New Livestream: How Banks Protect Their Apps with FAPI 2.0.

Register Now!

Self-Hosted OpenID Connect, OAuth, & SAML Server for ASP.NET Core

Duende IdentityServer is a standards-compliant OpenID Connect, OAuth 2.1, and SAML solution for ASP.NET Core. Centralize authentication for APIs, SPAs, mobile apps, microservices, and Agentic AI. Delivered as an SDK you host. Own your data. Control every flow. The OpenID-certified SDK for ASP.NET Core that 2,500+ organizations already run in production.

Duende Graphic Key

"Duende has been incredibly easy to build, maintain, and scale for our
cloud-hosted SaaS solution, and we have been thoroughly impressed with
the responsiveness from the team."


Dean Maier, Head of Cloud, Synthesis Software Technologies

CTA Background
How It Works

Your Identity Infrastructure

Duende IdentityServer sits between your applications and your identity data. It issues tokens, manages sessions, handles consent, and federates with external providers.

SPAs, APIs, mobile apps, and services all authenticate through IdentityServer. You connect it to your user database, external identity providers like Google or Entra ID, and SAML partners.

You control the code, the data, and the infrastructure. No vendor lock-in. No shared tenancy.

Architecture diagram showing Duende IdentityServer as the central identity infrastructure hub. Client applications (SPAs, APIs, Mobile, and Services) connect from the top, while user stores, external OIDC/social identity providers, and enterprise SAML/Entra ID providers feed in from the bottom. The server provides SSO, Sessions, Tokens, Keys, and Consent capabilities.
Deployment

Host It Your Way. Runs wherever ASP.NET Core runs.

Any Cloud

Azure, AWS, GCP. Standard ASP.NET Core deployment patterns apply to any cloud provider.

On-Premises

Private data center. Behind your VPN. Air-gapped networks. Full control over data residency.

Containers

Docker, Docker Compose, any OCI runtime. FIPS-compliant deployment supported.

Orchestrated

Kubernetes, Helm charts, multi-instance HA. .NET Aspire for dev/test orchestration.

Technology Ecosystem

Works With Your Stack

Duende IdentityServer runs on ASP.NET Core and integrates with any OIDC-compliant client, regardless of language or platform.

Circular collage of technology logos surrounding a central .NET logo, including Docker, Kubernetes, Google, Azure DevOps, Visual Studio, OpenAI/ChatGPT, AWS, Linux (Tux), React, PostgreSQL, OpenTelemetry, Microsoft, and other cloud and developer ecosystem icons on a green-striped background.
Trusted by the World's Most Demanding Organizations
  • VISA logo
  • Microsoft logo
  • UHC logo
  • Abbott logo
  • BNP Paribas logo
  • apprenda
  • S&P Global logo
  • Novartis logo
  • Fiserv logo
  • Commonwealth Bank of Australia logo
  • MUFG logo
Developer Experience

Get Running in Minutes

Install the NuGet package, configure IdentityServer in your Program.cs, and run. Start simple. Extend everything. IdentityServer is an SDK you configure in code, not a black box behind a dashboard.

JetBrains Rider IDE showing a C# Program.cs file for a project called MyUnicorn, with Duende IdentityServer v8.0.6 configured using in-memory clients, API scopes, identity resources, and test users. The NuGet package manager panel is open at the bottom showing the installed Duende.IdentityServer package.
Try It Now

Free for Development and Testing

Install the NuGet package and start building. No license required until you deploy to production.

Developer Lifecycle

From Install to Operate

  • Install: dotnet add package and go. NuGet templates, in-memory stores, no license needed. Working identity server in 5 minutes.
  • Build: Configure clients and scopes, build your login UI, integrate your user store. All in code, all yours.
  • Test: Integration tests with .NET Aspire orchestration. Validate protocol conformance before anything hits production.
  • Deploy: Add your license key, run EF Core migrations, deploy multi-instance for high availability. Standard ASP.NET Core app.
  • Operate: Automatic key rotation, OpenTelemetry traces, health checks and alerts. Duende support when you need it.
Five-stage workflow diagram for Duende IdentityServer adoption: Stage 1 Install (free, via dotnet add package and NuGet templates), Stage 2 Build (free, configure and customize), Stage 3 Test (free, unit and integration tests), Stage 4 Deploy (license required, add license key and enable add-ons), and Stage 5 Operate (license required, OTEL monitoring and automatic key management). Fingerprint imagery decorates the background.
Trust & Credibility

Created by the Original Authors of IdentityServer

Founded by Brock Allen and Dominick Baier, who created and maintained IdentityServer since 2009. Source-available so you can inspect every line of code.

OpenID Certified

Certified by the OpenID Foundation for conformance to OpenID Connect specifications.

Learn More

Source-Available

Inspect every line of code. Understand exactly what runs in your infrastructure. Extend and customize with confidence.

See Source

Production Proven

2,500+ organizations run Duende IdentityServer in production, from startups to Fortune 500 enterprises.

Read More
Capabilities

Modular add-ons by design. Add what you need when you're ready.

User Management

A first-party .NET SDK for user management, profiles, authentication, and lifecycle management. Passwords, MFA, and passkeys included.

Learn More

Automatic Key Management

Automated lifecycle management for signing and validation keys: generation, rotation, propagation, and retirement.

Learn More

SAML 2.0

SAML 2.0 in both directions. Provide SAML SSO to downstream partners and accept SAML assertions from upstream enterprise IdPs.

Learn More

Financial Grade Security & Conformance

Validate your configuration against FAPI 2.0 and OAuth 2.1 requirements. Produce conformance reports with remediation guidance.

Learn More

Multi-Issuer

Serve multiple issuer URLs from a single deployment. Tokens carry the correct iss claim per OpenID Connect specification.

Learn More

Redistribution License

Include IdentityServer as an integrated component of a product you redistribute to customers or third parties.

Learn More
Transparent Pricing

No Surprise Charges

Predictable, flat-tier pricing based on client count and deployment. Free for development and testing on all tiers. Community edition free for up to 10 clients in production.

CTA Background

Frequently Asked Questions

  • Review our licensing packages on our pricing page. We offer a variety of licensing options designed for your architectural and business requirements. Not sure which license is right for you, or require a custom package? Reach out to our team to learn more.

    If you are a current IdentityServer4 user, book a free 30-minute IS4 upgrade assessment with our team.

  • You do not need a license for development, testing, or trial. Download and use our library from NuGet and get started with trial mode. Start learning with the Duende IdentityServer quickstart tutorials.

  • No. Evaluation, development, test environments, and personal projects do not require a license. A startup warning message appears in non-licensed mode but does not constrain the application in any way.

  • Upgrading is simple and flexible – you can do so at any time. We'll issue a new license for your updated term and ensure you receive prorated credit for the remaining unused time on your existing license.

  • Where do I get help?

Can't find what you're looking for?

Ellipse Left Texture Ellipse Right Texture
Ellipse Right Texture
Get Started

Run Your First IdentityServer in 5 Minutes

Install the NuGet package, follow the quickstart, and deploy when ready. Free for development and testing.

CTA Background