEAD/Docker Pulls https://github.com/casdoor/casdoor/blob/HEAD/Build Status https://github.com/casdoor/casdoor/blob/HEAD/golangci-lint https://github.com/casdoor/casdoor/blob/HEAD/OpenSSF Best Practices https://github.com/casdoor/casdoor/blob/HEAD/Discord https://github.com/casdoor/casdoor/blob/HEAD/License

https://github.com/casdoor/casdoor/blob/HEAD/casdoor%2Fcasdoor | Trendshift

https://github.com/casdoor/casdoor/blob/HEAD/Casdoor sign-in page with password, code, WebAuthn and Face ID tabs and social login icons

The sign-in page your users see: password, email/SMS code, WebAuthn and Face ID, plus every social provider you enable.

https://github.com/casdoor/casdoor/blob/HEAD/Casdoor admin console dashboard with user, application and provider statistics Admin console. Users, tokens, organizations and providers at a glance. https://github.com/casdoor/casdoor/blob/HEAD/Casdoor applications list showing several applications with their organizations and providers Applications. Every app that delegates login to Casdoor, across all organizations. https://github.com/casdoor/casdoor/blob/HEAD/Casdoor application settings, Providers tab, with per-provider signup, signin and unlink toggles Application settings. OAuth, SAML, providers and branding — no redeploy, no config file.

❤️ Sponsors

Want to appear here?
https://github.com/casdoor/casdoor/blob/HEAD/APIMart Thanks to APIMart for sponsoring this project! APIMart is a low-cost API platform for AI image & video generation — GPT-Image-2 from $0.006/image, 160+ images per dollar. One async API covers both image and video: submit a task, get an ID, fetch results via polling or callback. Batch tens of thousands of images without timeouts, switch models without changing code. Pay-as-you-go with no monthly fee — sign up here to get started.

🚀 Try it in 30 seconds

No database and no config file needed. This runs Casdoor on SQLite with sample data:

docker run -p 8000:8000 casbin/casdoor-all-in-one

Open and sign in:

| Field | Value | |-------|-------| | Organization | built-in | | Username | admin | | Password | 123 |

The sign-in form has separate organization and username fields. Docs sometimes write this pair as built-in/admin — that is the same thing, not a username containing a slash.

Prefer not to install anything? Use the hosted demos:

| Demo | URL | Notes | |------|-----|-------| | Writable | demo.casdoor.com | Full access, so you can click through everything. All data resets about every 5 minutes. | | Read-only | door.casdoor.com | Stable global demo. Every write operation fails by design. |

Both accept the same built-in / admin / 123 credentials.

Want it hosted for production instead? Casdoor Cloud runs a dedicated Casdoor instance and database for you, kept up to date by the Casdoor team. It is the same open-source Casdoor, so you can move between Cloud and self-hosting at any time. New accounts get $20 in free credit to try it, so you can start a free trial without talking to anyone.

🤔 Why Casdoor

Casdoor is a complete identity provider, not an authentication proxy and not a library you embed. It stores your users, issues the tokens, and gives you an admin console to manage all of it — so your applications can delegate login entirely and never handle a password themselves.

If all you need is a login screen in front of an existing reverse proxy, a smaller tool may suit you better. Casdoor is for when you want to own the user directory itself.

Coming from another product? See how Casdoor compares with Keycloak, Auth0, Okta and others.

📦 Installation

Four supported paths, fastest first. All of them end up at .

Rather not run the server, database and upgrades yourself? Casdoor Cloud gives you a dedicated Casdoor instance in the region you choose, with flat monthly pricing and no per-user fees.

Docker — all-in-one (evaluation)

docker run -p 8000:8000 casbin/casdoor-all-in-one

Bundles SQLite and demo data into a single container. Ideal for a first look, but not intended for production: the data lives inside the container and disappears with it.

Guide: Try with Docker

Docker Compose — Casdoor with MySQL

docker-compose.yml starts Casdoor next to a MySQL 8 container.

Two things to know before running it:
> 1. Compose builds the image from source (Go backend plus React frontend). The first docker compose up takes several minutes, so it is not the quick-trial path — use the all-in-one image above for that.
2. You have to point Casdoor at the bundled database first.

Set the MySQL settings in conf/app.conf to match the db service:

driverName = mysql
dataSourceName = root:123456@tcp(localhost:3306)/
dbName = casdoor

Use localhost here even though MySQL runs in a separate container: the compose file sets RUNNING_IN_DOCKER=true, and Casdoor rewrites localhost to the Docker host address at startup (see conf/conf.go). Then start everything:

docker compose up

The compose entrypoint already passes --createDatabase=true, so the casdoor database is created for you.

