Casdoor
Open-source, self-hosted IAM with built-in MCP server for AI agent identity control.
Casdoor's built-in MCP server, OAuth 2.1 agent support, and OpenClaw observability are genuinely differentiating in open-source IAM. It's an early mover, and for engineering teams that can self-host and operate infrastructure, it's a compelling, cost-effective choice. Compare it to managed options like Auth0 or Okta if you want zero ops; to Keycloak if you need a more mature IAM community. If you're agent-centric and technically capable, Casdoor is worth serious evaluation.
Verified 1d ago · liveness 69/100 · cite: rightaichoice.com/tools/casdoor
- Enterprises adopting AI agents that need IAM with MCP support
- Teams building SaaS platforms requiring integrated billing and auth
- Organizations needing LLM observability and audit trails for agent activity
- Developers seeking a self-hosted, open-source IAM with SSO and agent capabilities
- Users wanting a fully managed, closed-source IAM with no self-hosting
- Organizations that do not use AI agents or need MCP functionality
- Teams requiring no-code or low-code configuration for complex auth workflows
We scan live Reddit threads, YouTube comments, X posts, G2 reviews and other communities — and hand you an honest verdict in under a minute.
- Honest verdict, not marketing
- Real pros & cons from real users
- Attributed quotes with receipts
3 free scans · no card needed
Skip Casdoor if you need a fully managed, zero-ops IAM solution where you don't want to handle deployment, maintenance, and scaling yourself.
You bear the full cost of hosting, scaling, and maintaining the infrastructure yourself, including uptime and security patching.
Casdoor is free and open-source, so you pay only for your own infrastructure — a major cost advantage over managed IAM like Okta or Auth0, which charge per user per month. For teams with the engineering capacity to self-host, it's far cheaper at scale, though you trade away managed convenience.
In short
Casdoor — Open-source, self-hosted IAM with built-in MCP server for AI agent identity control. Best for Enterprises adopting AI agents that need IAM with MCP support, Teams building SaaS platforms requiring integrated billing and auth, Organizations needing LLM observability and audit trails for agent activity. Free to use.
What's new in Casdoor
Checked yesterdayAcross the latest 1 update: 1 news mention.
What people actually say about Casdoor — is it worth it?
We ran a structured research pass across product reviews, community discussions, and post-purchase forum threads to surface the patterns vendors won't publish themselves. Below: the recurring strengths, the hidden costs people mention most, and the cohort that consistently regrets adopting this tool.
23 mentions across 4 sources (Hacker News, YouTube, GitHub, Lemmy) · researched Aug 12, 2026.
- +Built-in MCP server enables AI agents to manage identity via natural language, a unique feature.
- +Fine-grained, scope-based authorization per tool call for AI agents.
- +Agent-to-agent authentication with OAuth 2.1 and Dynamic Client Registration.
- +Supports 100+ identity providers and protocols like OAuth, OIDC, SAML, LDAP.
- +Includes OpenClaw observability for LLM applications, providing audit trails.
- −Community data shows limited real-world feedback; most discussions are about competitors.
- −A security advisory lists multiple authentication bypass vulnerabilities, a major concern.
- −Competes with more established tools like Keycloak and Authentik that have larger communities.
- −The agent-first focus may be overkill for traditional IAM use cases.
- −Learning curve is intermediate; users may need to understand MCP and OAuth 2.1 nuances.
- • Self-hosting requires infrastructure and maintenance time.
- • Cloud pricing is not clearly documented, may be costly at scale.
- • No enterprise support tier mentioned in community data.
