跳到主要内容
Supermarket
返回能力市场
Agent Pack
design
Apache-2.0

casdoor

An open-source Agent-first Identity and Access Management (IAM) /LLM MCP & agent gateway and auth server with web UI supporting OpenClaw, MCP, OAuth, OIDC, SAML, CAS, LDAP, SCIM, WebAuthn, TOTP, MFA, Face ID, Google Workspace, Azure AD

casdoorcasdoor
85/ 100

公开评测 · 综合采用结论

证据充分,整体质量与安全表现优秀

查看评测依据 评测我的项目基于公开项目证据,非安全认证或安装推荐
14.5kstars
1.8kforks
最近更新 8小时前
评测生成时间(北京时间)
本报告引擎
v3.10.0
当前引擎
v3.16.0

本报告与当前引擎使用不同规则;原分数不会自动更新,不同版本的分数不宜直接对比。

重新评测此项目

进入后确认来源与额度,提交才会创建任务。

Evaluation report

综合采用结论

85
A
满分 100
值得推荐低风险
决策摘要

证据充分,整体质量与安全表现优秀

84%
高置信度
83
文档
100
安全
73
质量
100
活跃
70
采用
  • 基础评测完成+25/25确定性评分与静态安全扫描已完成
  • README 有效证据+25/2512,344 个去重后的有效字符
  • 独立证据来源+4/201 类非重复证据,重复文件不叠加
  • 仓库元数据+10/10已取得仓库状态与采用数据
  • 活跃记录+5/5已取得最近提交时间
  • AI 复核+15/15已完成结构化 AI 证据复核
How it works · 架构图

Casdoor 架构与部署方式

README 描述了前端、后端、数据库和多种部署方式,无明确时间顺序,适合架构图。

AI 提取 · 证据约束

左右滑动查看完整图示

Casdoor 架构与部署方式README 描述了前端、后端、数据库和多种部署方式,无明确时间顺序,适合架构图。API调用数据读写运行React前端用户界面Go后端API服务数据库数据存储部署方式安装选项
图示依据
  • • 技术栈章节说明前后端分离
  • • 安装章节提供多种部署方式
  • • 数据库支持多种类型
五维表现
Casdoor 作为自托管 IAM 平台,价值明确,提供多协议支持和快速部署。文档详尽,但缺少错误处理和排障指南,且生产配置需自行补充。
质量证据
  • 安装章节提供docker run命令和Compose配置
  • 快速开始表格给出演示凭据
  • 功能列表列出OAuth、OIDC、SAML等协议
  • 安全章节强调修改默认密码和HTTPS
  • 文档链接指向详细指南
采用建议
优势
  • 问题与用途描述
  • 有效 README
  • 安装或接入步骤
  • 可执行示例
  • 未发现已知高风险模式
关注点
  • 缺少输出或结果说明
  • 缺少错误处理或排障
  • 缺少错误处理和排障指南
  • 生产环境配置细节需参考外部文档
  • 未提供输出或结果说明
适合

需要自托管身份管理的团队、需要多协议SSO的企业、希望快速评估IAM功能的开发者、需要AI/Agent网关的场景

不建议直接用于

仅需简单反向代理登录的场景、无数据库或容器环境的小型项目

也有自己的公开项目?先看完证据,再用当前规则生成独立报告。

评测我的项目 →
文档证据
83/100
问题与用途描述10 分
有效 README12 分
安装或接入步骤14 分
可执行示例16 分
输入、参数或工具说明11 分
输出或结果说明9 分
限制、权限或边界12 分
错误处理或排障8 分
许可证信息5 分
结构化章节3 分
安全证据
低风险
未发现已知高风险模式

静态扫描不是安全保证,生产接入前仍应人工复核权限和数据边界。

优先改进清单
  1. 01补充输出或结果说明
  2. 02补充错误处理或排障
方法、证据与局限展开
数据来源

GitHub Repository API

扫描范围

1 个文件 · 16,626 字符

评测引擎

v3.10.0 · AI 复核已启用(deepseek-chat)

局限
  • 静态评测不会安装或执行项目代码
  • 安全扫描基于高信号文件与已知模式,不能替代人工审计
  • 流行度只反映采用程度,不代表安全或工程质量

30 天热度趋势

README

Casdoor

An open-source, self-hosted identity and access management platform

Casdoor is a single sign-on (SSO) and authentication server with a web console.
It speaks OAuth 2.0, OIDC, SAML 2.0, CAS, LDAP, SCIM 2.0, WebAuthn, TOTP/MFA and MCP,
and connects to Google Workspace, Microsoft Entra ID (Azure AD), GitHub and many other identity providers.

