Home
Providers
Casdoor
Casdoor
Casdoor is an open-source, AI-first identity and access management (IAM) and MCP gateway authentication server with a web UI. Built in Go (Beego) with a React frontend, Casdoor supports OAuth 2.0, OIDC, SAML 2.0, CAS, LDAP, Kerberos/SPNEGO, WebAuthn / Passkeys, TOTP / MFA, SCIM 2.0 provisioning, social login, multi-tenant organizations, role-based access control, and an MCP Gateway plus A2A Protocol for agent-to-agent communication. The platform exposes a RESTful API documented via Swagger and ships SDKs for Go, Java, Python, Node.js, C#, C++, PHP, Ruby, JavaScript, Lua, and Haskell. Released under the Apache License 2.0.
Casdoor publishes 8 APIs on the APIs.io network, including REST API, Applications API, Authentication API, and 5 more. Tagged areas include Authentication, Authorization, IAM, Identity, and LDAP.
Casdoor’s developer surface includes authentication, documentation, getting-started guide, GitHub presence, engineering blog, pricing, and 17 more developer resources.
1 APIs
1 MCP Servers
22 Features
10 Use Cases
On this page
Kin Score
APIs 15
Open Collections 9
MCP Servers 1
Pricing Plans 1
Rate Limits 1
FinOps 1
Features 22
Security Posture 2
Agentic Access 1
Use Cases 10
Integrations 12
Resources 23
apis.yml
37 Operational Transparency
0 Create-or-Update Ergonomics
Composite quality — 20.8/100 · emerging
Agent readiness — 23/100 · agent aware
Individual APIs this provider publishes, each with its own machine-readable definition.
Scroll for all 15
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
Scroll for all 9
Model Context Protocol servers that expose these APIs to AI agents.
Published pricing tiers and plan structures.
Documented rate limits and quota policies.
Cost, billing, and metering signals for API financial operations.
Notable capabilities this provider offers.
Scroll for all 22
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Recommended x-agentic-access execution contracts for AI agents.
What developers build with this provider.
Scroll for all 10
Pre-built integrations with other platforms and tools.
Scroll for all 12
Get Started 2
Portal, sign-up, and the first successful call
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 2
MCP servers, agent skills, and machine-readable catalogs
Build 3
SDKs, sample code, and the tooling you integrate with
Access & Security 4
Authentication, authorization, and security posture
Operate 4
Status, limits, changes, and where to get help
Commercial 3
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API
Other 1
Properties that don't map to a standard resource type
Source (apis.yml)
aid: casdoor
name: Casdoor
description: Casdoor is an open-source, AI-first identity and access management (IAM) and MCP gateway authentication server
with a web UI. Built in Go (Beego) with a React frontend, Casdoor supports OAuth 2.0, OIDC, SAML 2.0, CAS, LDAP, Kerberos/SPNEGO,
WebAuthn / Passkeys, TOTP / MFA, SCIM 2.0 provisioning, social login, multi-tenant organizations, role-based access control,
and an MCP Gateway plus A2A Protocol for agent-to-agent communication. The platform exposes a RESTful API documented via
Swagger and ships SDKs for Go, Java, Python, Node.js, C#, C++, PHP, Ruby, JavaScript, Lua, and Haskell. Released under the
Apache License 2.0.