Viability Score
How well maintained and how widely used is Casdoor? Built from what the vendor actually publishes (docs, changelog, tutorials, integrations, pricing), whether the site is live, and how much real users discuss it. How we calculate this
Last calculated: August 2026
How we score →Key Features
- Built-in MCP server with Streamable HTTP
- OAuth 2.1 with Dynamic Client Registration
- Per-tool permissions for MCP calls
- Secure agent-to-agent authentication
- Support for 100+ identity providers
- OAuth 2.0, OIDC, SAML, CAS protocols
- LDAP and WebAuthn support
- MFA (multi-factor authentication)
- SSO for multiple applications
- User registration and password recovery
- SaaS billing: plans, pricing tiers, payment providers
- OpenClaw LLM observability via OTLP
- Web UI for managing users, applications, permissions
- Customizable login pages
- SDK for identity auth, user management, resource uploads
About Casdoor
Casdoor is an open-source Identity and Access Management (IAM) and SSO platform built for the AI agent era. It is the first open-source IAM to include a native MCP server with Streamable HTTP, enabling AI agents to manage users, applications, and permissions via natural language. Every MCP tool call is protected by fine-grained, scope-based authorization, and OAuth 2.1 with Dynamic Client Registration secures agent-to-agent authentication. This makes Casdoor a practical choice for enterprises integrating AI agents while maintaining strong identity controls. Beyond AI-specific features, Casdoor delivers enterprise-grade authentication with support for 100+ identity providers (including Google Workspace and Azure AD) and protocols like OAuth 2.0, OIDC, SAML, CAS, LDAP, WebAuthn, and MFA. Its SaaS management module handles billing plans, pricing tiers, payment providers, and subscriptions, centralizing revenue. Integration with OpenClaw, an observability agent, collects OpenTelemetry traces, metrics, and logs from LLM applications, providing a full runtime audit trail of agent activity. Architecturally, Casdoor is built for scale with clean frontend-backend separation and horizontal scalability for high concurrency. It offers an intuitive console, customizable login pages, and a documented SDK for identity authentication, user management, and resource uploads. Being part of the CNCF Cloud Native Landscape adds credibility for teams seeking a self-hosted, open-source alternative to managed IAM solutions. For teams that need granular identity control over AI agents without the cost of proprietary IAM, Casdoor is a solid, self-hosted contender.
Behind the Verdict
Casdoor stands out in the crowded IAM space by being the first open-source platform to bake in MCP server support natively. That's a meaningful differentiator for teams building AI agents, because it lets those agents manage users, apps, and permissions in natural language — something you'd otherwise have to bolt on yourself. The per-tool permissions and OAuth 2.1 with Dynamic Client Registration show real security thought, not just a demo feature. For enterprise buyers, the support for 100+ identity providers, OAuth 2.0, OIDC, SAML, CAS, LDAP, WebAuthn, and MFA is genuinely enterprise-grade, and the SaaS billing module is a nice bonus for teams monetizing their product. The OpenClaw integration giving you an audit trail of agent activity via OpenTelemetry is forward-looking — it addresses a real need for governance as agents proliferate. Where Casdoor might not fit: if you're looking for a zero-ops managed solution, it's not that — you have to self-host and maintain it. Its MCP features are newer, so expect to dig into docs (which are improving). Compared to Keycloak, Casdoor is less battle-tested in the broader IAM community; compared to Auth0/Okta, you lose the managed convenience but gain cost control and data sovereignty. If you're a technical team already running infrastructure and you care about AI agent identity, Casdoor is a strong, cost-effective choice. If you need hand-holding or have no ops capacity, look elsewhere.
Researching Casdoor? Get your full AI stack in 60 seconds.
Free, no signup — tell us your goal and get tools matched to your budget & existing stack.
Real-world workflow fit
Concrete scenarios for the personas Casdoor actually fits — and what changes day-one when you adopt it.
You need to add SSO and MFA to your web app without paying per-user licensing.
Outcome: You deploy Casdoor in your cloud, configure Google Workspace as an identity provider, and integrate your app via the SDK — getting SSO, MFA, and user management in under a day.
You want AI agents (like Claude Desktop or Cursor) to manage users and permissions autonomously but with strict controls.
Outcome: You set up Casdoor's MCP server, define per-tool permissions and OAuth 2.1 client registration, and connect MCP clients — giving you secure, auditable agent-driven identity management.
You need a full audit trail of what your AI agents actually do at runtime.
Outcome: You deploy OpenClaw configured to export OTLP traces, metrics, and logs to your Casdoor instance, and inspect the structured Entries in the UI — getting complete agent activity logs.
Use Cases
- Deploy Casdoor as your central IAM for web applications with SSO, MFA, and 100+ identity providers.
- Integrate Casdoor's MCP server with Claude Desktop or Cursor to manage users and permissions via natural language.
