{"id":83319,"url":"https://github.com/paulveillard/cybersecurity-auth","name":"cybersecurity-auth","description":"An ongoing \u0026 curated collection of awesome AuthN+Z software, libraries and frameworks, best guidelines and technical resources and cool stuff about Authentication \u0026 Authorization \u0026 SSO \u0026 IAM","projects_count":126,"last_synced_at":"2026-09-05T12:00:28.528Z","repository":{"id":109656987,"uuid":"456759340","full_name":"paulveillard/cybersecurity-auth","owner":"paulveillard","description":"An ongoing \u0026 curated collection of awesome AuthN+Z software, libraries and frameworks, best guidelines and technical resources and cool stuff about Authentication \u0026 Authorization \u0026 SSO \u0026 IAM","archived":false,"fork":false,"pushed_at":"2023-12-13T15:38:03.000Z","size":128,"stargazers_count":18,"open_issues_count":0,"forks_count":2,"subscribers_count":2,"default_branch":"main","last_synced_at":"2026-07-09T09:03:33.640Z","etag":null,"topics":["auth-api","auth-service","auth0","authenticated-encryption","authentication","authentication-service","authentication-strategy","authenticator","authn","authn-server","authorization","authz","authz-authority","awesome","aws-iam","aws-iam-policies","iam","iam-role"],"latest_commit_sha":null,"homepage":"","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/paulveillard.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"contributing.md","funding":null,"license":"LICENSE","code_of_conduct":"code-of-conduct.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null}},"created_at":"2022-02-08T02:50:47.000Z","updated_at":"2025-09-01T14:10:01.000Z","dependencies_parsed_at":"2023-07-29T12:15:13.191Z","dependency_job_id":null,"html_url":"https://github.com/paulveillard/cybersecurity-auth","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/paulveillard/cybersecurity-auth","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/paulveillard%2Fcybersecurity-auth","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/paulveillard%2Fcybersecurity-auth/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/paulveillard%2Fcybersecurity-auth/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/paulveillard%2Fcybersecurity-auth/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/paulveillard","download_url":"https://codeload.github.com/paulveillard/cybersecurity-auth/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/paulveillard%2Fcybersecurity-auth/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36720922,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-06T04:43:03.162Z","status":"online","status_checked_at":"2026-08-16T02:00:06.462Z","response_time":62,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"created_at":"2025-01-17T00:00:59.410Z","updated_at":"2026-09-05T12:00:28.528Z","primary_language":null,"list_of_lists":false,"displayable":true,"categories":["Authorization Development","`Cloud solutions`","`License`","`Authentication`","Identity \u0026 Access management (IAM)","Articles","Authorization","Tools","Other aggregators","`Authentication Development`"],"sub_categories":["\u003ca name=\"authZ-ios\"\u003e\u003c/a\u003eiOS","`Amazon Web Services (AWS)`","`Microsoft Azure`","`SSO (Single-Sign-On)`","\u003ca name=\"authZ-ruby\"\u003e\u003c/a\u003eRuby","`SAML`","`Passwordless authentication`","`Google Cloud Platform (GCP)`","`OAuth`","\u003ca name=\"authN-ruby\"\u003e\u003c/a\u003eRuby","\u003ca name=\"authZ-php\"\u003e\u003c/a\u003ePHP","\u003ca name=\"authN-node\"\u003e\u003c/a\u003eNode.js","\u003ca name=\"authZ-golang\"\u003e\u003c/a\u003eGolang","\u003ca name=\"authZ-cSharp\"\u003e\u003c/a\u003eC#","\u003ca name=\"authN-golang\"\u003e\u003c/a\u003eGolang","\u003ca name=\"authN-python\"\u003e\u003c/a\u003ePython","\u003ca name=\"authZ-android\"\u003e\u003c/a\u003eAndroid","\u003ca name=\"authZ-node\"\u003e\u003c/a\u003eNode.js","\u003ca name=\"authN-java\"\u003e\u003c/a\u003eJava","\u003ca name=\"authZ-python\"\u003e\u003c/a\u003ePython","\u003ca name=\"authN-cSharp\"\u003e\u003c/a\u003eC#","\u003ca name=\"authZ-java\"\u003e\u003c/a\u003eJava","\u003ca