Product roadmap
Integration directions, capabilities under consideration and current scope for PandaAuth.
PandaAuth evolves around product teams’ sign-in, account security and integration needs. These directions do not promise delivery dates or a release order. Integration docs and release notes describe available capabilities.
Near-term plans
- Automated administration: improve public integration options for applications that need user and client management. See Management API for the current scope.
- Breached-password detection: help users identify passwords found in public breach records and reduce the risk of password reuse.
- Third-party sign-in: prioritize evaluating WeChat and WeCom scenarios to reduce repeated account creation.
Exploring
- Device sign-in: evaluate authorization experiences for CLI, desktop and other devices.
- Session management: consider ways for users to view and end individual sign-in sessions.
- Sign-in customization: explore branding on sign-in pages and customizable notification emails.
- Audit event export: consider ways to share audit information with external systems.
Not offered
- B2B organization management: the focus is single-tenant customer identity management; organization hierarchies and multi-tenant organization management are not provided.
- Complex identity federation: OIDC / OAuth 2.0 are the current integration foundation; SAML federation is not provided.
- Public self-service provisioning: self-service signup and pricing for a public hosted service are not offered.
See the overview and client integration guide for current capabilities, and the changelog for important releases. Discuss integration needs at hello@pandalabs.cc.