Shadow SSO is an open-source identity and access management platform. Secure, extensible, and fully spec-compliant — ready for production.
Capabilities
Production-ready authentication infrastructure, so you can focus on building your product.
Full spec-compliant implementation supporting authorization code, PKCE, client credentials, refresh tokens, and implicit flows.
Built-in TOTP, email OTP, and push notification MFA. Protect every user with layered security that's still easy to use.
Connect Google, GitHub, Apple, LDAP, and any OIDC-compatible identity provider with automatic account federation.
Full Keycloak-style GraphQL API for users, clients, roles, groups, and realm settings — introspectable and developer-friendly.
Type-safe, high-performance Connect-RPC services for user management, two-factor auth, clients, identity providers, and service accounts.
Prometheus metrics, OpenTelemetry tracing, and structured zerolog logging ready out of the box — plug straight into your stack.
Standards
Live Endpoints
All standard OAuth 2.0 and OpenID Connect endpoints are available right now.
Sign in or explore the live OpenID Connect discovery document to integrate with your application.