The Janssen Project is an open-source identity and access management server providing OAuth 2.0, OpenID Connect, SAML, FIDO2/WebAuthn and SCIM, with low-code flow orchestration (Agama) and a policy engine (Cedarling). Governed by the Linux Foundation and built on the Gluu Server heritage, it is a certified, standards-complete identity building block.
All DPGs in the DPGs for DPI Collection are assessed by the DPGA Secretariat against the DPGs for DPI criteria v2.0. Assessments use publicly available documentation and link to their evidence below. Assessed September 2026.
Layer 1
Recognised DPG
Layer 2
DPI Relevance
Layer 3
DPI Architecture Alignment

Does it provide a foundational DPI function, reusable across sectors, at population scale?
It provides authentication, authorisation and single sign-on, spanning the Digital Identity and Trust Infrastructure domains. Identity infrastructure of this kind is usable by any sector — health, finance, government, enterprise — and the Kubernetes-native design with auto-scaling targets enterprise and national scale.
How the solution's architecture reflects the principles that distinguish DPI from conventional digitisation.
Can other systems connect without modifying the core, using documented open standards?
A full REST API with OpenAPI documentation covers every endpoint, alongside standards-defined discovery endpoints. The project implements the full identity standards suite — OAuth 2.0, certified OpenID Connect, SAML 2.0, FIDO2, SCIM and UMA 2.0 — exchanging JSON in standard JWT, JWK, JWE and SCIM formats.
Is it a modular building block that does one thing well, rather than a monolithic platform?
The Auth Server, Agama orchestration and Cedarling policy engine are independent components. Janssen is the identity infrastructure and relying-party applications sit on top of it; Agama's low-code orchestration lets a country build its own authentication flows without modifying the core.
Can other public and private actors build on top of it?
Because it is standards-based, any OIDC or OAuth relying party can integrate without coordination, and Agama scripts support custom flows. Enterprise deployments worldwide date from its Gluu Server heritage, and Apache 2.0 licensing under Linux Foundation governance removes single-vendor dependency.
Can it run in distributed or federated deployments suited to national infrastructure?
Kubernetes-native, cloud-agnostic and multi-cluster capable, with service mesh compatibility. Self-hosting on any cloud or on premise leaves data fully under the deployer's control, and auto-scaling and service mesh support give high availability by design.
Does it meet the security and privacy bar for population-scale infrastructure?
Security covers brute-force protection, account lockout, encryption, detailed audit logging and security event monitoring, with security best practices published and regular patch releases through GitHub security advisories. Consent management via UMA 2.0, data minimisation through claims and per-jurisdiction configuration give privacy by design.
Criteria: DPGs for DPI Collection criteria v2.0 · Co-stewarded by CDPI, Co-Develop and the DPGA Secretariat.
Spot something out of date? Contact the DPGA