New Livestream: How Banks Protect Their Apps with FAPI 2.0.
Everything your procurement team needs to evaluate and purchase Duende IdentityServer. If a developer sent you this page — you’re in the right place.

Duende IdentityServer is a software development toolkit (SDK) — not a SaaS subscription.
About Duende Software
Duende Software builds IdentityServer, the most widely-adopted OpenID Connect and OAuth 2.0 framework for ASP.NET Core. We provide a software development toolkit (SDK) — not a SaaS subscription.
What is Duende IdentityServer?
A library that development teams integrate into their own applications, hosted on their own infrastructure. It handles authentication, authorization, and single sign-on using open standards.
Vendor Classification
Classify Duende Software as a software development toolkit (SDK) vendor. Not a SaaS provider, cloud platform, or managed service.
UNSPSC: 43232300 — Software Development Tools
With a SaaS identity provider, your data lives on someone else’s infrastructure. With Duende, you get the source code — it runs in your environment, on your terms, with zero runtime dependency on us.
| | Duende (SDK) | Typical SaaS |
|---|---|---|
| Where does it run? | Your infrastructure | Vendor’s cloud |
| Who controls the data? | You | Vendor |
| Vendor dependency at runtime? | None | Full |
| Captures Tracking and Telemetry Data? | None | Vendor Specific |
Because IdentityServer is an SDK that runs within your applications, standard SaaS security questionnaires and certifications like SOC 2 and ISO 27001 don’t apply — Duende never processes, stores, or transmits your data.
No Data Leaves Your Environment
Duende Software never processes, stores, or transmits your users’ data. The SDK runs entirely within your infrastructure under your security controls.
No Cloud Dependency
There is no Duende-hosted service to evaluate for uptime, data residency, or breach exposure. Zero runtime dependency on Duende.
No Shared Infrastructure
There is no multi-tenant environment or shared database. Your security review can focus on code quality and vulnerability management.
We’re happy to complete questionnaires, but expect many “N/A” responses.
Predictable, straightforward licensing. No usage metering, no surprise invoices.
Topic | Details |
|---|---|
| Annual Licensing | All licenses billed annually. Predictable budgeting with no monthly fluctuation or usage metering. |
| Payment Terms | Net 0 from invoice date. |
| Payment Methods | Credit card, ACH/wire transfer, check. |
| Multi-Year Purchasing | Multi-year agreements available. Contact sales for custom terms. |
| Purchase Orders | Contact us through our sales form to submit POs. |
| Vendor Portal Onboarding | Ariba, Coupa, and similar portals supported. Contact us to get started. |
| Resellers | Purchases through authorized resellers supported. See our partners page. |
Our terms and conditions are available at duendesoftware.com/terms.
Duende Software does not process customer data. Our SDK runs entirely within your infrastructure. See our Privacy Policy.
Not for standard purchases. If your organization requires one, request Duende's NDA via the documentation request form on this page.
No. Annual licensing provides predictable budgeting with no usage-based fluctuation — your costs are fixed for the year.
Yes. See our partners page for options, or contact us to set up a new reseller relationship.
Request a quote → receive a formal quote → issue a PO (optional) → receive invoice → pay within terms.
Yes. Contact sales for details on multi-year terms.
Contact us through our sales form to submit purchase orders.
Contact us through our sales form — we’ll complete your Ariba, Coupa, or other portal setup.
These certifications assess data handling practices. Since Duende never processes, stores, or transmits customer data, the standard audit scope doesn't apply to our business model.
Yes — request one via the documentation request form on this page. Note that many standard SaaS sections will be marked N/A since we're an SDK vendor, not a hosted service.
Available on request. Use the documentation request form on this page.