name=\"authZ-rust\"\u003e\u003c/a\u003eRust","`Two-factor authentication`"],"readme":"# Authentication \u0026 Authorization: Theory, Techniques, and Tools\nAn ongoing \u0026 curated collection of awesome  AuthN+Z software, software best practices and techniques, libraries and frameworks, E-books and videos, websites, blog posts, links to github Repositories, technical guidelines and important resources about Authentication \u0026 Authorization \u0026 SSO \u0026 IAM in Cybersecurity\n\u003e Thanks to all contributors, you're awesome and wouldn't be possible without you! Our goal is to build a categorized community-driven collection of very well-known resources\n\n[Authentication (aka AuthN)](https://en.wikipedia.org/wiki/Authentication) and [authorization (aka AuthZ)](https://en.wikipedia.org/wiki/Authorization) are both security measures. Authentication is the process of verifying who you are. Authorization is the process of verifying that you have access to something. Authorization occurs after successful authentication.\n\n### Authorization \n\u003e Access priviledges granted to a user, program, or process or the act of granting those privileges.\n\n![auth](https://github.com/paulveillard/cybersecurity-auth/blob/main/img/authentication-authorization.png)\n\n## `Table of Contents`\n- [Authentication](#authentication)\n   - [SSO](#sso-single-sign-on)\n   - [OAuth](#oauth)\n   - [SAML](#saml)\n   - [Two-factor authentication](#two-factor-authentication)\n   - [Passwordless authentication](#passwordless-authentication)\n\n- [Authentication Development](#authentication-development)\n\t- [C#](#authN-cSharp)\n\t- [Golang](#authN-golang)\n\t- [Java](#authN-java)\n\t- [Node.js](#authN-node)\n\t- [Python](#authN-python)\n\t- [Ruby](#authN-ruby)\n\n- [Authorization](#authorization)\n\n- [Authorization Development](#authorization-development)\n\t- [Android](#authZ-android)\n\t- [C#](#authZ-cSharp)\n\t- [Golang](#authZ-golang)\n\t- [Rust](#authZ-rust)\n\t- [iOS](#authZ-ios)\n\t- [Java](#authZ-java)\n\t- [Node.js](#authZ-node)\n\t- [PHP](#authZ-php)\n\t- [Python](#authZ-python)\n\t- [Ruby](#authZ-ruby)\n\n- [Articles](#articles)\n- [Identity \u0026 Access Management](#identity--access-management-iam)\n- [Tools](#tools)\n- [Other Aggregators](#other-aggregators)\n- [Cloud Solutions](#cloud-solutions)\n- [Contribute](#contribute)\n- [License](#license)\n\n\n **[`^        back to top        ^`](#)**\n\n## `Authentication`\n\n### `SSO (Single-Sign-On)`\n\n- [Casdoor](https://github.com/casdoor/casdoor) - UI-first centralized authentication / Single-Sign-On (SSO) platform supporting OAuth 2.0 / OIDC and SAML.\n- [Keycloak](https://www.keycloak.org/) - Open Source Identity and Access Management.\n- [Authelia](https://github.com/authelia/authelia) - The Single Sign-On Multi-Factor portal for web apps.\n- [ZITADEL](https://github.com/caos/zitadel) - Cloud-native Identity \u0026 Access Management platform for secure authentication, authorization and identity management.\n- [Single sign-on](https://en.wikipedia.org/wiki/Single_sign-on) - wiki page about SSO\n* [Central Authentication Service (CAS)](https://github.com/apereo/cas) - Open Source Enterprise Single Sign On\n* [Okta](https://www.okta.com/) - Identity and Access Management as a service; provides broad integrations\n* [Auth0](https://auth0.com/) - Identity and Access Management as a service\n* [Cloud-IAM](https://www.cloud-iam.com) - Keycloak IAM as a Service\n* [LoginRadius](https://www.loginradius.com/) - Identity and Access Management as a service\n* [FusionAuth](https://fusionauth.io/) - Identity and Access Management, either a service or self-hosted\n* [PAC4J](http://www.pac4j.org/) - The security library for Java\n* [buzzfeed/sso](https://github.com/buzzfeed/sso) - A single sign-on solution for securing internal services (Go based)\n* [cidaas](https://www.cidaas.com) - Cloud Identity \u0026 Access Management (Identity and Access Management as a service)\n\n### `OAuth`\n* [RFC6749](https://tools.ietf.org/html/rfc6749) - RFC with OAuth2 definition\n* [Spring Security OAuth](http://projects.spring.io/spring-security-oauth/) - OAuth