product-is is a free, open source identity & access management (iam) project written in Java and released under Apache-2.0. It has 882 GitHub stars, 1,033 forks and 1,632 open issues, and was last pushed 6 hours ago. On this registry it ranks #50 of 61 tracked projects in Identity & Access Management (IAM), with 5 head-to-head comparisons available.

What is product-is?

WSO2 Identity Server is an open-source identity and access management platform for Java-based on-premises and cloud deployments, aimed at teams that need to secure applications, APIs, workforce, consumer, and business-customer logins under standards such as OAuth 2.0, OIDC, and SAML 2.0.

What it is

WSO2 Identity Server is an identity and access management (IAM) product whose source code lives in the product-is repository, written in Java under the Apache 2.0 licence. It is positioned as a modern IAM solution that can be run on-premises or in a cloud environment, covering external consumers, internal workforce, business customers, and API access from a single identity foundation. It also backs the hosted identity cloud offering Asgardeo, which the project describes as built on the same technology core.

The concrete problem it addresses is the fragmentation of authentication and authorization across many application types and user populations. By consolidating adaptive authentication, single sign-on, multi-factor authentication, OAuth 2.0/OIDC, SAML 2.0, and RBAC-based API authorization into one server, it replaces the need to assemble and maintain separate components for each protocol and each audience, while still allowing an organisation to choose where the software is deployed.

Key capabilities

  • A visual designer for building authentication flows, with templates that simplify configuring applications and authentication methods.
  • Natural-language input that automatically generates complex login flows, together with assisted brand matching that generates the corresponding UX components.
  • Simplified use of RBAC to define fine-grained API access policies, plus an authentication API intended for in-app authentication.
  • B2B CIAM features including advanced RBAC for delegated administration rights, per-customer login options that can include an enterprise IdP, per-customer customizable branding, and support for organization hierarchies such as B2B2C.
  • API security built on the FAPI standard, layered on top of the OAuth 2.0 standard and originating in financial services.
  • Standards coverage across OAuth2, OIDC, SAML2, single sign-on, multi-factor and adaptive authentication, and authorization.
  • An all-new administrative console that is shared with Asgardeo and Private Identity Cloud.

Who uses it and how

  • Organisations securing external consumer applications alongside internal workforce applications on the same server.
  • Business-to-business teams onboarding customer organizations, using delegated administration and per-customer branding for B2B2C hierarchies.
  • API teams applying fine-grained RBAC policies and FAPI-based protections to programmatic access.
  • Deployments that need the freedom to run the software on-premises rather than committing to a hosted identity provider.
  • Developers who use the visual designer and authentication API while building login experiences into their applications.

Getting started

The code is published as the product-is repository on GitHub, where the README points to guidance on working with the repository and contributing code, and where the master branch build status and test results are tracked on the project's Jenkins instance.

How it compares

This registry entry stands alone: the facts provided name no comparable alternative tools for it to be measured against.

When to use it — and when not

It suits teams that want to operate their own identity layer rather than depend on a hosted provider, and for whom standards breadth and deploy-anywhere freedom matter. Organisations that would rather not run an identity server at all can use the hosted Asgardeo option instead, and prospective users should note the repository currently carries 1,632 open issues, which suggests a substantial and actively triaged backlog when evaluating support expectations.

project readme (upstream, from github) — read inline
WSO2 logo

WSO2 Identity Server

License DPG Badge Get Support on Stack Overflow Join the community on Discord X

Branch Build Status Test Results
master Build Status Test Results

WSO2 Identity Server is a powerful, modern identity and access management solution for your on-premises or cloud environment. It enables organizations to deliver exceptional, trusted digital experiences to all types of users.

To learn more about WSO2 Identity Server please visit WSO2 Identity Server website

Looking for a Hosted Identity Solution?

Try Asgardeo free of charge – a public identity cloud solution (iDaaS) offering, built on the same technology core as WSO2 Identity Server.

Why WSO2 Identity Server?

