PandaAuth product icon

PandaAuthReleased · Open source

Every login is trust on your terms.

Released · Open source · for product teams, hello@pandalabs.cc

Identity foundation

The shared identity foundation across the PandaLabs ecosystem

Unified sign-on

Standard protocols (OIDC), SSO and an account center; sign in once, pass everywhere

Authorization & security

Least-privilege authorization, account security built in; password changes and freezes revoke tokens in bulk, instantly

Auditable

Authentication and authorization you can audit end to end, with one security policy

SDK integration

Self-service onboarding inside the ecosystem; integrate once, reuse identity — with strict redirect allowlists

Security baseline

No convenience at the cost of security — production-ready defaults

Standard protocols

OIDC authorization code + PKCE, client credentials and refresh tokens; the password grant is disabled by default.

Short-lived tokens

10-minute access tokens with refresh-token rotation keep any leak window minimal.

Password & sign-in hardening

Argon2id password hashing, sign-in rate limiting and audit — anomalies can be acted on instantly.

Key rotation

Automatic JWKS key rotation, HTTPS enforced everywhere.

Where it sits

One identity foundation shared across the PandaLabs product lines — and open to outside product teams

One identity, ecosystem-wide

Panda Assistant, Oasis and what comes next share sign-on, authorization and audit

For outside product teams

Self-hosted CIAM: your deployment, your data

Standard-protocol core

OIDC / OAuth 2.0 · ASP.NET Core · OpenIddict

One integration, identity reused ecosystem-wide

PandaAuth v1.0.0 is officially released and open source: the product site offers docs, live status and a changelog. Integration talks with product teams continue — write about your product and scenario, and we reply to every message.

Integration docs live on the product site; a test environment is provided during the talks.