Product roadmap

Integration directions, capabilities under consideration and current scope for PandaAuth.

PandaAuth evolves around product teams’ sign-in, account security and integration needs. These directions do not promise delivery dates or a release order. Integration docs and release notes describe available capabilities.

Near-term plans

  • Automated administration: improve public integration options for applications that need user and client management. See Management API for the current scope.
  • Breached-password detection: help users identify passwords found in public breach records and reduce the risk of password reuse.
  • Third-party sign-in: prioritize evaluating WeChat and WeCom scenarios to reduce repeated account creation.

Exploring

  • Device sign-in: evaluate authorization experiences for CLI, desktop and other devices.
  • Session management: consider ways for users to view and end individual sign-in sessions.
  • Sign-in customization: explore branding on sign-in pages and customizable notification emails.
  • Audit event export: consider ways to share audit information with external systems.

Not offered

  • B2B organization management: the focus is single-tenant customer identity management; organization hierarchies and multi-tenant organization management are not provided.
  • Complex identity federation: OIDC / OAuth 2.0 are the current integration foundation; SAML federation is not provided.
  • Public self-service provisioning: self-service signup and pricing for a public hosted service are not offered.

See the overview and client integration guide for current capabilities, and the changelog for important releases. Discuss integration needs at hello@pandalabs.cc.