Casdoor

Casdoor

Open-source, self-hosted IAM with built-in MCP server for AI agent identity control.

69/100MonitorFreeFree

Casdoor's built-in MCP server, OAuth 2.1 agent support, and OpenClaw observability are genuinely differentiating in open-source IAM. It's an early mover, and for engineering teams that can self-host and operate infrastructure, it's a compelling, cost-effective choice. Compare it to managed options like Auth0 or Okta if you want zero ops; to Keycloak if you need a more mature IAM community. If you're agent-centric and technically capable, Casdoor is worth serious evaluation.

Verified 1d ago · liveness 69/100 · cite: rightaichoice.com/tools/casdoor

Best for
  • Enterprises adopting AI agents that need IAM with MCP support
  • Teams building SaaS platforms requiring integrated billing and auth
  • Organizations needing LLM observability and audit trails for agent activity
  • Developers seeking a self-hosted, open-source IAM with SSO and agent capabilities
Not ideal for
  • Users wanting a fully managed, closed-source IAM with no self-hosting
  • Organizations that do not use AI agents or need MCP functionality
  • Teams requiring no-code or low-code configuration for complex auth workflows
Visit Website

IntermediateA basic Casdoor setup can take under an hour for a technical user familiar with Docker and reverse proxies. Integrating it with your first app via the SDK typically adds a few hours. Setting up the MCP server for AI agents may take half a day to configure securely. Expect a few days to fully tailor for production, including custom login pages and scaling.Web · APIAPI availableVerified 1d ago
Pricing
Free
FreeFree tier3 hidden costs
Learning curve
Intermediate
A basic Casdoor setup can take under an hour for a technical user familiar with Docker and reverse proxies. Integrating it with your first app via the SDK typically adds a few hours. Setting up the MCP server for AI agents may take half a day to configure securely. Expect a few days to fully tailor for production, including custom login pages and scaling.
Runs on
WebAPI
API available · 11 integrations
Who it's for
DevOps engineer at a SaaS startupAI platform architect at an enterprisePlatform engineer responsible for LLM observability
Live sentiment
Is Casdoor actually worth it?

We scan live Reddit threads, YouTube comments, X posts, G2 reviews and other communities — and hand you an honest verdict in under a minute.

  • Honest verdict, not marketing
  • Real pros & cons from real users
  • Attributed quotes with receipts
Run a free scan

3 free scans · no card needed

Skip it if

Skip Casdoor if you need a fully managed, zero-ops IAM solution where you don't want to handle deployment, maintenance, and scaling yourself.

The 30-second take
Biggest gripe

You bear the full cost of hosting, scaling, and maintaining the infrastructure yourself, including uptime and security patching.

Price reality

Casdoor is free and open-source, so you pay only for your own infrastructure — a major cost advantage over managed IAM like Okta or Auth0, which charge per user per month. For teams with the engineering capacity to self-host, it's far cheaper at scale, though you trade away managed convenience.

In short

Casdoor — Open-source, self-hosted IAM with built-in MCP server for AI agent identity control. Best for Enterprises adopting AI agents that need IAM with MCP support, Teams building SaaS platforms requiring integrated billing and auth, Organizations needing LLM observability and audit trails for agent activity. Free to use.

What's new in Casdoor

Checked yesterday

Across the latest 1 update: 1 news mention.

What people actually say about Casdoor — is it worth it?

We ran a structured research pass across product reviews, community discussions, and post-purchase forum threads to surface the patterns vendors won't publish themselves. Below: the recurring strengths, the hidden costs people mention most, and the cohort that consistently regrets adopting this tool.

23 mentions across 4 sources (Hacker News, YouTube, GitHub, Lemmy) · researched Aug 12, 2026.

50% positive50% critical
Recurring strengths
  • +Built-in MCP server enables AI agents to manage identity via natural language, a unique feature.
  • +Fine-grained, scope-based authorization per tool call for AI agents.
  • +Agent-to-agent authentication with OAuth 2.1 and Dynamic Client Registration.
  • +Supports 100+ identity providers and protocols like OAuth, OIDC, SAML, LDAP.
  • +Includes OpenClaw observability for LLM applications, providing audit trails.
Recurring frustrations
  • Community data shows limited real-world feedback; most discussions are about competitors.
  • A security advisory lists multiple authentication bypass vulnerabilities, a major concern.
  • Competes with more established tools like Keycloak and Authentik that have larger communities.
  • The agent-first focus may be overkill for traditional IAM use cases.
  • Learning curve is intermediate; users may need to understand MCP and OAuth 2.1 nuances.
Patterns worth knowing
Security vulnerabilities raise concerns about reliability
Seen on Lemmy
Comparison to established IAM tools (Keycloak, Authentik, Authelia) dominates discussions
Seen on YouTube, Hacker News
Agent-first IAM concept is intriguing but under-validated
Seen on GitHub, Hacker News
Learning curve
intermediateProductive in ~A few hours
Hidden costs people mention
  • Self-hosting requires infrastructure and maintenance time.
  • Cloud pricing is not clearly documented, may be costly at scale.
  • No enterprise support tier mentioned in community data.

