PandaAuth product icon

PandaAuthReleased · Open source

Every login is trust on your terms.

Self-hosted identity services for product teams: sign-in, authorization and account management, with identity data under the deployer’s control.

Community Preview 0.2.0-preview.1 · Currently a community preview

For product teams that need control over identity

PandaAuth serves .NET product teams, ISVs and applications that need self-hosted identity. OIDC/OAuth 2.0 supports first-party applications and service-to-service access. Deployment, operations and preparation for production remain the deployer’s responsibility.

Sign-in and account management

Sign-in, authorization and account management over standard protocols

Unified sign-on

Standard protocols (OIDC), single sign-on and an account center for connected applications

Authorization & security

Least-privilege authorization, account security built in; password changes and account freezes revoke related tokens

Auditable

Authentication and authorization you can audit end to end, with one security policy

SDK integration

Integrate applications through the SDK, with an explicit allowlist for redirect addresses

Interface illustration

Security baseline

Configure identity services against a clear security baseline

Standard protocols

OIDC authorization code + PKCE, client credentials and refresh tokens; the password grant is disabled by default.

Short-lived tokens

10-minute access tokens with refresh-token rotation limit how long exposed tokens remain usable.

Password & sign-in hardening

Argon2id password hashing, sign-in rate limiting and audit — helps identify and track unusual sign-in activity.

Key rotation

Automatic JWKS key rotation, HTTPS enforced everywhere.

Security & trust

Verifiable security design facts and an honest compliance statement — nothing exaggerated, nothing omitted.

  • Self-hosted by design: identity data lives in the deployer’s own servers and databases; operational security of an instance (hardening, backups, key custody) belongs to the deployer
  • No SOC 2 or ISO/IEC 27001 certification, and no formal community security audit yet; no SLA during the preview
  • Security reports go through a private channel (hello@pandalabs.cc), never public issue trackers; no paid bug bounty is operated today
  • Website analytics follow a collect-the-minimum principle without advertising tracking cookies; see Privacy and analytics for data details and opt-out options

For different product teams

One identity service for Panda Assistant and Oasis, also available to outside product teams

For PandaLabs products

Sign-in, authorization and audit services for Panda Assistant and Oasis

For outside product teams

Self-hosted CIAM: your deployment, your data

Protocols and technology

OIDC / OAuth 2.0 · ASP.NET Core · OpenIddict

Roadmap & boundaries

Explore product direction and scope. Availability follows actual releases.

From a local trial to product integration

Start with the docs and Quickstart to explore self-hosting, or browse the open-source projects. The current suite is Community Preview 0.2.0-preview.1, without an SLA. Instance hardening, backups and key management are the deployer’s responsibility. Write to discuss your product and integration needs.

Integration docs are maintained on this site; a test environment is provided during the talks.