New Livestream: How Banks Protect Their Apps with FAPI 2.0.
Duende IdentityServer is a standards-compliant OpenID Connect, OAuth 2.1, and SAML solution for ASP.NET Core. Centralize authentication for APIs, SPAs, mobile apps, microservices, and Agentic AI. Delivered as an SDK you host. Own your data. Control every flow. The OpenID-certified SDK for ASP.NET Core that 2,500+ organizations already run in production.

"Duende has been incredibly easy to build, maintain, and scale for our
cloud-hosted SaaS solution, and we have been thoroughly impressed with
the responsiveness from the team."
— Dean Maier, Head of Cloud, Synthesis Software Technologies
Duende IdentityServer sits between your applications and your identity data. It issues tokens, manages sessions, handles consent, and federates with external providers.
SPAs, APIs, mobile apps, and services all authenticate through IdentityServer. You connect it to your user database, external identity providers like Google or Entra ID, and SAML partners.
You control the code, the data, and the infrastructure. No vendor lock-in. No shared tenancy.

Any Cloud
Azure, AWS, GCP. Standard ASP.NET Core deployment patterns apply to any cloud provider.
On-Premises
Private data center. Behind your VPN. Air-gapped networks. Full control over data residency.
Containers
Docker, Docker Compose, any OCI runtime. FIPS-compliant deployment supported.
Orchestrated
Kubernetes, Helm charts, multi-instance HA. .NET Aspire for dev/test orchestration.
Duende IdentityServer runs on ASP.NET Core and integrates with any OIDC-compliant client, regardless of language or platform.

Install the NuGet package, configure IdentityServer in your Program.cs, and run. Start simple. Extend everything. IdentityServer is an SDK you configure in code, not a black box behind a dashboard.

Install the NuGet package and start building. No license required until you deploy to production.

Founded by Brock Allen and Dominick Baier, who created and maintained IdentityServer since 2009. Source-available so you can inspect every line of code.
Certified by the OpenID Foundation for conformance to OpenID Connect specifications.
Inspect every line of code. Understand exactly what runs in your infrastructure. Extend and customize with confidence.
2,500+ organizations run Duende IdentityServer in production, from startups to Fortune 500 enterprises.
User Management
A first-party .NET SDK for user management, profiles, authentication, and lifecycle management. Passwords, MFA, and passkeys included.
Automatic Key Management
Automated lifecycle management for signing and validation keys: generation, rotation, propagation, and retirement.
SAML 2.0
SAML 2.0 in both directions. Provide SAML SSO to downstream partners and accept SAML assertions from upstream enterprise IdPs.
Financial Grade Security & Conformance
Validate your configuration against FAPI 2.0 and OAuth 2.1 requirements. Produce conformance reports with remediation guidance.
Multi-Issuer
Serve multiple issuer URLs from a single deployment. Tokens carry the correct iss claim per OpenID Connect specification.
Redistribution License
Include IdentityServer as an integrated component of a product you redistribute to customers or third parties.
Predictable, flat-tier pricing based on client count and deployment. Free for development and testing on all tiers. Community edition free for up to 10 clients in production.
Review our licensing packages on our pricing page. We offer a variety of licensing options designed for your architectural and business requirements. Not sure which license is right for you, or require a custom package? Reach out to our team to learn more.
If you are a current IdentityServer4 user, book a free 30-minute IS4 upgrade assessment with our team.
You do not need a license for development, testing, or trial. Download and use our library from NuGet and get started with trial mode. Start learning with the Duende IdentityServer quickstart tutorials.
No. Evaluation, development, test environments, and personal projects do not require a license. A startup warning message appears in non-licensed mode but does not constrain the application in any way.
Upgrading is simple and flexible – you can do so at any time. We'll issue a new license for your updated term and ensure you receive prorated credit for the remaining unused time on your existing license.
Where do I get help?
Can't find what you're looking for?
Install the NuGet package, follow the quickstart, and deploy when ready. Free for development and testing.