PandaAuth product icon

PandaAuthReleased · Open source

Every login is trust on your terms.

Released · Open source · for product teams, hello@pandalabs.cc

Identity foundation

The shared identity foundation across the PandaLabs ecosystem

Unified sign-on

Standard protocols (OIDC), SSO and an account center; sign in once, pass everywhere

Authorization & security

Least-privilege authorization, account security built in; password changes and freezes revoke tokens in bulk, instantly

Auditable

Authentication and authorization you can audit end to end, with one security policy

SDK integration

Self-service onboarding inside the ecosystem; integrate once, reuse identity — with strict redirect allowlists

Security baseline

No convenience at the cost of security — production-ready defaults

Standard protocols

OIDC authorization code + PKCE, client credentials and refresh tokens; the password grant is disabled by default.

Short-lived tokens

10-minute access tokens with refresh-token rotation keep any leak window minimal.

Password & sign-in hardening

Argon2id password hashing, sign-in rate limiting and audit — anomalies can be acted on instantly.

Key rotation

Automatic JWKS key rotation, HTTPS enforced everywhere.

Where it sits

One identity service for Panda Assistant and Oasis, also available to outside product teams

One identity, ecosystem-wide

Panda Assistant, Oasis and what comes next share sign-on, authorization and audit

For outside product teams

Self-hosted CIAM: your deployment, your data

Standard-protocol core

OIDC / OAuth 2.0 · ASP.NET Core · OpenIddict

One integration, identity reused ecosystem-wide

PandaAuth v1.0.0 is officially released and open source: the product site offers docs, live status and a changelog. Integration talks with product teams continue — write about your product and scenario, and we reply to every message.

Integration docs live on the product site; a test environment is provided during the talks.