implementation for Spring\n* [OAuth server for PHP](http://bshaffer.github.io/oauth2-server-php-docs/) - OAuth server for PHP\n* [ORY Hydra](https://www.ory.sh/hydra/) - Go based OAuth and OIDC server\n* [JSON Web Tokens](http://jwt.io/) - All you need to know about JWT\n* [OAuth+JWT in microservices](https://www.youtube.com/watch?v=BdKmZ7mPNns) - Good video on how to use tokens in microservices\n* [OpenID Connect](http://openid.net/connect/) - Identity layer on top of OAuth\n* [oauth2-proxy](https://github.com/oauth2-proxy/oauth2-proxy) - A reverse proxy that provides authentication with Google, Github or other providers.\n\n### `SAML`\n* [SAML](https://en.wikipedia.org/wiki/Security_Assertion_Markup_Language) - Security Assertion Markup Language wiki page\n* [Spring Security SAML](http://projects.spring.io/spring-security-saml/) - SAML implementation for Spring\n* [SAMLTest](https://samltest.id/) SAML Testing service\n\n### `Two-factor authentication`\n* [U2F and UAF spec](https://fidoalliance.org/specifications/overview/) - 2FA specifications\n* [Two Factor Auth](https://twofactorauth.org/) - List of websites with 2FA info\n\n### `Passwordless authentication`\n* [MojoAuth](https://mojoauth.com/) - Email and WebAuthN Authentication\n* [Sawolabs](https://sawolabs.com/) - Authentication without OTPs and Passwords\n* **[`^        back to top        ^`](#)**\n\n## `Authentication Development`\n\n### \u003ca name=\"authN-cSharp\"\u003e\u003c/a\u003eC#\n\n- [Xamarin.Auth](https://github.com/xamarin/Xamarin.Auth) - Helps developers authenticate users via standard authentication mechanisms (e.g. OAuth 1.0 and 2.0), and store user credentials.\n- [Kentor Authentication Services](https://github.com/KentorIT/authservices) - Saml2 authentication services for ASP.NET.\n- [SimpleAuthentication](https://github.com/SimpleAuthentication/SimpleAuthentication) - ASP.NET library that makes it really easy and simple for developers to add social authentication to an ASP.NET application.\n- [OwinOAuthProviders](https://github.com/TerribleDev/OwinOAuthProviders) - OAuth providers for Owin.\n- [AspNet.Security.OAuth.Providers](https://github.com/aspnet-contrib/AspNet.Security.OAuth.Providers) - OAuth2 social authentication providers for ASP.NET Core.\n- [IdentityServer4](https://github.com/IdentityServer/IdentityServer4) - OpenID Connect \u0026 OAuth 2.0 framework for ASP.NET Core.\n\n### \u003ca name=\"authN-golang\"\u003e\u003c/a\u003eGolang\n\n- [Casdoor](https://github.com/casdoor/casdoor) - UI-first centralized authentication / Single-Sign-On (SSO) platform supporting OAuth 2.0 / OIDC and SAML.\n- [OIDC](https://github.com/caos/oidc) - OpenID Connect Library (client and server) for Go\n- [Ory Hydra](https://github.com/ory/hydra) - OpenID Connect certified OAuth2 server.\n- [Ory Kratos](https://github.com/ory/kratos) - API-first Identity and User Management system built for cloud applications. \n- [Ory Oathkeeper](https://github.com/ory/oathkeeper) - Identity/Access proxy inspired by the BeyondCorp/Zero-Trust white paper.\n- [Ory Fosite](https://github.com/ory/fosite) - Extensible OAuth 2.0 and OpenID Connect SDK for Golang.\n- [ZITADEL](https://github.com/caos/zitadel) - Cloud-native Identity \u0026 Access Management platform for secure authentication, authorization and identity management.\n\n### \u003ca name=\"authN-java\"\u003e\u003c/a\u003eJava\n\n- [Apache Shiro](https://github.com/apache/shiro) - Powerful and easy-to-use Java security framework that performs authentication, authorization, cryptography, and session management.\n- [pac4j](https://github.com/pac4j/pac4j) - Security engine for Java (authentication, authorization, multi frameworks): OAuth, CAS, SAML, OpenID Connect, LDAP, JWT.\n- [Spring Security OAuth](https://github.com/spring-projects/spring-security-oauth) - Provides support for using Spring Security with OAuth (1a) and OAuth2.\n\n### \u003ca name=\"authN-node\"\u003e\u003c/a\u003eNode.js\n\n- [Passport](https://github.com/jaredhanson/passport) - Simple, unobtrusive authentication for Node.js. A comprehensive set of strategies support authentication using a username and password, Facebook, Twitter, and more.