Ross ROSS = Recommend OSS · open-source software intelligence for agents

dromara/MaxKey

Dromara MaxKey 🗝️ SSO ,Leading-Edge IAM-IDaas(Identity and Access Management) Product , Under Apache-2.0 is free ,业界领先的IAM-IDaas身份管理和认证产品,遵循Apache-2.0开源免费,支持OAuth2.x、OpenID Connect、SAML2.0、CAS、JWT、SCIM等SSO标准协议,基于RBAC统一权限控制,实现用户生命周期管理,开源、安全、合规、自主可控。 observed · 2026-08-28

github.com/dromara/MaxKey · homepage · Java · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

92/100

  • Activity 99
  • Release rhythm 78
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 54.0
  • age_days: 3577
  • days_rel: 64
  • days_push: 10
  • n_releases_24m: 11

Full methodology

Adoption not part of the score

1940 stars · 411 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

MaxKey is an open-source IAM/IDaaS product providing Single Sign-On (SSO), identity management, and RBAC-based access control. It supports standard protocols including OAuth 2.x/OpenID Connect, SAML 2.0, JWT, CAS, and SCIM 2, with MFA, LDAP/Active Directory integration, and multi-tenancy.

Use cases

  • implement single sign-on across multiple enterprise applications
  • self-hosted identity and access management (IAM) platform
  • centralize authentication with OAuth2, OIDC, SAML, and CAS
  • manage user lifecycle and provisioning with SCIM and LDAP sync
  • add multi-factor authentication (TOTP, SMS, passkeys) to logins
  • enforce RBAC permissions across internal apps
  • integrate Active Directory or Kerberos domain authentication
  • multi-tenant identity management for a group of companies

When to choose

  • you need a free, Apache-2.0 licensed, self-hosted SSO/IAM solution supporting many standard protocols
  • your organization uses Active Directory, LDAP, or Chinese enterprise tools (WeCom, DingTalk, Feishu) and needs connectors
  • you require MFA, social login, and passkey support out of the box
  • you need multi-tenancy and RBAC with an admin console

When to avoid

  • you need a lightweight embedded auth library rather than a full standalone identity platform
  • you require cloud-managed IDaaS with zero infrastructure
  • your stack is not Java/JVM-friendly or you cannot run MySQL/Redis/Tomcat dependencies
  • you need features gated behind the enterprise edition, such as fine-grained authorization or HR sync connectors

Facets

application · maturity active

auth authorization security self-hosted middleware security backend web-development self-hosted erp jvm self-hosted sso iam idaas single-sign-on oauth2 openid-connect saml cas scim rbac mfa ldap active-directory kerberos multi-tenancy identity-management user-lifecycle passkey webauthn linux docker web-server

10 sources

Member repositories

RepositoryRoleHealth v2
dromara/MaxKeymain92

For agents

markdown · JSON · MCP: product_card(name="dromara/MaxKey")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem