PandaAuthReleased · Open source
Every login is trust on your terms.
Released · Open source · for product teams, hello@pandalabs.cc
Identity foundation
The shared identity foundation across the PandaLabs ecosystem
Unified sign-on
Standard protocols (OIDC), SSO and an account center; sign in once, pass everywhere
Authorization & security
Least-privilege authorization, account security built in; password changes and freezes revoke tokens in bulk, instantly
Auditable
Authentication and authorization you can audit end to end, with one security policy
SDK integration
Self-service onboarding inside the ecosystem; integrate once, reuse identity — with strict redirect allowlists
Security baseline
No convenience at the cost of security — production-ready defaults
Standard protocols
OIDC authorization code + PKCE, client credentials and refresh tokens; the password grant is disabled by default.
Short-lived tokens
10-minute access tokens with refresh-token rotation keep any leak window minimal.
Password & sign-in hardening
Argon2id password hashing, sign-in rate limiting and audit — anomalies can be acted on instantly.
Key rotation
Automatic JWKS key rotation, HTTPS enforced everywhere.
Where it sits
One identity foundation shared across the PandaLabs product lines — and open to outside product teams
One identity, ecosystem-wide
Panda Assistant, Oasis and what comes next share sign-on, authorization and audit
For outside product teams
Self-hosted CIAM: your deployment, your data
Standard-protocol core
OIDC / OAuth 2.0 · ASP.NET Core · OpenIddict
One integration, identity reused ecosystem-wide
PandaAuth v1.0.0 is officially released and open source: the product site offers docs, live status and a changelog. Integration talks with product teams continue — write about your product and scenario, and we reply to every message.
Integration docs live on the product site; a test environment is provided during the talks.