Whether you’re securing apps for external consumers, internal workforce, business customers, or even API access, WSO2 Identity Server provides the modern, full-featured identity and access foundation you need.

Customers prefer Identity Server for its developer-centric design, extensive standards support, freedom to deploy however needed, and massive scalability.

Optimized developer experience
- New visual designer that simplifies development of authentication flows. 
- New templates to easily configure apps and authentication methods. 
- Simplified use of RBAC to define fine-grained API access policies. 
- New authentication API for in-app authentication, further streamlining user access. 
AI-assisted development
- Natural language for login flow requirements to automatically generate complex authentication flows. 
- Assisted brand matching to automatically generate all UX components
Industry-leading B2B CIAM capabilities, simplifying secure access for business customers and partners
- Advanced RBAC to define delegated administration rights.
- Choice of login options per customer, including enterprise IDP. 
- Subscription model to ensure the right apps are available to customers.
- Customizable branding per customer to ensure the highest user engagement.
- Rich support for various organization hierarchies, such as B2B2C. 
Best API security available anywhere, using the powerful FAPI standard
- Additional security features built on top of the OAuth2 standard.
- Originating in financial services, but now desired by many industries. 
Unified user experience
- All-new administrative console.
- Shared with [Asgardeo](https://wso2.com/asgardeo/) and Private Identity Cloud. 

Getting Started

System prerequisites

Refer to this page to consult pre-requisites based on your target architecture and operating system: https://is.docs.wso2.com/en/latest/deploy/get-started/install

Installation

  1. WSO2 Identity Server requires a JDK to run and supports versions from JDK 11 through JDK 21. For the full list of supported versions, please refer to the environment compatibility section in the documentation.
  2. Make sure you have set the JAVA_HOME environment variable to point to your JDK. See this documentation if you need help doing so.
  3. Extract the downloaded distribution zip file and go to the 'bin' directory
  4. Run the wso2server.sh or wso2server.bat script based on your operating system.
  5. Access the respective WSO2 Identity Server interfaces
    • Developer and Administrator Console web application is running at: https://localhost:9443/console
      You may sign in to the Developer and Administrator Console using the default administrator credentials (username: admin, password: admin).
    • End User Portal web application is running at: - https://localhost:9443/myaccount
      You may sign in to the End User Portal using the default administrator credentials (username: admin, password: admin).

Try out a sample app or build your own sample app

Follow our Quick Start guide to try out a sample app or build your own sample app.

Reporting Product Issues

All known issues of WSO2 IS are filed at: https://github.com/wso2/product-is/issues. Please check this list before opening a new issue.

Opening an issue

Help us make our software better! Submit any bug reports or feature requests through GitHub: https://github.com/wso2/product-is/issues.

Reporting Security Issues

Please do not report security issues via GitHub issues. Instead, follow the WSO2 Security Vulnerability Reporting Guidelines.

Join our community!

Commercial Support

You can take advantage of a WSO2 on-prem product subscription for the full range of software product benefits like expert support, continuous product updates, vulnerability monitoring, and access to the licensed distribution for commercial use.

To learn more, check WSO2 Subscription.

Contributing

If you are planning on contributing to the development efforts of WSO2 Identity Server, you can do that by checking out the latest development version. The master branch holds the latest unreleased source code.

Please read our Contribution Guide for detailed instructions on how to contribute.

Can you fill this survey ? WSO2 wants to learn more about our open source software (OSS) community and your communication preferences to serve you better.

In addition, we may reach out to a small number of respondents to ask additional questions and offer a small gift.

Survey is available at: https://forms.gle/h5q4M3K7vyXba3bK6


(c) Copyright 2019 - 2026 WSO2 LLC. All Rights Reserved.

Frequently asked questions

Is product-is free to use?

product-is is open source under the Apache-2.0 licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does product-is do?

Welcome to the WSO2 Identity Server source code! For info on working with the WSO2 Identity Server repository and contributing code, click the link below.

What is product-is written in?

product-is is primarily written in Java. Its source is publicly available at https://github.com/wso2/product-is, and it has 882 GitHub stars.