New Livestream: How Banks Protect Their Apps with FAPI 2.0.

Register Now!
For Procurement Teams

Procurement Made Simple

Everything your procurement team needs to evaluate and purchase Duende IdentityServer. If a developer sent you this page — you’re in the right place.

Procurement hero image
Product Overview

What You’re Purchasing

Duende IdentityServer is a software development toolkit (SDK) — not a SaaS subscription.

About Duende Software

Duende Software builds IdentityServer, the most widely-adopted OpenID Connect and OAuth 2.0 framework for ASP.NET Core. We provide a software development toolkit (SDK) — not a SaaS subscription.

What is Duende IdentityServer?

A library that development teams integrate into their own applications, hosted on their own infrastructure. It handles authentication, authorization, and single sign-on using open standards.

Vendor Classification

Classify Duende Software as a software development toolkit (SDK) vendor. Not a SaaS provider, cloud platform, or managed service.

Classify Duende as an SDK vendor, not a SaaS provider.

UNSPSC: 43232300 — Software Development Tools

CTA Background

SDK vs. SaaS

With a SaaS identity provider, your data lives on someone else’s infrastructure. With Duende, you get the source code — it runs in your environment, on your terms, with zero runtime dependency on us.

Duende (SDK)

Typical SaaS

Where does it run? Your infrastructure Vendor’s cloud
Who controls the data? You Vendor
Vendor dependency at runtime? None Full
Captures Tracking and Telemetry Data? None Vendor Specific
Security & Compliance

Zero Data Exposure by Design

Because IdentityServer is an SDK that runs within your applications, standard SaaS security questionnaires and certifications like SOC 2 and ISO 27001 don’t apply — Duende never processes, stores, or transmits your data.

No Data Leaves Your Environment

Duende Software never processes, stores, or transmits your users’ data. The SDK runs entirely within your infrastructure under your security controls.

No Cloud Dependency

There is no Duende-hosted service to evaluate for uptime, data residency, or breach exposure. Zero runtime dependency on Duende.

No Shared Infrastructure

There is no multi-tenant environment or shared database. Your security review can focus on code quality and vulnerability management.

Because we deliver code — not a service — your security review is simpler than you’d expect.

We’re happy to complete questionnaires, but expect many “N/A” responses.

Billing & Payment

Predictable, straightforward licensing. No usage metering, no surprise invoices.

Topic

Details

Annual Licensing All licenses billed annually. Predictable budgeting with no monthly fluctuation or usage metering.
Payment Terms Net 0 from invoice date.
Payment Methods Credit card, ACH/wire transfer, check.
Multi-Year Purchasing Multi-year agreements available. Contact sales for custom terms.
Purchase Orders Contact us through our sales form to submit POs.
Vendor Portal Onboarding Ariba, Coupa, and similar portals supported. Contact us to get started.
Resellers Purchases through authorized resellers supported. See our partners page.
Common Questions

Frequently Asked Questions

Purchasing

  • No. Annual licensing provides predictable budgeting with no usage-based fluctuation — your costs are fixed for the year.

  • Yes. See our partners page for options, or contact us to set up a new reseller relationship.

  • Request a quote → receive a formal quote → issue a PO (optional) → receive invoice → pay within terms.

  • Yes. Contact sales for details on multi-year terms.

  • Contact us through our sales form to submit purchase orders.

  • Contact us through our sales form — we’ll complete your Ariba, Coupa, or other portal setup.

Security & Compliance

  • These certifications assess data handling practices. Since Duende never processes, stores, or transmits customer data, the standard audit scope doesn't apply to our business model.

  • Yes — request one via the documentation request form on this page. Note that many standard SaaS sections will be marked N/A since we're an SDK vendor, not a hosted service.

  • Available on request. Use the documentation request form on this page.