type: Index
deliveryModel:
model: unknown
open_source: unknown
commercial: true
callable_host: true
label: Delivery model not determined — needs a product licence on record
confidence: low
source:
- openapi
- pricing
- repository-unlicensed
generated: '2026-08-28'
method: derived
accessModel:
pricing: freemium
onboarding: self-serve
trial: false
try_now: true
public: false
label: Freemium · Self-serve signup
confidence: medium
source:
- plans
- authentication
- security
generated: '2026-09-03'
method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/casdoor.png
tags:
- Authentication
- Authorization
- IAM
- Identity
- LDAP
- MCP
- MFA
- OIDC
- Open-Source
- Passkeys
- SAML
- SCIM
- Single Sign-On
- SSO
- WebAuthn
tags_raw:
- Authentication
- Authorization
- IAM
- Identity
- LDAP
- MCP
- MFA
- OAuth
- OIDC
- Open Source
- Passkeys
- SAML
- SCIM
- Single Sign-On
- SSO
- WebAuthn
url: https://raw.githubusercontent.com/api-evangelist/casdoor/refs/heads/main/apis.yml
created: '2026-03-25'
modified: '2026-05-19'
specificationVersion: '0.23'
apis:
- aid: casdoor:casdoor-rest-api
name: Casdoor REST API
description: The Casdoor REST API provides programmatic access to the IAM platform's core resources including users, organizations,
applications, roles, groups, permissions, identity providers, tokens, sessions, certificates, adapters, syncers, webhooks,
products, payments, MFA enrollments, and enforcers. The API follows RESTful conventions with JSON payloads and is documented
via a hosted Swagger UI.
humanURL: https://casdoor.ai/docs/basic/api
baseURL: https://door.casdoor.com
tags:
- Application
- IAM
- Organization
- REST
- Roles
- Sessions
- Tokens
- User
tags_raw:
- Applications
- IAM
- Organizations
- REST
- Roles
- Sessions
- Tokens
- Users
properties:
- type: Documentation
url: https://casdoor.ai/docs/basic/api
- type: Swagger
url: https://door.casdoor.com/swagger/
- type: GitHubRepository
url: https://github.com/casdoor/casdoor
- type: Authentication
url: https://casdoor.ai/docs/basic/core-concepts
- aid: casdoor:casdoor-oauth-oidc
name: Casdoor OAuth 2.0 / OIDC Provider
description: Casdoor implements an OAuth 2.0 authorization server and OpenID Connect identity provider, exposing the standard
authorization, token, userinfo, revocation, introspection, JWKS, and OIDC discovery endpoints used by web, mobile, native,
and machine-to-machine clients to obtain ID tokens and access tokens.
humanURL: https://casdoor.ai/docs/how-to-connect/oauth
tags:
- Authentication
- JWT
- OIDC
- SSO
- Tokens
tags_raw:
- Authentication
- JWT
- OAuth
- OIDC
- SSO
- Tokens
properties:
- type: Documentation
url: https://casdoor.ai/docs/how-to-connect/oauth
- type: Discovery
url: https://door.casdoor.com/.well-known/openid-configuration
- type: Specification
url: https://datatracker.ietf.org/doc/html/rfc6749
- aid: casdoor:casdoor-saml
name: Casdoor SAML 2.0 Identity Provider
description: SAML 2.0 identity provider endpoints in Casdoor that issue SAML assertions to enterprise service providers,
supporting SSO scenarios for legacy and enterprise SaaS applications via standard SAML metadata, ACS, and SLO bindings.
humanURL: https://casdoor.ai/docs/how-to-connect/saml
tags:
- Enterprise SSO
- Federation
- SAML
- SSO
properties:
- type: Documentation
url: https://casdoor.ai/docs/how-to-connect/saml
- type: Specification
url: http://docs.oasis-open.org/security/saml/v2.0/
- aid: casdoor:casdoor-cas
name: Casdoor CAS Server
description: Casdoor exposes a CAS (Central Authentication Service) server compatible with CAS protocol versions 1.0, 2.0,
and 3.0, providing single sign-on to applications that integrate via the CAS ticket-validation flow.
humanURL: https://casdoor.ai/docs/how-to-connect/cas
tags:
- Authentication
- CAS
- SSO
properties:
- type: Documentation
url: https://casdoor.ai/docs/how-to-connect/cas
- aid: casdoor:casdoor-ldap
name: Casdoor LDAP Server
description: Casdoor provides an LDAP server interface so that legacy applications and infrastructure components requiring
LDAP authentication can bind against Casdoor users and groups, and a sync engine that imports users from external LDAP
directories.
