{"id":51756095,"url":"https://github.com/thunder-id/thunderid","last_synced_at":"2026-08-07T14:00:40.197Z","repository":{"id":290964928,"uuid":"976142433","full_name":"thunder-id/thunderid","owner":"thunder-id","description":"ThunderID is a high-performance, open-source identity stack designed for developers to secure and manage access for humans, AI agents, and workloads through fully composable identity flows.","archived":false,"fork":false,"pushed_at":"2026-08-06T20:31:24.000Z","size":140375,"stargazers_count":386,"open_issues_count":633,"forks_count":354,"subscribers_count":19,"default_branch":"main","last_synced_at":"2026-08-06T21:54:31.932Z","etag":null,"topics":["access-management","ai-agents","authentication","authorization","go","golang","hacktoberfest","iam","identity","mfa","oauth2","oidc"],"latest_commit_sha":null,"homepage":"https://thunderid.dev","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/thunder-id.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":"MAINTAINERS.md","copyright":null,"agents":"AGENTS.md","claude":"CLAUDE.md","gemini":null,"cursor":null,"copilot":".github/copilot-instructions.md","dco":null,"cla":null,"disclosure":null}},"created_at":"2025-05-01T15:17:40.000Z","updated_at":"2026-08-06T13:13:20.000Z","dependencies_parsed_at":"2026-08-06T22:12:32.184Z","dependency_job_id":null,"html_url":"https://github.com/thunder-id/thunderid","commit_stats":null,"previous_names":["asgardeo/thunder","thunder-id/thunder-id","thunder-id/thunderid"],"tags_count":140,"template":false,"template_full_name":null,"purl":"pkg:github/thunder-id/thunderid","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/thunder-id%2Fthunderid","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/thunder-id%2Fthunderid/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/thunder-id%2Fthunderid/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/thunder-id%2Fthunderid/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/thunder-id","download_url":"https://codeload.github.com/thunder-id/thunderid/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/thunder-id%2Fthunderid/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36362458,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-06T04:43:03.162Z","status":"online","status_checked_at":"2026-08-07T02:00:06.708Z","response_time":57,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["access-management","ai-agents","authentication","authorization","go","golang","hacktoberfest","iam","identity","mfa","oauth2","oidc"],"created_at":"2026-07-19T06:44:38.875Z","updated_at":"2026-08-07T14:00:40.190Z","avatar_url":"https://github.com/thunder-id.png","language":"Go","funding_links":[],"categories":["AI 机器学习"],"sub_categories":[],"readme":"\u003cimg src=\"https://thunderid.dev/assets/images/readme/repo-banner.png\" alt=\"ThunderID\" width=\"100%\" /\u003e\n\n###\n\n[![License](https://img.shields.io/badge/License-Apache%202.0-blue.svg)](https://opensource.org/licenses/Apache-2.0)\n[![GitHub last commit](https://img.shields.io/github/last-commit/thunder-id/thunderid.svg)](https://github.com/thunder-id/thunderid/commits/main)\n[![GitHub issues](https://img.shields.io/github/issues/thunder-id/thunderid.svg)](https://github.com/thunder-id/thunderid/issues)\n[![codecov.io](https://codecov.io/github/thunder-id/thunderid/coverage.svg?branch=main)](https://codecov.io/github/thunder-id/thunderid?branch=main)\n[![GitHub Release](https://img.shields.io/github/v/release/thunder-id/thunderid?color=blue)](https://github.com/thunder-id/thunderid/releases/latest)\n\n\nThunderID is a lightweight, open-source Identity and Access Management (IAM) engine built to secure access for humans, AI agents, and machines.\n\nDesigned for the agentic era, ThunderID provides a developer-first IAM platform and supporting tools for securing applications, APIs, services, and agent-driven workflows. It works across traditional and decentralized identity ecosystems, with post-quantum-ready security built in from the start.\n\nCore design goals of ThunderID include:\n- **Agent-native identity:** Manage AI agents as first-class identities with delegated authority, consent-aware access, traceability, and support for issuing verifiable credentials to agents. ThunderID also aims to expose IAM capabilities through interfaces that agents can use safely and programmatically.