Product overview

What PandaAuth is, who it is for, and what it consists of.

PandaAuth is a self-hosted customer identity and access management (CIAM) platform for .NET product teams, ISVs, and applications that need to keep their identity data under their own control. It is built on ASP.NET Core and OpenIddict, and serves first-party apps across platforms as well as service-to-service calls with OIDC / OAuth 2.0.

Components

Component Responsibility
IdP (server) Authentication protocols, user storage, token issuance and governance
Product site (this site) Brand entry point, docs, status, and changelog
Admin console (admin) Management console for users, clients, and audit
Account center (me) Self-service center for end users

Current release

  • PandaAuth Community Preview 0.2.0-preview.1 is deployed to production for early community use; no SLA is promised at this stage. The stable 1.0.0 release still needs the remaining acceptance work and release materials, and access remains invitation- or application-based (hello@pandalabs.cc).
  • Delivered capabilities are exactly what the capability matrix lists (SSO/MFA/Passkey/audit/self-service credentials, and so on); planned features are never presented as shipped.
  • Phased roadmap: Phase 0 protocol prototype → Phase 1 basic account management and a complete integration loop → Phase 2 extended self-service and session governance → Phase 3 regional deployment and operations at scale.

Ground rules for these docs

  • The single source of truth for protocol behavior is the OIDC discovery document; these pages are a quick reference and a guide.
  • Governance and licensing follow the LICENSE and CONTRIBUTING files of the community repository.
  • Capabilities the product has not delivered are explicitly marked as “planned / on the roadmap”; there is no vague wording.