pac4j is a free, open source identity & access management (iam) project written in Java and released under Apache-2.0. It has 2,530 GitHub stars, 711 forks and 5 open issues, and was last pushed 13 hours ago. On this registry it ranks #29 of 54 tracked projects in Identity & Access Management (IAM), with 5 head-to-head comparisons available.

What is pac4j?

pac4j is a security engine for Java that adds authentication and authorization — across OpenID Connect, SAML 2, CAS, OAuth, JWT, LDAP and more — to any Java framework through one shared API.

What it is

pac4j is an open-source Java security library, developed since 2013 and released under the Apache 2 license, that implements a single set of concepts and configuration and applies them across many frameworks: Spring Boot (Web MVC, Spring Security and WebFlux variants), Jakarta EE, Play 2.x and 3.x, Vert.x, Javalin, JAX-RS, Dropwizard, Spark Java, Undertow, Apache Shiro, Ratpack and Lagom. It acts as a client-side security layer: you declare an identity provider and the URL patterns to protect, and pac4j handles the protocol exchange and hands you the resulting user profile through the ProfileManager.

The concrete problem it solves is that Java applications otherwise need a different security integration for every protocol and every framework. With pac4j, swapping the identity provider — Keycloak, Microsoft Entra ID, Google, GitHub, Okta, Auth0, any SAML IdP or CAS server — is a matter of changing the client configuration rather than rewriting the security layer, and the same configuration approach carries across frameworks.

Key capabilities

  • Supports OpenID Connect, SAML 2, CAS, OAuth 1.0 and 2.0, JWT, LDAP, Kerberos and HTTP authentication under one API.
  • Provides authorization and web security controls including roles, authentication levels, CSRF protection, CORS and security headers.
  • Integrates with Spring Web MVC, Spring Security, Spring WebFlux, Jakarta EE, Play, Vert.x, Javalin, JAX-RS, Dropwizard, Spark Java, Undertow, Apache Shiro, Ratpack and Lagom.
  • Ships as Maven modules such as org.pac4j:spring-webmvc-pac4j (8.0.3) and org.pac4j:pac4j-oidc (6.5.9).
  • Reads OpenID Connect provider configuration from a discovery endpoint, as in OidcConfiguration.setDiscoveryURI(...) with setClientId and setSecret.
  • Intercepts protected paths declaratively, for example addSecurity(registry, "OidcClient").addPathPatterns("/protected/**").
  • Implements newer specifications including OpenID for Verifiable Presentations (EUDI wallet, eIDAS 2.0) and OpenID Federation.

Who uses it and how

  • Teams securing Spring Boot applications with OpenID Connect, defining a Config bean and adding interceptors so that /protected/** requires login.
  • Jakarta EE, Play, Vert.x, Javalin and JAX-RS shops that need SAML or CAS without changing their framework.
  • Organizations embedded in larger identity stacks: pac4j is used inside Apereo CAS, Apache Syncope and Apache Knox.
  • Developers integrating against enterprise providers such as Keycloak, Microsoft Entra ID, Okta and Auth0, or any SAML IdP or CAS server.
  • Framework authors and integrators who want one security abstraction across Spring Boot, Apache Shiro and Undertow deployments.

Getting started

Add org.pac4j:spring-webmvc-pac4j and org.pac4j:pac4j-oidc from Maven Central, then extend Pac4jSecurityConfig, register a Config bean with your OidcClient, and add the security interceptor to the paths you want protected; runnable demos are available in the simple-spring-boot-pac4j-demos repository.

How it compares

pac4j stands alone in this registry as an independent, framework-agnostic security engine; the facts name only the frameworks it plugs into — Spring Security, Apache Shiro, Undertow and others — as integration targets rather than as alternatives. Its distinguishing position is one Apache-2.0-licensed API covering many protocols at once, embedded in projects such as Apereo CAS, Apache Syncope and Apache Knox.

When to use it — and when not

Because pac4j is a client-side library rather than an identity provider, you still need to run or subscribe to an actual IdP — Keycloak, a SAML IdP, a CAS server or a hosted provider — and handle the application-side profile storage yourself. It is a poor fit for teams that want a batteries-included framework security stack with built-in user management, and integrators should note that the README is largely a marketing-style overview with per-framework guides hosted externally on pac4j.org. The project is actively maintained, with five open issues and a push on 30 September 2026, and is licensed under Apache-2.0.

project readme (upstream, from github) — read inline

pac4j

The security engine for Java: one API to add OpenID Connect, SAML, CAS, OAuth, JWT, LDAP... authentication and authorization to any Java framework.