\n- **Decentralized identity:** Bridge the adoption gap for relying parties by making it practical for service providers to consume, verify, and trust decentralized identity in real-world applications, including DIDs, verifiable credentials, digital wallets, trust registries, and issuer-verifier-holder interaction models.\n- **Cloud-native IAM:** Provide a lightweight, containerized identity product that can run across on-premises and cloud environments, with declarative identity flows, policies, and configuration suitable for automation, versioning, and GitOps practices.\n- **Post-quantum-safe security:** Build on a crypto-agile foundation where algorithms, key types, signing methods, and token protection mechanisms can evolve over time, including support for post-quantum-safe algorithms and hybrid transition approaches across key management, credential issuance, assertions, and secure service-to-service communication.\n\n\n## Getting Started\n\nGet started by exploring how ThunderID can be used to secure:\n* Applications - by following [Securing B2C Application Guide](https://thunderid.dev/docs/next/use-cases/b2c/try-it-out)\n* AI Agents - by following [Securing AI Agents Guide](https://thunderid.dev/docs/next/use-cases/ai-agents/try-it-out)\n* MCP - by following [Securing MCP Guide](https://thunderid.dev/docs/next/use-cases/ai-agents/mcp-authorization/try-it-out)\n\n To learn more about overall requirements, solution patterns of these scenarios, refer to the [Use Cases](https://thunderid.dev/docs/next/use-cases/overview/) section.\n\nVisit [Get ThunderID](https://thunderid.dev/docs/next/guides/getting-started/get-thunderid/) to learn more about installation methods.\n\n\n## Architecture\n\n\u003cimg src=\"https://thunderid.dev/assets/images/readme/architecture.png\" alt=\"ThunderID Architecture\" width=\"100%\" /\u003e\n\n\n## Features\n\n* **Identity Management**\n    * Humans, AI agents, and workloads as first-class identity types\n    * Hierarchical organizational units (OUs) and groups\n\n* **Standards**\n    * OAuth 2.1 and OpenID Connect, with PAR and PKCE\n    * Verifiable Credentials — OpenID4VCI (issuance) and OpenID4VP (verification)\n    * WebAuthn / passkeys\n    * IdP federation — Google, Microsoft, GitHub, and any OIDC or SAML provider\n\n* **Decentralized Identity**\n    * Issue Verifiable Credentials to user wallets from configurable credential templates\n    * Verify presented credentials against presentation definitions and trust anchors\n    * Use them on their own, or as part of an identity journey\n\n* **User Journeys**\n    * Login, registration, and recovery defined as journeys\n    * 20+ built-in executors - password, passkey, OTP, social login, consent, and more\n    * Orchestratable in the server or the application\n    * Themeable end-user UI\n\n* **Authorization**\n    * Hierarchical resources with derived permissions\n    * Role-based access control across users, agents, and applications\n    * Consent management with user-facing review\n\n* **Developer Experience**\n    * Console UI, REST APIs, and SDKs\n    * MCP server for managing and querying IAM from AI agents\n\n* **Declarative and GitOps-Ready**\n    * YAML resource definitions for every entity\n    * Immutable runtime\n\n\n## Contributing\n\nPlease refer to the [Contributing Guide](https://thunderid.dev/docs/next/community/overview) for the different ways to contribute to this project and the relevant guidelines.\n\nFor code contributions, refer to the [Contributing Code](https://thunderid.dev/docs/next/community/contributing/contributing-code/prerequisites) section for details on the prerequisites and instructions for running ThunderID in development mode.\n\n\n## License\n\nLicenses this source under the Apache License, Version 2.0 ([LICENSE](LICENSE)), You may not use this file except in compliance with the License.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fthunder-id%2Fthunderid","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fthunder-id%2Fthunderid","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fthunder-id%2Fthunderid/lists"}