\n- [bell](https://github.com/hapijs/bell) - Third-party authentication plugin for hapi. Ships with built-in support for various well-known sites and simple configuration object will support other OAuth 1.0a and OAuth 2.0 sites.\n\n### \u003ca name=\"authN-python\"\u003e\u003c/a\u003ePython\n\n- [Keystone](https://github.com/openstack/keystone) - Provides authentication, authorization and service discovery mechanisms via HTTP primarily for use by projects in the OpenStack family.\n- [Authomatic](https://github.com/authomatic/authomatic) - Simple yet powerful authorization \u0026 authentication client library for Python web applications.\n- [Python Social Auth](https://github.com/python-social-auth/social-core) - Easy to setup social authentication/registration mechanism with support for several frameworks and auth providers.\n- [Raider](https://github.com/OWASP/raider) - Web authentication testing framework, which treats the authentication process as finite state machines.\n\n### \u003ca name=\"authN-ruby\"\u003e\u003c/a\u003eRuby\n\n- [Authlogic](https://github.com/binarylogic/authlogic) - Clean, simple, and unobtrusive Ruby authentication solution.\n- **[`^        back to top        ^`](#)**\n\n\n## Authorization\n* [Role-based access control](https://en.wikipedia.org/wiki/Role-based_access_control) - wiki page about RBAC\n* [XACML](https://en.wikipedia.org/wiki/XACML) - XML-based access control markup language\n* [angular-permissions](https://github.com/Narzerus/angular-permission) authorization for AngularJS\n\n**[`^        back to top        ^`](#)**\n\n## Authorization Development\n\n### \u003ca name=\"authZ-android\"\u003e\u003c/a\u003eAndroid\n\n- [AndPermission](https://github.com/yanzhenjie/AndPermission) - Android runtime permission, support the right to apply for permission at any place.\n\n### \u003ca name=\"authZ-cSharp\"\u003e\u003c/a\u003eC#\n\n- [Casbin.NET](https://github.com/casbin/Casbin.NET) - Authorization library that supports access control models like ACL, RBAC, ABAC in .NET (C#).\n- [DotNetOpenAuth](https://github.com/DotNetOpenAuth/DotNetOpenAuth) - Implementation of the OpenID, OAuth protocols.\n- [AuthorizationServer](https://github.com/IdentityModel/AuthorizationServer) - Sample implementation of an OAuth2 authorization server.\n\n### \u003ca name=\"authZ-golang\"\u003e\u003c/a\u003eGolang\n\n- [Aserto] (https://www.aserto.com) - Fine-grained access controls for cloud-native applications (based on Go). Support role, attribute, and relationship-based access controls.\n- [Casbin](https://github.com/casbin/casbin) - Authorization library that supports access control models like ACL, RBAC, ABAC in Golang.\n- [goRBAC](https://github.com/mikespook/gorbac) - Lightweight role-based access control implementation in Go.\n- [Ladon](https://github.com/ory/ladon) - SDK for access control policies: authorization for the microservice and IoT age.\n- [Foulkon](https://github.com/Tecsisa/foulkon) - Authorization server that allows or denies access to web resources.\n- [Gocialite](https://github.com/danilopolani/gocialite) - Social OAuth login in Go with multiple providers has never been so easy.\n- [OIDC](https://github.com/caos/oidc) - OpenID Connect Library (client and server) for Go\n- [Ory Keto](https://github.com/ory/keto) - Access control server capable of solving complex use cases (multi-tenant, attribute-based access control, etc.) with access control policies.\n- [Oso](https://github.com/osohq/oso) - Batteries-included framework for building authorization in your Go application.\n- [ZITADEL](https://github.com/caos/zitadel) - Cloud-native Identity \u0026 Access Management platform for secure authentication, authorization and identity management.\n\n\n### \u003ca name=\"authZ-rust\"\u003e\u003c/a\u003eRust\n\n- [Casbin-Rs](https://github.com/casbin/casbin-rs) - Authorization library that supports access control models like ACL, RBAC, ABAC in Rust.\n- [Oso](https://github.com/osohq/oso) - Batteries-included framework for building authorization in your Rust application.