WSO2 Identity Server

Digital Identity

WSO2 Identity Server is an open-source identity and access management product covering single sign-on, multi-factor and federated authentication, consent management and the full standards suite from OAuth 2.0 to SCIM 2.0. It is a candidate identity building block with mature enterprise and government deployments; the open questions are its place inside the wider WSO2 platform and how closely its ecosystem is tied to its commercial originator.

IAM
OAuth 2.0
OIDC
SAML 2.0
FIDO2
SCIM 2.0

All DPGs in the DPGs for DPI Collection are assessed by the DPGA Secretariat against the DPGs for DPI criteria v2.0. Assessments use publicly available documentation and link to their evidence below. Assessed September 2026.

16 of 18 checks met

2 partially met

Layer 1

Recognised DPG

Layer 2

DPI Relevance

Layer 1 Recognised Digital Public Good

Listed in the DPG Registry.
VerifiedVerified DPG logo

Layer 2 DPI Relevance

Does it provide a foundational DPI function, reusable across sectors, at population scale?

Domain fit
Cross-sector reuse
Population scale
3/3

Authentication, authorisation, identity verification and single sign-on place it in the Digital Identity domain. The platform is sector-agnostic, used across government, finance, healthcare and education, with enterprise and government deployments at population scale worldwide.

Layer 3 DPI Architecture Alignment

How the solution's architecture reflects the principles that distinguish DPI from conventional digitisation.

A · Interoperability

3/3

Can other systems connect without modifying the core, using documented open standards?

External API docs
Open standards
Open data formats

REST API documentation is comprehensive with published OpenAPI specifications. Standards coverage is extensive — OAuth 2.0, OpenID Connect, SAML 2.0, FIDO2, SCIM 2.0, UMA 2.0 and WS-Federation — exchanging JSON, JWT, SAML XML and SCIM JSON.

B · Minimalist & Reusable Design

2/3

Is it a modular building block that does one thing well, rather than a monolithic platform?

Modular architecture
Core/app separation · Partially meets
Config-driven adaptability

A modular, OSGi-based connector architecture allows extension through custom authenticators and provisioners, and multi-tenant, configuration-driven deployment avoids code forking with templates for various environments. Because the product sits inside the broader WSO2 platform, the boundary between core infrastructure and surrounding application layer is less sharp than in purpose-built DPI.

C · Ecosystem Enablement

2/3

Can other public and private actors build on top of it?

Third-party buildability
External integrations
No vendor lock-in · Partially meets

An extensive connector framework, SDK and extension marketplace support third-party development, and thousands of enterprise integrations and system integrators build on it. It is Apache 2.0 licensed, but the project originated with WSO2 Inc. and its ecosystem remains closely coupled to the WSO2/Choreo platform.

D · Federation Readiness

3/3

Can it run in distributed or federated deployments suited to national infrastructure?

Federated deployment
Data sovereignty
High availability

Federated identity management is a core feature, with multi-domain federation and identity brokering. On-premise and private cloud deployment keep data within jurisdictional boundaries, and active-active high-availability clustering is documented for production-grade redundancy.

E · Security & Privacy at Scale

3/3

Does it meet the security and privacy bar for population-scale infrastructure?

Infrastructure-grade security
Vulnerability disclosure
Privacy by design

Security documentation is comprehensive, covering encryption, role-based access control and audit logging, and WSO2 publishes security advisories through a responsible disclosure process. Privacy is designed in, with built-in consent management, data minimisation features and GDPR tooling.

Criteria: DPGs for DPI Collection criteria v2.0 · Co-stewarded by CDPI, Co-Develop and the DPGA Secretariat.

Spot something out of date? Contact the DPGA