jans is a free, open source identity & access management (iam) project written in Java and released under Apache-2.0. It has 652 GitHub stars, 176 forks and 489 open issues, and was last pushed 2 hours ago. On this registry it ranks #60 of 65 tracked projects in Identity & Access Management (IAM), with 5 head-to-head comparisons available.

What is jans?

Janssen is a Linux Foundation open source identity and access management project for teams that need to run OAuth 2.0/OpenID Connect single sign-on, low-code authentication flows, and policy-based authorization on infrastructure they control.

What it is

Janssen is a collection of open source IAM components developed under the Linux Foundation, with the Gluu team driving day-to-day priorities under a community Technical Steering Committee. Its three headline components are Auth Server, which implements the OAuth 2.0 and OpenID Connect protocols; Agama, a low-code framework for identity orchestration; and Cedarling, a policy decision point. The "Janssen Server" distributions bundle these components together under a single control plane, and the project ships binaries, cloud-native deployment assets and documentation alongside the code.

The concrete problem it addresses is that organizations implementing digital identity and access management typically have to assemble and stitch together a token issuer, a login flow builder, and a policy engine as separate pieces of software. Janssen replaces that patchwork with components distributed together and governed by a common maturity-stage process, so a self-hoster obtains an authorization server, low-code orchestration layer, and policy decision point from one project rather than three unrelated ones. The repository lives in the Java ecosystem and covers the access-management, api, identity, oauth2, openid-connect, sso and kubernetes topics.

Key capabilities

  • Auth Server issues and validates tokens under the OAuth 2.0 and OpenID Connect protocols, providing API-scoped access management and single sign-on.
  • Agama provides low-code identity orchestration, letting teams define authentication flows declaratively rather than writing each flow in code.
  • Cedarling operates as a policy decision point, evaluating authorization policy alongside the authentication stack.
  • The "Janssen Server" distribution bundles the components under one control plane instead of requiring separate administration of each service.
  • Cloud-native deployment assets are provided, including a janssen-auth-server Helm chart published on Artifact Hub for Kubernetes.
  • Each component is published with an explicit lifecycle stage, so adopters can see which parts are stable versus still demos.
  • Releases, all release tags, documentation, contribution guides and developer guides are published, with builds carrying SLSA 3 provenance and OpenSSF scorecard and best-practices badges.

Who uses it and how

  • Enterprises running a production deployment can take the open source components and self-manage them, or take Gluu's commercial distribution for supported operations.
  • Platform teams deploy it onto Kubernetes using the published Helm chart from Artifact Hub rather than installing from binaries.
  • Integrators building products or mission-critical cybersecurity services assemble Auth Server, Agama and Cedarling into a single sign-on and policy stack.
  • Contributors participate through GitHub Discussions and the project's chat room, with priorities guided by the Technical Steering Committee.
  • New adopters and administrators use the documentation at docs.jans.io and Gluu Academy to learn the deployment and administration workflow.

Getting started

Install the janssen-auth-server Helm chart from Artifact Hub to deploy on Kubernetes, or take the latest release from the project's GitHub releases page, following the deployment documentation at docs.jans.io.

How it compares

Janssen is Apache-2.0 licensed and self-hostable, so operators keep the software, the deployment and the identity data under their own control with no licence fee; Gluu Flex and Gluu Solo are Gluu's commercial distributions of the same Janssen Project components, sold as supported products for production use. The practical difference is therefore the cost model and support relationship rather than the underlying capability: the same components are available either as open source you operate yourself or as a commercial offering.

When to use it — and when not

A self-hoster must operate the cloud-native deployment assets, which in practice means running Kubernetes and administering the bundled control plane for Auth Server, Agama and Cedarling. It is a poor fit for teams that want a hosted identity service with no infrastructure to run, or who need everything polished immediately, since the project itself notes its components sit at different maturity stages and the repository currently carries 489 open issues.

project readme (upstream, from github) — read inline

Janssen Project - Open Source Digital Identity Infrastructure Software

Welcome to the Janssen Project

The Linux Foundation DPG Badge

Janssen is a self-funded project chartered directly under the Linux Foundation to foster the development of enterprise digital identity and access management infrastructure. As the lead Contributors, the Gluu team drives the priorities on a day-to-day basis, governed and guided by the Janssen community Technical Steering Committee.

There are several Janssen Components in different stages of development, from demos to stable releases. Janssen Project software has batteries included. You will find binaries, cloud-native deployment assets, documentation and more-- enabling you to build a product or mission-critical cybersecurity service with Janssen software.

If your enterprise needs Janssen for a production deployment, Gluu offers a commercial distribution of Janssen Project Components called Gluu Flex and Gluu Solo.