humanURL: https://casdoor.ai/docs/ldap/overview
tags:
- Directory
- LDAP
- Sync
properties:
- type: Documentation
url: https://casdoor.ai/docs/ldap/overview
- aid: casdoor:casdoor-scim
name: Casdoor SCIM 2.0 API
description: SCIM 2.0 (System for Cross-domain Identity Management) endpoints for automated user and group provisioning
between Casdoor and downstream identity-aware systems.
humanURL: https://casdoor.ai/docs/scim/overview
tags:
- Identity
- Provisioning
- SCIM
properties:
- type: Documentation
url: https://casdoor.ai/docs/scim/overview
- type: Specification
url: https://datatracker.ietf.org/doc/html/rfc7644
- aid: casdoor:casdoor-mcp-gateway
name: Casdoor MCP Gateway
description: Casdoor's MCP (Model Context Protocol) gateway and A2A (Agent-to-Agent) protocol surface, designed to broker
authentication and authorization for AI agents and MCP-aware tooling using Casdoor as the identity provider.
humanURL: https://casdoor.ai/docs/mcp/overview
tags:
- A2A
- Agents
- Artificial Intelligence
- MCP
tags_raw:
- A2A
- Agents
- AI
- MCP
properties:
- type: Documentation
url: https://casdoor.ai/docs/mcp/overview
- aid: casdoor:casdoor-webhooks
name: Casdoor Webhooks
description: Outbound webhook events that notify external systems of identity events such as user signup, login, logout,
profile changes, password resets, and MFA enrollments.
humanURL: https://casdoor.ai/docs/integration/webhook
tags:
- Event
- Integration
- Webhook
tags_raw:
- Events
- Integration
- Webhooks
properties:
- type: Documentation
url: https://casdoor.ai/docs/integration/webhook
- aid: casdoor:casdoor-applications-api
name: Casdoor Applications API
description: OAuth/OIDC client applications
humanURL: https://casdoor.ai/docs/basic/api
baseURL: https://door.casdoor.com
tags:
- Application
tags_raw:
- Applications
properties:
- type: OpenAPI
url: openapi/casdoor-applications-api-openapi.yml
- aid: casdoor:casdoor-authentication-api
name: Casdoor Authentication API
description: Login, callback, and device authorization
humanURL: https://casdoor.ai/docs/basic/api
baseURL: https://door.casdoor.com
tags:
- Authentication
properties:
- type: OpenAPI
url: openapi/casdoor-authentication-api-openapi.yml
- aid: casdoor:casdoor-oidc-api
name: Casdoor OIDC API
description: OpenID Connect discovery and JWKS endpoints
humanURL: https://casdoor.ai/docs/basic/api
baseURL: https://door.casdoor.com
tags:
- OIDC
properties:
- type: OpenAPI
url: openapi/casdoor-oidc-api-openapi.yml
- aid: casdoor:casdoor-organizations-api
name: Casdoor Organizations API
description: Multi-tenant organization management
humanURL: https://casdoor.ai/docs/basic/api
baseURL: https://door.casdoor.com
tags:
- Organization
tags_raw:
- Organizations
properties:
- type: OpenAPI
url: openapi/casdoor-organizations-api-openapi.yml
- aid: casdoor:casdoor-permissions-api
name: Casdoor Permissions API
description: Casbin policy enforcement
humanURL: https://casdoor.ai/docs/basic/api
baseURL: https://door.casdoor.com
tags:
- Permissions
properties:
- type: OpenAPI
url: openapi/casdoor-permissions-api-openapi.yml
- aid: casdoor:casdoor-roles-api
name: Casdoor Roles API
description: Role-based access control
humanURL: https://casdoor.ai/docs/basic/api
baseURL: https://door.casdoor.com
tags:
- Roles
properties:
- type: OpenAPI
url: openapi/casdoor-roles-api-openapi.yml
- aid: casdoor:casdoor-users-api
name: Casdoor Users API
description: User CRUD and credential operations
humanURL: https://casdoor.ai/docs/basic/api
baseURL: https://door.casdoor.com
tags:
- User
tags_raw:
- Users
properties:
- type: OpenAPI
