phpCAS is a free, open source identity & access management (iam) project written in PHP and released under Apache-2.0. It has 800 GitHub stars, 419 forks and 29 open issues, and was last pushed 3 months ago. On this registry it ranks #53 of 63 tracked projects in Identity & Access Management (IAM), with 5 head-to-head comparisons available.

What is phpCAS?

phpCAS is a PHP authentication library for application developers who need to sign users in through a Central Authentication Service (CAS) server as part of a single sign-on setup.

What it is

phpCAS is an open-source client library written in PHP and maintained by the Apereo Foundation under the Apache License, Version 2.0. It sits inside the PHP ecosystem and is published in this registry under the Security & Privacy / Identity & Access Management category, with topic tags covering authentication, cas, php, and sso. The project is documented through its project site at https://apereo.github.io/phpCAS/, which hosts a wiki and a separate API reference at https://apereo.github.io/phpCAS/api/, and the repository reports roughly 800 stars and 419 forks.

The concrete problem it addresses is that a PHP application otherwise has to implement the CAS protocol itself in order to authenticate users. phpCAS removes that work by acting as the CAS client: an application calls the library, which handles the conversation with a Central Authentication Service server and returns an authenticated user, so developers do not hand-roll single sign-on logic. In effect it replaces a from-scratch CAS client implementation with a maintained library that has documented API surface and a published set of guides.

Key capabilities

  • Authenticates users of PHP applications against a CAS server through a single client library, which is the core function described in the README.
  • Provides single sign-on (SSO) support for PHP, as reflected in the project's authentication, cas, php, and sso topic classification.
  • Exposes a documented application programming interface published at https://apereo.github.io/phpCAS/api/.
  • Ships written guidance through a dedicated wiki site at https://apereo.github.io/phpCAS/, referenced as the starting point in the README.
  • Runs an automated test workflow in GitHub Actions, visible as the test.yml workflow status badge in the README.
  • Is distributed under the Apache License, Version 2.0, with the full licence text and Apereo Foundation copyright (2007-2026) included in the repository.
  • Maintains an open issue tracker, currently listing 29 open issues, with development activity recorded as recently as 30 June 2026.

Who uses it and how

  • PHP application developers who need their software to accept users authenticated by an institutional or organisational CAS server rather than handling credentials locally.
  • Teams adopting single sign-on who already run or connect to a CAS server and want a client library instead of a bespoke protocol implementation.
  • Maintainers extending an existing PHP codebase who consult the wiki for integration guidance and the API reference for method-level detail.
  • Contributors and integrators working in the open: the repository carries 419 forks and an active issue queue, and changes are validated by the test.yml GitHub Actions workflow before merge.

Getting started

The README does not state a specific package name, Docker image, or compose file; instead it directs new users to the wiki at https://apereo.github.io/phpCAS/ for installation and usage instructions and to https://apereo.github.io/phpCAS/api/ for API documentation.

How it compares

The provided facts list no comparable or competing tools, so phpCAS stands alone in this registry. Its distinctive attributes on the record are an Apache-2.0 licence, stewardship by the Apereo Foundation, and a documented API and wiki.

When to use it — and when not to

Choose it when you are writing PHP and your users must be authenticated by an external CAS server; you should be prepared to operate that CAS server (or connect to one your organisation already runs), since phpCAS is only the client side of the exchange. The README is brief — it points to external documentation rather than describing installation, configuration, or supported PHP and CAS versions — so anyone evaluating it should budget time to read the wiki and API reference, and should weigh the 29 open issues when judging how well it fits their requirements.

project readme (upstream, from github) — read inline

phpCAS

phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server.

Please see the wiki website for more information:

https://apereo.github.io/phpCAS/

Api documentation can be found here:

https://apereo.github.io/phpCAS/api/

Test

LICENSE

Copyright 2007-2026, Apereo Foundation. This project includes software developed by Apereo Foundation. http://www.apereo.org/

Licensed under the Apache License, Version 2.0 (the "License"); you may not use this software except in compliance with the License. You may obtain a copy of the License at:

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.

Frequently asked questions

Is phpCAS free to use?

phpCAS is open source under the Apache-2.0 licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does phpCAS do?

Apereo PHP CAS Client

What is phpCAS written in?

phpCAS is primarily written in PHP. Its source is publicly available at https://github.com/apereo/phpCAS, and it has 800 GitHub stars.