Releases: Latest | All

Get Help: Discussions | Chat

Docs: Documentation

Contribute: Contribution Guide | Community Docs | Developer Guides

Social: Linkedin | YouTube

Resources to learn more: Gluu Academy

Artifact Hub OpenSSF Scorecard OpenSSF Best Practices SLSA 3 Hex.pm GitHub contributors Conventional Commits


Janssen Components

The table below lists components of the Janssen Project and their maturity stages.

Component Description Lifecycle Stage
Jans Auth Server A complete OAuth Authorization Server and a certified OpenID Connect Provider written in Java. It's the upstream open-source core of Gluu Flex. Graduated
Agama Agama offers an interoperable way to design authentication flows, coded in a DSL purpose-built for writing identity journeys. Graduated
Jans FIDO Enables end-users to enroll and authenticate with passkeys and other FIDO authenticators. Graduated
Jans SCIM SCIM JSON/REST API for user management, including associated FIDO devices. Graduated
Jans Config API RESTful APIs manage configuration for all Janssen components. Graduated
Text UI ("TUI") User interface accessible from command line. TUI is text-based interactive configuration tool that leverages config-API to configure Janssen Server modules Graduated
Jans CLI Command line configuration tools to help you correctly call the Config API. Graduated
Jans Casa Jans Casa is a self-service web portal for end-users to manage authentication and authorization preferences for their account in the Janssen Server Graduated
Jans Cedarling Cedarling is an embeddable stateful Policy Decision Point for authorization requests. In simple terms, the Cedarling returns the answer: should the application allow this action on this resource given these JWT tokens. It is written in Rust with bindings to WASM, iOS, Android, and Python. Graduated
Jans Lock An enterprise authorization solution featuring the Cedarling, a stateless PDP and the Lock Server which centralizes audit logs and configuration. Incubating
Janssen Tarp An OpenID Connect RP test website that runs as a browser plugin in Chrome or Firefox. Incubating
Jans Chip Sample iOS and Android mobile applications that implement the full OAuth and FIDO security stack for app integrity, client constrained access tokens, and user presence. Demo

Installation

The Janssen Project offers several installation options to fit different needs:

  1. Helm deployments for production-grade setup on Kubernetes like Amazon, Google, Microsoft, Local, and Rancher
  2. Docker deployment for development/testing (not production)
  3. VM packages for Ubuntu, SUSE and Red Hat

Check out the Janssen Documentation for details.

Community

A BIG thanks to all the amazing contributors!! 👏 👏

Building a diverse and inclusive community is an important goal. Please let us know what we can do to make you feel more welcome, no matter what you want to contribute.

Code of Conduct / Contribution Guidelines / Security

  • Janssen code of conduct ensures that the Janssen community is a welcoming place for everyone.

  • Start with the Contribution Guide for an introduction on the Janssen development lifecycle.

  • If you think you found a security vulnerability, please refrain from posting it publicly on the forums, the chat, or GitHub. Instead, email us at security@jans.io. Refer to Janssen Security Policy

Governance

Janssen is a self-funded Linux Foundation project, governed according to the charter. Technical oversight of the project is the responsibility of the Technical Steering Committee ("TSC"). Day-to-day decision-making is in the hands of the Contributors. The TSC helps to guide the direction of the project and to improve the quality and security of the development process.

Support

If you find a bug in the Janssen project, would like to suggest a new feature, or have a "howto" question, please post on GitHub Discussions, which is the main channel for community support. There is also a community chat on Zulip.

Releases

Check out the latest release of the Janssen Project for new features and updates.

Janssen History

In 2020, Gluu decided to give contributors a role in the governance and collaborated with the Linux Foundation to charter the Janssen Project. The initial software contribution for the Janssen Project was a fork of the Gluu Server version 4. Subsequently, the Janssen Project developers added a new configuration control plane, tools, demos, documentation, packaging and deployment assets.

Why the name Janssen?

Pigeons (or doves...) are universally regarded as a symbol of peace--which we need more of today. But pigeons are also really fast, capable of flying 1000 kilometers in a single day, powered by a handful of seeds. The Janssen brothers of Arendonk in Belgium bred the world's fastest family of racing pigeons. Janssen racing pigeons revolutionized the sport. The Janssen Project seeks to revolutionize how open-source digital identity scales in the clouds.

Frequently asked questions

Is jans free to use?

jans is open source under the Apache-2.0 licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does jans do?

The Janssen Project is a home for open source IAM components, featuring Auth Server (OAuth/OpenID), Agama low-code identity orchestration, and the Cedarling pol

What is jans written in?

jans is primarily written in Java. Its source is publicly available at https://github.com/JanssenProject/jans, and it has 652 GitHub stars.