Website · Documentation · Live demo · Discord

Release Docker Pulls Build Status golangci-lint Discord License

Casdoor sign-in page with password, code, WebAuthn and Face ID tabs and social login icons

The sign-in page your users see: password, email/SMS code, WebAuthn and Face ID, plus every social provider you enable.

Casdoor admin console dashboard with user, application and provider statistics Admin console. Users, tokens, organizations and providers at a glance. Casdoor applications list showing several applications with their organizations and providers Applications. Every app that delegates login to Casdoor, across all organizations. Casdoor application settings, Providers tab, with per-provider signup, signin and unlink toggles Application settings. OAuth, SAML, providers and branding — no redeploy, no config file.

❤️ Sponsors

APIMart Thanks to APIMart for sponsoring this project! APIMart is a low-cost API platform for AI image & video generation — GPT-Image-2 from $0.006/image, 160+ images per dollar. One async API covers both image and video: submit a task, get an ID, fetch results via polling or callback. Batch tens of thousands of images without timeouts, switch models without changing code. Pay-as-you-go with no monthly fee — sign up here to get started.

🚀 Try it in 30 seconds

No database and no config file needed. This runs Casdoor on SQLite with sample data:

docker run -p 8000:8000 casbin/casdoor-all-in-one

Open http://localhost:8000 and sign in:

FieldValue
Organizationbuilt-in
Usernameadmin
Password123

The sign-in form has separate organization and username fields. Docs sometimes write this pair as built-in/admin — that is the same thing, not a username containing a slash.

Prefer not to install anything? Use the hosted demos:

DemoURLNotes
Writabledemo.casdoor.comFull access, so you can click through everything. All data resets about every 5 minutes.
Read-onlydoor.casdoor.netStable global demo. Every write operation fails by design.

Both accept the same built-in / admin / 123 credentials.

🤔 Why Casdoor

Casdoor is a complete identity provider, not an authentication proxy and not a library you embed. It stores your users, issues the tokens, and gives you an admin console to manage all of it — so your applications can delegate login entirely and never handle a password themselves.

  • One server, many protocols. The same user directory is reachable over OAuth 2.0, OIDC, SAML 2.0, CAS, LDAP and SCIM, so a modern SPA and a legacy CAS-only app can share one set of accounts.
  • Everything is editable in the UI. Organizations, applications, providers, sign-in methods, email and SMS templates, and login-page branding are configured in the web console instead of in files you have to redeploy.
  • Policy-based authorization built in. Access rules are expressed with Casbin — ACL, RBAC, ABAC and custom models — rather than a fixed permission scheme.
  • Straightforward to self-host. A single Go binary plus a database. No JVM, no operator, no cluster required.

If all you need is a login screen in front of an existing reverse proxy, a smaller tool may suit you better. Casdoor is for when you want to own the user directory itself.

📦 Installation

Four supported paths, fastest first. All of them end up at http://localhost:8000.

Docker — all-in-one (evaluation)

docker run -p 8000:8000 casbin/casdoor-all-in-one

Bundles SQLite and demo data into a single container. Ideal for a first look, but not intended for production: the data lives inside the container and disappears with it.

Guide: Try with Docker

Docker Compose — Casdoor with MySQL

docker-compose.yml starts Casdoor next to a MySQL 8 container.

Two things to know before running it:

  1. Compose builds the image from source (Go backend plus React frontend). The first docker compose up takes several minutes, so it is not the quick-trial path — use the all-in-one image above for that.
  2. You have to point Casdoor at the bundled database first.

Set the MySQL settings in conf/app.conf to match the db service:

driverName = mysql
dataSourceName = root:123456@tcp(localhost:3306)/
dbName = casdoor

Use localhost here even though MySQL runs in a separate container: the compose file sets RUNNING_IN_DOCKER=true, and Casdoor rewrites localhost to the Docker host address at startup (see conf/conf.go). Then start everything:

docker compose up

The compose entrypoint already passes --createDatabase=true, so the casdoor database is created for you.

Guide: Try with Docker

Kubernetes — Helm

Requires Helm v3 and a running cluster:

helm install casdoor oci://registry-1.docker.io/casbin/casdoor-helm-charts

The chart does not expose Casdoor outside the cluster by default. To reach it, find the service and forward a port:

kubectl get svc
kubectl port-forward svc/<service-name-from-above> 8000:8000

For a real deployment, configure an Ingress and an external database through the chart's values. k8s.yaml in this repo is a minimal plain-manifest example if you would rather not use Helm.