Viability Score

69/100
Monitor

How well maintained and how widely used is Casdoor? Built from what the vendor actually publishes (docs, changelog, tutorials, integrations, pricing), whether the site is live, and how much real users discuss it. How we calculate this

Recent activity
90
Traction
100
Site health
95
User sentiment
50
What the vendor publishes
20

Last calculated: August 2026

How we score →

Key Features

  • Built-in MCP server with Streamable HTTP
  • OAuth 2.1 with Dynamic Client Registration
  • Per-tool permissions for MCP calls
  • Secure agent-to-agent authentication
  • Support for 100+ identity providers
  • OAuth 2.0, OIDC, SAML, CAS protocols
  • LDAP and WebAuthn support
  • MFA (multi-factor authentication)
  • SSO for multiple applications
  • User registration and password recovery
  • SaaS billing: plans, pricing tiers, payment providers
  • OpenClaw LLM observability via OTLP
  • Web UI for managing users, applications, permissions
  • Customizable login pages
  • SDK for identity auth, user management, resource uploads

About Casdoor

FreeIntermediateAPI availableWeb · API

Casdoor is an open-source Identity and Access Management (IAM) and SSO platform built for the AI agent era. It is the first open-source IAM to include a native MCP server with Streamable HTTP, enabling AI agents to manage users, applications, and permissions via natural language. Every MCP tool call is protected by fine-grained, scope-based authorization, and OAuth 2.1 with Dynamic Client Registration secures agent-to-agent authentication. This makes Casdoor a practical choice for enterprises integrating AI agents while maintaining strong identity controls. Beyond AI-specific features, Casdoor delivers enterprise-grade authentication with support for 100+ identity providers (including Google Workspace and Azure AD) and protocols like OAuth 2.0, OIDC, SAML, CAS, LDAP, WebAuthn, and MFA. Its SaaS management module handles billing plans, pricing tiers, payment providers, and subscriptions, centralizing revenue. Integration with OpenClaw, an observability agent, collects OpenTelemetry traces, metrics, and logs from LLM applications, providing a full runtime audit trail of agent activity. Architecturally, Casdoor is built for scale with clean frontend-backend separation and horizontal scalability for high concurrency. It offers an intuitive console, customizable login pages, and a documented SDK for identity authentication, user management, and resource uploads. Being part of the CNCF Cloud Native Landscape adds credibility for teams seeking a self-hosted, open-source alternative to managed IAM solutions. For teams that need granular identity control over AI agents without the cost of proprietary IAM, Casdoor is a solid, self-hosted contender.

Behind the Verdict

Casdoor stands out in the crowded IAM space by being the first open-source platform to bake in MCP server support natively. That's a meaningful differentiator for teams building AI agents, because it lets those agents manage users, apps, and permissions in natural language — something you'd otherwise have to bolt on yourself. The per-tool permissions and OAuth 2.1 with Dynamic Client Registration show real security thought, not just a demo feature. For enterprise buyers, the support for 100+ identity providers, OAuth 2.0, OIDC, SAML, CAS, LDAP, WebAuthn, and MFA is genuinely enterprise-grade, and the SaaS billing module is a nice bonus for teams monetizing their product. The OpenClaw integration giving you an audit trail of agent activity via OpenTelemetry is forward-looking — it addresses a real need for governance as agents proliferate. Where Casdoor might not fit: if you're looking for a zero-ops managed solution, it's not that — you have to self-host and maintain it. Its MCP features are newer, so expect to dig into docs (which are improving). Compared to Keycloak, Casdoor is less battle-tested in the broader IAM community; compared to Auth0/Okta, you lose the managed convenience but gain cost control and data sovereignty. If you're a technical team already running infrastructure and you care about AI agent identity, Casdoor is a strong, cost-effective choice. If you need hand-holding or have no ops capacity, look elsewhere.

Researching Casdoor? Get your full AI stack in 60 seconds.

Free, no signup — tell us your goal and get tools matched to your budget & existing stack.

Real-world workflow fit

Concrete scenarios for the personas Casdoor actually fits — and what changes day-one when you adopt it.

