What is FerrisKey?
FerrisKey is an open-source Identity & Access Management (IAM) system written in Rust. It handles authentication, authorization, and user management for your applications, without the operational weight of the older IAM platforms.
What is IAM?
Identity & Access Management answers two questions about every request your system receives:
- Authentication: who are you? Verified through passwords, multi-factor challenges, passkeys, or a federated provider.
- Authorization: what are you allowed to do? Which resources and actions the authenticated identity can reach.
On top of those two, an IAM system issues and validates JWTs, ties applications together with single sign-on, tracks sessions, records an audit trail, and talks to external identity providers.
Why FerrisKey?
FerrisKey was written from scratch for teams who want an IAM they can actually read and reason about.
- Rust foundation: memory safety and predictable performance, with async I/O throughout.
- Multi-tenancy: realms isolate users, clients, roles, credentials, and configuration, so one deployment can serve many organizations.
- Modular: the product is split into focused modules. Turn on the ones you need.
- Open source: licensed under Apache-2.0, developed in the open.
Modules
Each module owns one part of identity management.
Trident
Multi-factor authentication with TOTP, WebAuthn passkeys, magic links, and recovery codes.
SeaWatch
Audit and security events for critical actions across your realms.
Compass
Authentication flow recording and debugging for multi-step sign-in.
Abyss
Identity provider federation for Google, GitHub, Discord, and custom OIDC providers.
Aegis
Scopes and protocol mappers to control what goes into your tokens.
Webhooks
Event-driven integrations for lifecycle events and external notifications.
Organizations
B2B tenancy: organizations, groups, membership, and custom attributes.
SAML
FerrisKey as a SAML 2.0 identity provider for applications that speak nothing else.