WSO2 Identity Server is an open-source identity and access management product covering single sign-on, multi-factor and federated authentication, consent management and the full standards suite from OAuth 2.0 to SCIM 2.0. It is a candidate identity building block with mature enterprise and government deployments; the open questions are its place inside the wider WSO2 platform and how closely its ecosystem is tied to its commercial originator.
All DPGs in the DPGs for DPI Collection are assessed by the DPGA Secretariat against the DPGs for DPI criteria v2.0. Assessments use publicly available documentation and link to their evidence below. Assessed September 2026.
2 partially met
Layer 1
Recognised DPG
Layer 2
DPI Relevance
Layer 3
DPI Architecture Alignment

Does it provide a foundational DPI function, reusable across sectors, at population scale?
Authentication, authorisation, identity verification and single sign-on place it in the Digital Identity domain. The platform is sector-agnostic, used across government, finance, healthcare and education, with enterprise and government deployments at population scale worldwide.
How the solution's architecture reflects the principles that distinguish DPI from conventional digitisation.
Can other systems connect without modifying the core, using documented open standards?
REST API documentation is comprehensive with published OpenAPI specifications. Standards coverage is extensive — OAuth 2.0, OpenID Connect, SAML 2.0, FIDO2, SCIM 2.0, UMA 2.0 and WS-Federation — exchanging JSON, JWT, SAML XML and SCIM JSON.
Is it a modular building block that does one thing well, rather than a monolithic platform?
A modular, OSGi-based connector architecture allows extension through custom authenticators and provisioners, and multi-tenant, configuration-driven deployment avoids code forking with templates for various environments. Because the product sits inside the broader WSO2 platform, the boundary between core infrastructure and surrounding application layer is less sharp than in purpose-built DPI.
Can other public and private actors build on top of it?
An extensive connector framework, SDK and extension marketplace support third-party development, and thousands of enterprise integrations and system integrators build on it. It is Apache 2.0 licensed, but the project originated with WSO2 Inc. and its ecosystem remains closely coupled to the WSO2/Choreo platform.
Can it run in distributed or federated deployments suited to national infrastructure?
Federated identity management is a core feature, with multi-domain federation and identity brokering. On-premise and private cloud deployment keep data within jurisdictional boundaries, and active-active high-availability clustering is documented for production-grade redundancy.
Does it meet the security and privacy bar for population-scale infrastructure?
Security documentation is comprehensive, covering encryption, role-based access control and audit logging, and WSO2 publishes security advisories through a responsible disclosure process. Privacy is designed in, with built-in consent management, data minimisation features and GDPR tooling.
Criteria: DPGs for DPI Collection criteria v2.0 · Co-stewarded by CDPI, Co-Develop and the DPGA Secretariat.
Spot something out of date? Contact the DPGA