PandaAuthReleased · Open source
Every login is trust on your terms.
Released · Open source · for product teams, hello@pandalabs.cc
Identity foundation
The shared identity foundation across the PandaLabs ecosystem
Unified sign-on
Standard protocols (OIDC), SSO and an account center; sign in once, pass everywhere
Authorization & security
Least-privilege authorization, account security built in; password changes and freezes revoke tokens in bulk, instantly
Auditable
Authentication and authorization you can audit end to end, with one security policy
SDK integration
Self-service onboarding inside the ecosystem; integrate once, reuse identity — with strict redirect allowlists
Security baseline
No convenience at the cost of security — production-ready defaults
Standard protocols
OIDC authorization code + PKCE, client credentials and refresh tokens; the password grant is disabled by default.
Short-lived tokens
10-minute access tokens with refresh-token rotation keep any leak window minimal.
Password & sign-in hardening
Argon2id password hashing, sign-in rate limiting and audit — anomalies can be acted on instantly.
Key rotation
Automatic JWKS key rotation, HTTPS enforced everywhere.
Where it sits
One identity service for Panda Assistant and Oasis, also available to outside product teams
One identity, ecosystem-wide
Panda Assistant, Oasis and what comes next share sign-on, authorization and audit
For outside product teams
Self-hosted CIAM: your deployment, your data
Standard-protocol core
OIDC / OAuth 2.0 · ASP.NET Core · OpenIddict
One integration, identity reused ecosystem-wide
PandaAuth v1.0.0 is officially released and open source: the product site offers docs, live status and a changelog. Integration talks with product teams continue — write about your product and scenario, and we reply to every message.
Integration docs live on the product site; a test environment is provided during the talks.