Maven Central Build status Java 17+ Apache 2 license GitHub stars

Documentation • Quick start • Frameworks • Concepts • Help


✨ Why pac4j?

  • 🧩 One security engine, every framework: the same concepts and the same configuration for Spring Boot, Jakarta EE, Play, Vert.x, Javalin, JAX-RS and many more.
  • 🔐 All the major protocols: OpenID Connect, SAML 2, CAS, OAuth 1.0 & 2.0, JWT, LDAP, Kerberos, HTTP... Log in with Keycloak, Microsoft Entra ID, Google, GitHub, Okta, Auth0, any SAML IdP or CAS server.
  • 🛡️ Authorization & web security built in: roles, authentication levels, CSRF protection, CORS and security headers.
  • 🚀 Ready for the future: OpenID for Verifiable Presentations (EUDI wallet, eIDAS 2.0) and OpenID Federation.
  • 🏭 Battle-tested: developed since 2013 and embedded in Apereo CAS, Apache Syncope and Apache Knox.
  • 📜 Open source under the Apache 2 license.

⚡ Quick start (Spring Boot + OpenID Connect)

Add the Spring MVC integration and the OpenID Connect module:

<dependency>
    <groupId>org.pac4j</groupId>
    <artifactId>spring-webmvc-pac4j</artifactId>
    <version>8.0.3</version>
</dependency>
<dependency>
    <groupId>org.pac4j</groupId>
    <artifactId>pac4j-oidc</artifactId>
    <version>6.5.9</version>
</dependency>

Then define your identity provider and the URLs to protect:

@Configuration
public class SecurityConfig extends Pac4jSecurityConfig {

    @Bean
    public Config config() {
        final var oidc = new OidcConfiguration()
            .setDiscoveryURI("https://www.casserverpac4j.dev/oidc/.well-known/openid-configuration")
            .setClientId("myclient")
            .setSecret("mysecret")
            .setAllowUnsignedIdTokens(true); // only for this demo server
        return new Config("http://localhost:8080/callback", new OidcClient(oidc));
    }

    @Override
    public void addInterceptors(final InterceptorRegistry registry) {
        addSecurity(registry, "OidcClient").addPathPatterns("/protected/**");
    }
}

That's it: /protected/** now requires an OpenID Connect login, and the user profile is available through the ProfileManager. Switching to Keycloak, Google or Microsoft Entra ID is a matter of changing the client: read the full guide or run the demo.

🧭 Get started with your framework

Framework Get started
Spring Web MVC / Spring Boot OpenID Connect guide
Spring Security / Spring Boot OpenID Connect guide
Spring WebFlux / Spring Boot OpenID Connect guide
Jakarta EE OpenID Connect guide
Play 2.x / 3.x SAML guide
Vert.x CAS guide
Javalin SAML guide
JAX-RS OpenID Connect guide
Dropwizard OpenID Connect guide
Spark Java OpenID Connect guide
Undertow OpenID Connect guide
Apache Shiro CAS guide
Ratpack • Lagom • Akka HTTP • Jooby Ratpack • Lagom • Akka HTTP • Jooby

pac4j also powers the authentication delegation of Apereo CAS, Apache Syncope and Apache Knox.

🔑 Authentication mechanisms

Login protocols Credentials validation
OpenID Connect • SAML • CAS • OAuth • HTTP • Kerberos • OpenID4VP (EUDI wallet, eIDAS 2.0) LDAP • SQL • JWT • MongoDB • IP address • REST API

🛡️ Authorization mechanisms

🧪 Advanced mechanisms

OpenID Federation • OpenID for Verifiable Presentations (EUDI wallet, eIDAS 2.0)

📦 Versions

JDK pac4j Usage of Lombok
17 v6.x Yes
11 v5.x No
8 v4.x No

The latest released version is Maven Central. The next version is under development. See the release notes.

🤖 Use of AI

This project is developed using various AI tools across multiple areas, including development, testing, and documentation.

💬 Need help?

🤝 Contributing

Contributions are welcome: read the contribution guide to get started.

⭐ If pac4j is useful to you, please star this repository: it helps other developers discover it!

💙 Supported by

CAS in the cloud The CAS and pac4j consulting company

NLnet NLnet foundation

Frequently asked questions

Is pac4j free to use?

pac4j is open source under the Apache-2.0 licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does pac4j do?

Security engine for Java (authentication, authorization, multi frameworks): OpenID Connect, SAML2, CAS, OAuth, LDAP, JWT...

What is pac4j written in?

pac4j is primarily written in Java. Its source is publicly available at https://github.com/pac4j/pac4j, and it has 2,530 GitHub stars.