\n\n### \u003ca name=\"authZ-ios\"\u003e\u003c/a\u003eiOS\n\n- [Permission](https://github.com/delba/Permission) - Unified API to ask for permissions on iOS.\n\n### \u003ca name=\"authZ-java\"\u003e\u003c/a\u003eJava\n\n- [jCasbin](https://github.com/casbin/jcasbin) - Authorization library that supports access control models like ACL, RBAC, ABAC in Java.\n- [Apache Shiro](https://github.com/apache/shiro) - Powerful and easy-to-use Java security framework that performs authentication, authorization, cryptography, and session management.\n- [pac4j](https://github.com/pac4j/pac4j) - Security engine for Java (authentication, authorization, multi-frameworks): OAuth, CAS, SAML, OpenID Connect, LDAP, JWT.\n- [AT\u0026T XACML](https://github.com/att/XACML) - XACML 3.0 implementation from AT\u0026T.\n- [Apache Sentry](https://github.com/apache/sentry) - Highly modular system for providing fine grained role based authorization to both data and metadata stored on an Apache Hadoop cluster.\n- [TOTP Server-Side Library](https://github.com/wstrange/GoogleAuth) - TOTP server-side library.\n- [Oso](https://github.com/osohq/oso) - Batteries-included framework for building authorization in your Java application.\n\n### \u003ca name=\"authZ-node\"\u003e\u003c/a\u003eNode.js\n\n- [Node-Casbin](https://github.com/casbin/node-casbin) - Authorization library that supports access control models like ACL, RBAC, ABAC in Node.js.\n- [RBAC](https://github.com/CherryProjects/rbac) - Hierarchical role-based access control for Node.js.\n- [ABAC](https://github.com/vovantics/abac) - Attribute-based access control for Node.js.\n- [accesscontrol](https://github.com/onury/accesscontrol) - Role and attribute-based access control for Node.js.\n- [Oso](https://github.com/osohq/oso) - Batteries-included framework for building authorization in your Node.js application.\n\n### \u003ca name=\"authZ-php\"\u003e\u003c/a\u003ePHP\n\n- [PHP-Casbin](https://github.com/php-casbin/php-casbin) - Authorization library that supports access control models like ACL, RBAC, ABAC in PHP.\n- [PHP-RBAC](https://github.com/OWASP/rbac) - Authorization library for PHP which provides developers with NIST Level 2 hierarchical role-based access control.\n- [ezRbac](https://github.com/xiidea/ezRbac) - Simple yet easy to implement role-based access control library for popular PHP framework: [Codeigniter](https://github.com/bcit-ci/CodeIgniter).\n- [php-abac](https://github.com/Kilix/php-abac) - Attribute-based access control library.\n- [laravel-permission](https://github.com/spatie/laravel-permission) - Allows you to manage user permissions and roles in a database.\n- [logical-permissions-php](https://github.com/ordermind/logical-permissions-php) - This is a generic library that provides support for array-based permissions with logic gates such as AND and OR.\n- [symfony-logical-authorization-bundle](https://github.com/ordermind/symfony-logical-authorization-bundle) - This Symfony bundle provides a unifying solution for authorization that aims to be flexible, convenient and consistent.\n\n### \u003ca name=\"authZ-python\"\u003e\u003c/a\u003ePython\n\n- [PyCasbin](https://github.com/casbin/pycasbin) - Authorization library that supports access control models like ACL, RBAC, ABAC in Python.\n- [Simple RBAC](https://github.com/tonyseek/simple-rbac) - Simple role-based access control utility for Python.\n- [Flask-RBAC](https://github.com/shonenada/flask-rbac) - Adds RBAC support to [Flask](https://github.com/pallets/flask).\n- [Vakt](https://github.com/kolotaev/vakt) - Attribute-based access control (ABAC) SDK for Python.\n- [Oso](https://github.com/osohq/oso) - Batteries-included framework for building authorization in your Python application.\n\n### \u003ca name=\"authZ-ruby\"\u003e\u003c/a\u003eRuby\n\n- [Oso](https://github.com/osohq/oso) - Batteries-included framework for building authorization in your Ruby application.\n- [Pundit](https://github.com/varvet/pundit) - Minimal authorization through OO design and pure Ruby classes.\n- [Casbin](https://github.com/CasbinRuby/casbin-ruby) - Authorization library that supports access control models like ACL, RBAC, ABAC in Ruby.