Introducing the next era of Duende IdentityServer.

Read our CEO’s announcement

Multiple Issuers on a Single Deployment

Multi-Issuer allows a single Duende IdentityServer deployment serve multiple issuer URLs. Tokens carry the iss claim that matches the URL used to obtain them, in full compliance with OpenID Connect specification. The result is a protocol-level trust boundary between contexts, from a single licensed deployment.

digital eyeball graphic

What it Enables

Standards-Compliant Trust Boundary

Each issuer URL is a distinct OIDC Issuer Identifier. Tokens carry the issuer that signed them. Discovery documents describe the trust boundary.

Customization and Operational Efficiency

Multi-Issuer turns one Duende IdentityServer deployment into a host for every issuer your business operates. Brand portfolios, regional subsidiaries, and partitioned-trust deployments run under a single instance, each with its own OIDC issuer. Add a brand, region, or business unit on the existing instance, reducing operational overhead.

Foundation for Future Multi-Tenancy Capabilities

The protocol foundation for the multi-tenancy capabilities on our roadmap [coming soon].

Capabilities

  • One Duende IdentityServer instance hosts every issuer URL you operate, with no per-issuer infrastructure to maintain.
  • Tokens carry the iss claim of the URL that issued them, exactly as OIDC requires. Standards-conformant clients and APIs see the separation by spec.
  • Flat-rate pricing. Cost is predictable and does not scale with your customer count.

How to Get It

Cost scales with your contract, not your customer count. Multi-Issuer is included as a capability of Duende IdentityServer on eligible tiers:

Tier

Availability

Community Edition Not available
Lite Not available
Standard Not available
Advanced Add-on, $7,500 flat fee
Custom Add-on, $7,500 flat fee

See the IdentityServer pricing page for full tier details.