The security engine for Java: one API to add OpenID Connect, SAML, CAS, OAuth, JWT, LDAP... authentication and authorization to any Java framework.
Documentation • Quick start • Frameworks • Concepts • Help
✨ Why pac4j?
- 🧩 One security engine, every framework: the same concepts and the same configuration for Spring Boot, Jakarta EE, Play, Vert.x, Javalin, JAX-RS and many more.
- 🔐 All the major protocols: OpenID Connect, SAML 2, CAS, OAuth 1.0 & 2.0, JWT, LDAP, Kerberos, HTTP... Log in with Keycloak, Microsoft Entra ID, Google, GitHub, Okta, Auth0, any SAML IdP or CAS server.
- 🛡️ Authorization & web security built in: roles, authentication levels, CSRF protection, CORS and security headers.
- 🚀 Ready for the future: OpenID for Verifiable Presentations (EUDI wallet, eIDAS 2.0) and OpenID Federation.
- 🏭 Battle-tested: developed since 2013 and embedded in Apereo CAS, Apache Syncope and Apache Knox.
- 📜 Open source under the Apache 2 license.
⚡ Quick start (Spring Boot + OpenID Connect)
Add the Spring MVC integration and the OpenID Connect module:
<dependency>
<groupId>org.pac4j</groupId>
<artifactId>spring-webmvc-pac4j</artifactId>
<version>8.0.3</version>
</dependency>
<dependency>
<groupId>org.pac4j</groupId>
<artifactId>pac4j-oidc</artifactId>
<version>6.5.9</version>
</dependency>
Then define your identity provider and the URLs to protect:
@Configuration
public class SecurityConfig extends Pac4jSecurityConfig {
@Bean
public Config config() {
final var oidc = new OidcConfiguration()
.setDiscoveryURI("https://www.casserverpac4j.dev/oidc/.well-known/openid-configuration")
.setClientId("myclient")
.setSecret("mysecret")
.setAllowUnsignedIdTokens(true); // only for this demo server
return new Config("http://localhost:8080/callback", new OidcClient(oidc));
}
@Override
public void addInterceptors(final InterceptorRegistry registry) {
addSecurity(registry, "OidcClient").addPathPatterns("/protected/**");
}
}
That's it: /protected/** now requires an OpenID Connect login, and the user profile is available through the ProfileManager.
Switching to Keycloak, Google or Microsoft Entra ID is a matter of changing the client:
read the full guide or run the demo.
🧭 Get started with your framework
| Framework | Get started |
|---|---|
| Spring Web MVC / Spring Boot | OpenID Connect guide |
| Spring Security / Spring Boot | OpenID Connect guide |
| Spring WebFlux / Spring Boot | OpenID Connect guide |
| Jakarta EE | OpenID Connect guide |
| Play 2.x / 3.x | SAML guide |
| Vert.x | CAS guide |
| Javalin | SAML guide |
| JAX-RS | OpenID Connect guide |
| Dropwizard | OpenID Connect guide |
| Spark Java | OpenID Connect guide |
| Undertow | OpenID Connect guide |
| Apache Shiro | CAS guide |
| Ratpack • Lagom • Akka HTTP • Jooby | Ratpack • Lagom • Akka HTTP • Jooby |
pac4j also powers the authentication delegation of Apereo CAS, Apache Syncope and Apache Knox.
🔑 Authentication mechanisms
| Login protocols | Credentials validation |
|---|---|
| OpenID Connect • SAML • CAS • OAuth • HTTP • Kerberos • OpenID4VP (EUDI wallet, eIDAS 2.0) | LDAP • SQL • JWT • MongoDB • IP address • REST API |
🛡️ Authorization mechanisms
| User profile | Web request |
|---|---|
| Roles • Anonymous / remember-me / (fully) authenticated • Profile type, attribute | CORS • CSRF • Security headers • IP address, HTTP method |
🧪 Advanced mechanisms
OpenID Federation • OpenID for Verifiable Presentations (EUDI wallet, eIDAS 2.0)
📦 Versions
| JDK | pac4j | Usage of Lombok |
|---|---|---|
| 17 | v6.x | Yes |
| 11 | v5.x | No |
| 8 | v4.x | No |
The latest released version is .
The next version is under development.
See the release notes.
🤖 Use of AI
This project is developed using various AI tools across multiple areas, including development, testing, and documentation.
💬 Need help?
- 📖 Read the documentation
- ✉️ Ask on the mailing lists
- 🏢 Get commercial support
- 🔒 Report a vulnerability: see the security policy
🤝 Contributing
Contributions are welcome: read the contribution guide to get started.
⭐ If pac4j is useful to you, please star this repository: it helps other developers discover it!

