Janssen Project

Digital Identity

The Janssen Project is an open-source identity and access management server providing OAuth 2.0, OpenID Connect, SAML, FIDO2/WebAuthn and SCIM, with low-code flow orchestration (Agama) and a policy engine (Cedarling). Governed by the Linux Foundation and built on the Gluu Server heritage, it is a certified, standards-complete identity building block.

OAuth 2.0 server
OpenID Connect provider
SSO
SAML IdP
FIDO2/WebAuthn
SCIM

All DPGs in the DPGs for DPI Collection are assessed by the DPGA Secretariat against the DPGs for DPI criteria v2.0. Assessments use publicly available documentation and link to their evidence below. Assessed September 2026.

18 of 18 checks met

Layer 1

Recognised DPG

Layer 2

DPI Relevance

Layer 1 Recognised Digital Public Good

Listed in the DPG Registry.
VerifiedVerified DPG logo

Layer 2 DPI Relevance

Does it provide a foundational DPI function, reusable across sectors, at population scale?

Domain fit
Cross-sector reuse
Population scale
3/3

It provides authentication, authorisation and single sign-on, spanning the Digital Identity and Trust Infrastructure domains. Identity infrastructure of this kind is usable by any sector — health, finance, government, enterprise — and the Kubernetes-native design with auto-scaling targets enterprise and national scale.

Layer 3 DPI Architecture Alignment

How the solution's architecture reflects the principles that distinguish DPI from conventional digitisation.

A · Interoperability

3/3

Can other systems connect without modifying the core, using documented open standards?

External API docs
Open standards
Open data formats

A full REST API with OpenAPI documentation covers every endpoint, alongside standards-defined discovery endpoints. The project implements the full identity standards suite — OAuth 2.0, certified OpenID Connect, SAML 2.0, FIDO2, SCIM and UMA 2.0 — exchanging JSON in standard JWT, JWK, JWE and SCIM formats.

B · Minimalist & Reusable Design

3/3

Is it a modular building block that does one thing well, rather than a monolithic platform?

Modular architecture
Core/app separation
Config-driven adaptability

The Auth Server, Agama orchestration and Cedarling policy engine are independent components. Janssen is the identity infrastructure and relying-party applications sit on top of it; Agama's low-code orchestration lets a country build its own authentication flows without modifying the core.

C · Ecosystem Enablement

3/3

Can other public and private actors build on top of it?

Third-party buildability
External integrations
No vendor lock-in

Because it is standards-based, any OIDC or OAuth relying party can integrate without coordination, and Agama scripts support custom flows. Enterprise deployments worldwide date from its Gluu Server heritage, and Apache 2.0 licensing under Linux Foundation governance removes single-vendor dependency.

D · Federation Readiness

3/3

Can it run in distributed or federated deployments suited to national infrastructure?

Federated deployment
Data sovereignty
High availability

Kubernetes-native, cloud-agnostic and multi-cluster capable, with service mesh compatibility. Self-hosting on any cloud or on premise leaves data fully under the deployer's control, and auto-scaling and service mesh support give high availability by design.

E · Security & Privacy at Scale

3/3

Does it meet the security and privacy bar for population-scale infrastructure?

Infrastructure-grade security
Vulnerability disclosure
Privacy by design

Security covers brute-force protection, account lockout, encryption, detailed audit logging and security event monitoring, with security best practices published and regular patch releases through GitHub security advisories. Consent management via UMA 2.0, data minimisation through claims and per-jurisdiction configuration give privacy by design.

Criteria: DPGs for DPI Collection criteria v2.0 · Co-stewarded by CDPI, Co-Develop and the DPGA Secretariat.

Spot something out of date? Contact the DPGA