Guide: Try with Helm

From source — for development

Use this if you intend to modify Casdoor. Prerequisites: Go 1.25+ (see go.mod), Node.js 20 LTS, Yarn 1.x, and a supported database (MySQL, PostgreSQL, SQLite, SQL Server and others).

git clone https://github.com/casdoor/casdoor.git
cd casdoor

Set driverName, dataSourceName and dbName in conf/app.conf. For MySQL, create the casdoor database first, or start the server with --createDatabase=true. Then build the frontend and run the server:

cd web && yarn install && yarn build && cd .. && go run main.go

While working on the frontend, run yarn start in web/ instead of yarn build to get hot reload on port 7001, with go run main.go serving the API from a second terminal.

Guide: Server installation

👉 After you sign in

At this point you have a running identity provider with nothing connected to it yet. Next:

  1. Change the admin password. 123 is a demo credential and must not survive contact with production.
  2. Connect your first application — create an Application in the console, copy its Client ID and Client Secret, and point your app's OAuth/OIDC client at Casdoor.
  3. Add an identity provider if you want Google, GitHub or Entra ID sign-in.
  4. Pick an SDK for your language, or call the Public API directly.

✨ Features

🔐 Authentication

  • OAuth 2.0 / OIDC — full authorization server and OpenID Connect provider
  • SAML 2.0 — enterprise SSO, as both IdP and SP
  • CAS — Central Authentication Service for legacy applications
  • LDAP — sync from a directory, or serve as one
  • WebAuthn / passkeys — passwordless sign-in
  • TOTP / MFA — multi-factor authentication, including email and SMS codes
  • Face ID — biometric sign-in

🏢 Organizations and access control

  • Multi-tenancy — independent organizations, each with its own users and branding
  • RBAC and beyond — roles, permissions and Casbin policy models
  • SCIM 2.0 — automated user provisioning and de-provisioning
  • Social login — Google, GitHub, Entra ID (Azure AD) and many more
  • Custom providers — plug in your own identity, email, SMS, storage or payment backends
  • Audit logs — a record of sign-ins and administrative changes

🤖 AI and agents

  • MCP gateway — expose Model Context Protocol servers and control access to them
  • A2A — agent-to-agent communication support

🛠️ Developer experience

  • REST API — every console action is also an API call
  • SDKs — Go, Java, Python, Node.js, .NET, PHP, Rust and more
  • Swagger UI — live API explorer
  • Webhooks — push user and sign-in events into your own systems
  • Customizable UI — theme the login page and console per organization

🧱 Technology stack

Casdoor is a frontend–backend separated application:

  • Backend — Go with the Beego framework, exposing REST APIs (repository root)
  • Frontend — React 18 with shadcn/ui on Tailwind CSS, built with Vite (web/). The previous Ant Design console is kept for reference at web-old/ and is no longer built or served.
  • Database — MySQL, PostgreSQL, SQLite, SQL Server and others through XORM
  • Cache — Redis, optional; needed if you run more than one Casdoor replica

📖 Documentation

The full documentation lives at casdoor.ai/docs. Common starting points:

I want to…Go to
Install CasdoorFrom source · Docker · Helm
Connect my applicationHow to connect to Casdoor
Use the APIPublic API · Swagger UI
Choose an SDKIntegrations
Deploy to productionDeployment

🔌 SDKs and integrations

Official SDKs and framework integrations, by language:

The complete list, including reverse proxies and third-party applications, is in the Integrations documentation.

🔒 Security

Please do not report security vulnerabilities in public GitHub issues. Email admin@casdoor.org instead — SECURITY.md has the full policy and disclosure process.

Before exposing a Casdoor instance to the internet:

  • Change the built-in admin password. Never ship the demo credential 123.
  • Serve Casdoor over HTTPS only, and set origin in conf/app.conf to your public URL.
  • Review conf/app.conf for values inherited from the sample file, especially dataSourceName and any provider secrets.
  • Set runmode = prod and keep showSql = false in production.

🤝 Community and support

🌍 Contributing

Contributions are welcome. For anything larger than a small fix, please open an issue first so you can agree on the approach with the maintainers before writing code.

Read the contribution guidelines before you start.

Translations. User-facing strings in the web console go through i18next. When you add or change one under web/, update the English catalog at web/src/locales/en/data.json. The other languages are translated on Crowdin and should not be edited by hand.

🙌 Support Casdoor

Casdoor is free and open source. If it saves you time, consider supporting its development on Open Collective.

Sponsors on Open Collective

Backers on Open Collective

📄 License

Casdoor is licensed under the Apache License 2.0.


If Casdoor is useful to you, a star helps other people find it.

GitHub Stars

© 2026 Casdoor · Apache License 2.0