PandaAuthReleased · Open source
Every login is trust on your terms.
Self-hosted identity services for product teams: sign-in, authorization and account management, with identity data under the deployer’s control.
Community Preview 0.2.0-preview.1 · Currently a community preview
For product teams that need control over identity
PandaAuth serves .NET product teams, ISVs and applications that need self-hosted identity. OIDC/OAuth 2.0 supports first-party applications and service-to-service access. Deployment, operations and preparation for production remain the deployer’s responsibility.
Sign-in and account management
Sign-in, authorization and account management over standard protocols
Unified sign-on
Standard protocols (OIDC), single sign-on and an account center for connected applications
Authorization & security
Least-privilege authorization, account security built in; password changes and account freezes revoke related tokens
Auditable
Authentication and authorization you can audit end to end, with one security policy
SDK integration
Integrate applications through the SDK, with an explicit allowlist for redirect addresses
Interface illustration
Security baseline
Configure identity services against a clear security baseline
Standard protocols
OIDC authorization code + PKCE, client credentials and refresh tokens; the password grant is disabled by default.
Short-lived tokens
10-minute access tokens with refresh-token rotation limit how long exposed tokens remain usable.
Password & sign-in hardening
Argon2id password hashing, sign-in rate limiting and audit — helps identify and track unusual sign-in activity.
Key rotation
Automatic JWKS key rotation, HTTPS enforced everywhere.
Security & trust
Verifiable security design facts and an honest compliance statement — nothing exaggerated, nothing omitted.
- Self-hosted by design: identity data lives in the deployer’s own servers and databases; operational security of an instance (hardening, backups, key custody) belongs to the deployer
- No SOC 2 or ISO/IEC 27001 certification, and no formal community security audit yet; no SLA during the preview
- Security reports go through a private channel (hello@pandalabs.cc), never public issue trackers; no paid bug bounty is operated today
- Website analytics follow a collect-the-minimum principle without advertising tracking cookies; see Privacy and analytics for data details and opt-out options
For different product teams
One identity service for Panda Assistant and Oasis, also available to outside product teams
For PandaLabs products
Sign-in, authorization and audit services for Panda Assistant and Oasis
For outside product teams
Self-hosted CIAM: your deployment, your data
Protocols and technology
OIDC / OAuth 2.0 · ASP.NET Core · OpenIddict
Roadmap & boundaries
Explore product direction and scope. Availability follows actual releases.
From a local trial to product integration
Start with the docs and Quickstart to explore self-hosting, or browse the open-source projects. The current suite is Community Preview 0.2.0-preview.1, without an SLA. Instance hardening, backups and key management are the deployer’s responsibility. Write to discuss your product and integration needs.
Integration docs are maintained on this site; a test environment is provided during the talks.