\n- [CanCanCan](https://github.com/CanCanCommunity/cancancan) - Authorization for Ruby on Rails.\n- **[`^        back to top        ^`](#)**\n\n## Articles\n\n- [Modeling Authorization with PERM in Casbin](https://vicarie.in/posts/generalized-authz.html)\n- [Basic Role-Based HTTP Authorization in Go with Casbin](https://zupzup.org/casbin-http-role-auth)\n- [Policy enforcements on Kubernetes with Banzai Cloud's Pipeline and Casbin](https://banzaicloud.com/blog/policy-enforcement-k8s/)\n- [Organizational RBAC in Argo CD with Casbin](https://argoproj.github.io/docs/argo-cd/docs/rbac.html)\n- [Authorization Academy: A series of technical guides for building application authorization](https://www.osohq.com/academy)\n- [Why Authorization is Hard](https://www.osohq.com/post/why-authorization-is-hard)\n\n**[`^        back to top        ^`](#)**\n\n\n## Identity \u0026 Access management (IAM)\n* [Keycloak](https://www.keycloak.org/) - Open Source Identity and Access Management\n* [IdentityServer](https://identityserver.io/) - .NET based IAM server\n* [ORY](https://www.ory.sh/) - Open Source Identity Infrastructure and Services (Go based)\n* [casbin](https://casbin.org/en/) - Go authorization library\n* [OpenAM](https://forgerock.github.io/openam-community-edition/) - (discontinued), successor of OpenSSO\n* [WSO2 Identity Server](http://wso2.com/products/identity-server/) - also has SSO, authZ, ...\n\n**[`^        back to top        ^`](#)**\n\n## Tools\n* [Step CLI](https://smallstep.com/cli/) - A zero trust swiss army knife for working with X509, OAuth, JWT, OATH OTP, etc. \n* [JWT DEBUGGER](https://jwt.ssotools.com/)  - A simple JWT decoder tool, that can help to verify the JWT and with the help of signature.\n\n## Other aggregators\n* [awesome-keycloak](https://github.com/thomasdarimont/awesome-keycloak) - A curated list of Keycloak related resources\n* [casbin/awesome-auth](https://github.com/casbin/awesome-auth) - other auth list\n* [OAuth code libraries](https://oauth.net/code/)\n* [OIDC code libraries](https://openid.net/developers/libraries/)\n\n**[`^        back to top        ^`](#)**\n\n## `Cloud solutions`\n\n### `Amazon Web Services (AWS)`\n* [AWS IAM](https://aws.amazon.com/iam/) - Identity and Access Management for AWS\n* [AWS SSO](https://aws.amazon.com/single-sign-on/) - Centrally manage single sign-on (SSO) access to multiple AWS accounts\n* [Amazon Cognito](https://aws.amazon.com/cognito/) - SSO for business applications\n* [AWS Directory Service](https://aws.amazon.com/directoryservice/) - AD in the AWS Cloud\n* [AWS STS](https://docs.aws.amazon.com/STS/latest/APIReference/Welcome.html) - AWS Security Token Service for temporary IAM tokens\n\n### `Google Cloud Platform (GCP)`\n* [Identity and authentication, the Google Cloud way](https://cloud.google.com/blog/products/identity-security/identity-and-authentication-the-google-cloud-way) - Overview of Google approach to identity and access management\n\n### `Microsoft Azure`\n* [Microsoft identity platform](https://docs.microsoft.com/en-us/azure/active-directory/develop/) - Evolution of the Azure Active Directory\n\n**[`^        back to top        ^`](#)**\n## `Contribute`\n\nPR is welcomed.\n\n\n\n**[`^        back to top        ^`](#)**\n## `License`\n\nMIT License \u0026 [cc](https://creativecommons.org/licenses/by/4.0/) license\n\n\u003ca rel=\"license\" href=\"http://creativecommons.org/licenses/by/4.0/\"\u003e\u003cimg alt=\"Creative Commons License\" style=\"border-width:0\" src=\"https://i.creativecommons.org/l/by/4.0/88x31.png\" /\u003e\u003c/a\u003e\u003cbr /\u003eThis work is licensed under a \u003ca rel=\"license\" href=\"http://creativecommons.org/licenses/by/4.0/\"\u003eCreative Commons Attribution 4.0 International License\u003c/a\u003e.\n\nTo the extent possible under law, [Paul Veillard](https://github.com/paulveillard/) has waived all copyright and related or neighboring rights to this work.\n\n\n**[`^        back to top        ^`](#)**\n","projects_url":"https://awesome.ecosyste.ms/api/v1/lists/paulveillard%2Fcybersecurity-auth/projects"}