url: openapi/casdoor-users-api-openapi.yml
common:
- type: Releases
url: https://github.com/casdoor/casdoor/releases
- type: SecurityPolicy
url: https://github.com/casdoor/casdoor/blob/master/SECURITY.md
- type: AgenticAccess
url: agentic-access/casdoor-agentic-access.yml
- type: DomainSecurity
url: security/casdoor-domain-security.yml
- type: Authentication
url: authentication/casdoor-authentication.yml
- type: Website
url: https://casdoor.org
- type: Documentation
url: https://casdoor.ai/docs/overview
- type: GettingStarted
url: https://casdoor.ai/docs/basic/server-installation
- type: Authentication
url: https://casdoor.ai/docs/basic/core-concepts
- type: Swagger
url: https://door.casdoor.com/swagger/
- type: GitHub
url: https://github.com/casdoor/casdoor
- type: GitHubOrganization
url: https://github.com/casdoor
- type: SourceCode
url: https://github.com/casdoor/casdoor
- type: IssueTracker
url: https://github.com/casdoor/casdoor/issues
- type: Blog
url: https://casdoor.org/blog
- type: Community
url: https://casdoor.ai/docs/community/forum
- type: Discord
url: https://discord.gg/5rPsrAzK7S
- type: License
url: https://github.com/casdoor/casdoor/blob/master/LICENSE
- type: DockerHub
url: https://hub.docker.com/r/casbin/casdoor
- type: Demo
url: https://door.casdoor.com
- type: PrivacyPolicy
url: https://casdoor.org/privacy
- type: Pricing
url: https://casdoor.com/pricing
- name: Features
type: Features
data:
- name: OAuth 2.0 Server
- name: OIDC Provider
- name: SAML 2.0 IdP
- name: CAS Server
- name: LDAP Server
- name: SCIM 2.0 Provisioning
- name: WebAuthn / Passkeys
- name: TOTP MFA
- name: Face ID Biometrics
- name: Social Login
- name: RBAC
- name: ABAC
- name: ACL
- name: Multi-Tenancy
- name: Organizations
- name: Audit Logs
- name: Webhooks
- name: Identity Provider Federation
- name: MCP Gateway
- name: A2A Protocol
- name: Self-Hosted
- name: Apache 2.0 License
- name: UseCases
type: UseCases
data:
- name: Single Sign-On
- name: Customer Identity (CIAM)
- name: Workforce Identity
- name: Passwordless Login
- name: Multi-Factor Authentication
- name: Enterprise SSO via SAML
- name: API Authorization
- name: Identity Provider for AI Agents
- name: User Provisioning Automation
- name: Self-Hosted Auth Server
- name: Integrations
type: Integrations
data:
- name: GitHub
- name: Google
- name: Azure AD
- name: WeChat
- name: QQ
- name: MySQL
- name: PostgreSQL
- name: SQL Server
- name: Redis
- name: Beego
- name: React
- name: Casbin
- name: MCP Server
url: https://github.com/casdoor/public-mcp-server-registry
type: MCPServer
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
Every provider here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for providers
9 MCP tools reach this
find_providersBrowse and filter every provider in the catalog.
get_provider_artifactsEvery artifact this provider publishes, grouped by type.
get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
get_provider_ratingPRO — composite, band, trend and facet scores.
apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
resolveTurn a domain, URL or GitHub org into the provider it belongs to.
find_cohortsEvery scored population of providers in the catalog.
All 92 tools →
Call it yourself
curl for this page
This provider
curl "https://apis.io/api/v1/providers/casdoor"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/casdoor/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/casdoor/evidence"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms .
A second provider on the same verified email joins the account you already have.