DevOps engineer at a SaaS startup

You need to add SSO and MFA to your web app without paying per-user licensing.

Outcome: You deploy Casdoor in your cloud, configure Google Workspace as an identity provider, and integrate your app via the SDK — getting SSO, MFA, and user management in under a day.

AI platform architect at an enterprise

You want AI agents (like Claude Desktop or Cursor) to manage users and permissions autonomously but with strict controls.

Outcome: You set up Casdoor's MCP server, define per-tool permissions and OAuth 2.1 client registration, and connect MCP clients — giving you secure, auditable agent-driven identity management.

Platform engineer responsible for LLM observability

You need a full audit trail of what your AI agents actually do at runtime.

Outcome: You deploy OpenClaw configured to export OTLP traces, metrics, and logs to your Casdoor instance, and inspect the structured Entries in the UI — getting complete agent activity logs.

Use Cases

Limitations

  • Casdoor is an open-source, self-hosted IAM platform, so deployment and maintenance require technical expertise.
  • The built-in MCP server and AI agent features are newer additions and may have less mature documentation.
  • The platform supports enterprise-grade authentication and integration with leading identity providers.

as of 2026-09-01

Verification history

We have re-verified Casdoor 8 times since . Each pass re-reads the vendor's own pages and re-checks every listed field against that evidence; passes where nothing had changed are marked as such.

  1. re-checked, vendor evidence unchanged
  2. re-checked, vendor evidence unchanged
  3. re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  4. re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  5. re-checked, vendor evidence unchanged
  6. re-checked, vendor evidence unchanged

Showing the 6 most recent of 8 verification passes.

Free to cite with attribution — this page re-verifies continuously.

Hidden costs & gotchas

What the public pricing page doesn't put in bold. Captured from pricing-page footnotes, contract terms, and recurring complaints.

  • You bear the full cost of hosting, scaling, and maintaining the infrastructure yourself, including uptime and security patching.
  • Newer MCP and AI agent features may require additional engineering time to integrate and debug, as documentation is still maturing.
  • If you need enterprise support or SLAs, you'll have to find or pay for external support, as the project is community-driven.

Where the pricing makes sense

The company stage and team size where Casdoor's pricing actually pencils out — and where peers do it cheaper.

Casdoor is free and open-source, so you pay only for your own infrastructure — a major cost advantage over managed IAM like Okta or Auth0, which charge per user per month. For teams with the engineering capacity to self-host, it's far cheaper at scale, though you trade away managed convenience.

Setup time & first value

How long it actually takes to get something useful out of Casdoor — broken out by persona, not the marketing-page minute.

A basic Casdoor setup can take under an hour for a technical user familiar with Docker and reverse proxies. Integrating it with your first app via the SDK typically adds a few hours. Setting up the MCP server for AI agents may take half a day to configure securely. Expect a few days to fully tailor for production, including custom login pages and scaling.

Switching to or from Casdoor

How to bring data in from common predecessors and how to get it back out — written for the switcher, not the buyer.

Migrating in
  • From Auth0: Export your users and applications via Auth0's API and import them into Casdoor, then update your client libraries to use Casdoor's endpoints.
  • From Okta: Use Okta's SCIM or API to export user data, import into Casdoor, and reconfigure your apps to point to Casdoor.
  • From Keycloak: Use Keycloak's export features to get users and realms, then import them into Casdoor's realm structure.
Migrating out
  • To Auth0: Export users and apps from Casdoor via its API, then bulk-import into Auth0 using their management API.
  • To Okta: Use Casdoor's user export to CSV or JSON to import into Okta's directory via their import tools.
  • To Keycloak: Export users and clients from Casdoor and import them into Keycloak realms using its admin console.

Integrations

Google WorkspaceAzure ADClaude DesktopCursorWindsurfVS CodeGitHub CopilotOpenClawDiscordStack OverflowGoogle Groups

Resources & Guides

Tutorials & Learning

Official links

Tools that pair well with Casdoor

Common stack mates teams adopt alongside Casdoor, with the specific reason each pairing earns its keep.

Featured Head-to-Head Comparisons

Alternatives to Casdoor

View all
Chrome DevTools MCP

Chrome DevTools MCP

Open-source MCP server giving AI agents live control and deep debugging of Chrome DevTools.

FreeTry
CowAgent

CowAgent

Open-source, self-hosted AI agent that plans tasks, runs tools, and evolves memory across 10+ channels.

FreeTry

Popular in Security & Privacy

Push Security

Push Security

Browser-native security that stops AI-driven attacks and secures employee AI usage

FreemiumTry

Frequently Asked Questions

Used Casdoor? Help shape our editorial sentiment research.