- Use OpenClaw to collect and audit traces, metrics, and logs from your LLM applications in Casdoor.
- Set up a SaaS billing system with Casdoor's plans, pricing tiers, and payment providers.
- Enable face authentication SSO for enhanced user experience and security across multiple apps.
Limitations
- Casdoor is an open-source, self-hosted IAM platform, so deployment and maintenance require technical expertise.
- The built-in MCP server and AI agent features are newer additions and may have less mature documentation.
- The platform supports enterprise-grade authentication and integration with leading identity providers.
as of 2026-09-01
Verification history
We have re-verified Casdoor 8 times since . Each pass re-reads the vendor's own pages and re-checks every listed field against that evidence; passes where nothing had changed are marked as such.
- — re-checked, vendor evidence unchanged
- — re-checked, vendor evidence unchanged
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-checked, vendor evidence unchanged
- — re-checked, vendor evidence unchanged
Showing the 6 most recent of 8 verification passes.
Free to cite with attribution — this page re-verifies continuously.
Where the pricing makes sense
The company stage and team size where Casdoor's pricing actually pencils out — and where peers do it cheaper.
Casdoor is free and open-source, so you pay only for your own infrastructure — a major cost advantage over managed IAM like Okta or Auth0, which charge per user per month. For teams with the engineering capacity to self-host, it's far cheaper at scale, though you trade away managed convenience.
Setup time & first value
How long it actually takes to get something useful out of Casdoor — broken out by persona, not the marketing-page minute.
A basic Casdoor setup can take under an hour for a technical user familiar with Docker and reverse proxies. Integrating it with your first app via the SDK typically adds a few hours. Setting up the MCP server for AI agents may take half a day to configure securely. Expect a few days to fully tailor for production, including custom login pages and scaling.
Switching to or from Casdoor
How to bring data in from common predecessors and how to get it back out — written for the switcher, not the buyer.
- →From Auth0: Export your users and applications via Auth0's API and import them into Casdoor, then update your client libraries to use Casdoor's endpoints.
- →From Okta: Use Okta's SCIM or API to export user data, import into Casdoor, and reconfigure your apps to point to Casdoor.
- →From Keycloak: Use Keycloak's export features to get users and realms, then import them into Casdoor's realm structure.
- ↗To Auth0: Export users and apps from Casdoor via its API, then bulk-import into Auth0 using their management API.
- ↗To Okta: Use Casdoor's user export to CSV or JSON to import into Okta's directory via their import tools.
- ↗To Keycloak: Export users and clients from Casdoor and import them into Keycloak realms using its admin console.
Integrations
Resources & Guides
Tutorials & Learning
Official links
Tools that pair well with Casdoor
Common stack mates teams adopt alongside Casdoor, with the specific reason each pairing earns its keep.
Featured Head-to-Head Comparisons
Casdoor vs Audioeye
Choose Casdoor if you need an open-source, AI-native IAM with agent authentication and minimal cost. Choose AudioEye if your priority is web accessibility compliance with automated scanning and legal support. They serve completely different needs, so the decision hinges on your core requirement: identity/security vs. accessibility/legal risk.
Casdoor vs Temporal Ai
Choose Temporal AI if you need durable execution for AI agents and critical workflows with automatic retries and state recovery. Choose Casdoor if you need an open-source IAM platform with native MCP support for AI agent authentication and SaaS management. They solve different problems — orchestration vs identity — so pick based on your primary need.
Casdoor vs Push Security
If your immediate need is preventing browser-based attacks (AiTM, session hijacking) and controlling AI tool data leakage, Push Security is the more specialized, agentic solution. If you are an enterprise building AI-agent workflows and need an open-source IAM with native MCP support and agent authentication, Casdoor is the stronger, extensible platform. Choose based on whether your priority is browser threat defense or identity management for AI agents.
Alternatives to Casdoor
View allChrome DevTools MCP
Open-source MCP server giving AI agents live control and deep debugging of Chrome DevTools.
Popular in Security & Privacy
Push Security
Browser-native security that stops AI-driven attacks and secures employee AI usage
Frequently Asked Questions
Used Casdoor? Help shape our editorial sentiment research.