Guide: Try with Docker

Kubernetes — Helm

Requires Helm v3 and a running cluster:

helm install casdoor oci://ghcr.io/casdoor/helm-charts/casdoor

The chart does not expose Casdoor outside the cluster by default. To reach it, find the service and forward a port:

kubectl get svc
kubectl port-forward svc/ 8000:8000

For a real deployment, configure an Ingress and an external database through the chart's values. k8s.yaml in this repo is a minimal plain-manifest example if you would rather not use Helm.

Guide: Try with Helm · Chart on Artifact Hub

Configuration as code

Organizations, applications, users, providers, roles and permissions can be kept in Git instead of being clicked together in the UI:

From source — for development

Use this if you intend to modify Casdoor. Prerequisites: Go 1.25+ (see go.mod), Node.js 20 LTS, Yarn 1.x, and a supported database (MySQL, PostgreSQL, SQLite, SQL Server and others).

git clone https://github.com/casdoor/casdoor.git
cd casdoor

Set driverName, dataSourceName and dbName in conf/app.conf. For MySQL, create the casdoor database first, or start the server with --createDatabase=true. Then build the frontend and run the server:

cd web && yarn install && yarn build && cd .. && go run main.go

While working on the frontend, run yarn start in web/ instead of yarn build to get hot reload on port 7001, with go run main.go serving the API from a second terminal.

Guide: Server installation

👉 After you sign in

At this point you have a running identity provider with nothing connected to it yet. Next:

1. Change the admin password. 123 is a demo credential and must not survive contact with production. 2. Connect your first application — create an Application in the console, copy its Client ID and Client Secret, and point your app's OAuth/OIDC client at Casdoor. 3. Add an identity provider if you want Google, GitHub or Entra ID sign-in. 4. Pick an SDK for your language, or call the Public API directly.

✨ Features

🔐 Authentication

🏢 Organizations and access control 🤖 AI and agents 🛠️ Developer experience

🧱 Technology stack

Casdoor is a frontend–backend separated application:

📖 Documentation

The full documentation lives at casdoor.ai/docs. Common starting points:

| I want to… | Go to | |------------|-------| | Install Casdoor | From source · Docker · Helm | | Connect my application | How to connect to Casdoor | | Use the API | Public API · Swagger UI | | Choose an SDK | Integrations | | Deploy to production | Deployment | | Upgrade from v3 to v4 | Upgrading from v3 to v4 |

🔌 SDKs and integrations

Official SDKs and framework integrations, by language:

The complete list, including reverse proxies and third-party applications, is in the Integrations documentation.

🔒 Security

Please do not report security vulnerabilities in public GitHub issues. Email instead — SECURITY.md has the full policy and disclosure process.

Before exposing a Casdoor instance to the internet:

🤝 Community and support

🌍 Contributing

Contributions are welcome. For anything larger than a small fix, please open an issue first so you can agree on the approach with the maintainers before writing code.

Read the contribution guidelines before you start.

Translations. User-facing strings in the web console go through i18next. When you add or change one under web/, update the English catalog at web/src/locales/en/data.json. The other languages are translated on Crowdin and should not be edited by hand.

🙌 Support Casdoor

Casdoor is free and open source. If it saves you time, consider supporting its development on Open Collective. Choosing Casdoor Cloud for hosting also funds the project directly.

https://github.com/casdoor/casdoor/blob/HEAD/Sponsors on Open Collective

https://github.com/casdoor/casdoor/blob/HEAD/Backers on Open Collective

📄 License

Casdoor is licensed under the Apache License 2.0.

---

If Casdoor is useful to you, a star helps other people find it.

https://github.com/casdoor/casdoor/blob/HEAD/GitHub Stars

© 2026 Casdoor · Apache License 2.0

GitHub Stars & Activity

14,546Stars
1,840Forks
0Open issues
GoLanguage

GitHub Popularity

GitHub stars14,546
Forks1,840
Open issues0
Primary languageGo
License-
Stars gained today10
Created-
Last pushed-

Trending History

Daily boardrank #58 · ▲ 10 stars

Related AI Projects

1

ollama / ollama

Go★ 182,635⑂ 0
→
2

infiniflow / ragflow

Go★ 91,959⑂ 10,948▲ 58 stars
→
3

QuantumNous / new-api

Go★ 49,664⑂ 11,934▲ 136 stars
→
4

alibaba / open-code-review

Go★ 45,834⑂ 3,311▲ 970 stars
→
5

Wei-Shaw / sub2api

Go★ 43,649⑂ 9,369▲ 90 stars
→
6

Tencent / WeKnora

Go★ 33,026⑂ 4,392▲ 215 stars
→
7

vxcontrol / pentagi

Go★ 25,433⑂ 3,276▲ 47 stars
→
8

larksuite / cli

Go★ 17,610⑂ 1,390▲ 28 stars
→

More AI Rankings