Gluu Fournisseur IAM
Open-source identity and access management platform from Austin, Texas, built around the Linux Foundation's Janssen Project (Apache 2.0), which implements OAuth 2.0, OpenID Connect, SAML 2.0, FIDO2, SCIM 2.0, and UMA 2.0. Free to self-host; Gluu Flex is the commercial distribution adding a hosted control plane, Cedarling (an embeddable Cedar-based policy decision point for fine-grained ABAC), Agama Lab (a low-code authentication workflow designer), and enterprise support. Historically known as the Gluu Server; increasingly positioned around Zero Trust and AI agent/workload identity.
Fonctionnalités
Si vous souhaitez comparer les fonctionnalités IAM de différents fournisseurs, consultez le benchmark des fournisseurs d'identité (C)IAM.
Vous cherchez la compatibilité du protocole OpenID Connect de Gluu ? Voir Gluu sur le benchmark des fournisseurs OpenID Connect.
Foire aux questions
Gluu prend-il en charge Nom d'utilisateur et mot de passe méthode d'authentification ?
Gluu prend en charge Nom d'utilisateur et mot de passe méthode d'authentification. Core authentication against the configured persistence layer (LDAP, MySQL, PostgreSQL, Couchbase, or Spanner). En savoir plus
Gluu prend-il en charge Connexion sociale méthode d'authentification ?
Gluu prend en charge Connexion sociale méthode d'authentification. Inbound identity from Google, Facebook, Apple, and other providers historically via the Passport.js module; configurable today via Agama or custom interception scripts. En savoir plus
Gluu prend-il en charge Passkey méthode d'authentification ?
Gluu prend en charge Passkey méthode d'authentification. FIDO2/WebAuthn passkey enrollment and authentication via the jans-fido2 component. En savoir plus
Gluu prend-il en charge Email Passwordless méthode d'authentification ?
Gluu prend partiellement en charge Email Passwordless méthode d'authentification. No built-in email-OTP authenticator; achievable via a custom Agama flow or person authentication script. En savoir plus
Gluu prend-il en charge Phone Passwordless méthode d'authentification ?
Gluu prend partiellement en charge Phone Passwordless méthode d'authentification. No built-in SMS-OTP passwordless authenticator; achievable via custom Agama flow integrating an SMS provider. En savoir plus
Gluu prend-il en charge Anonymous / Guest méthode d'authentification ?
Gluu ne prend pas en charge Anonymous / Guest méthode d'authentification. Gluu requires an identified user or client for authentication; no anonymous/guest session concept.
Gluu prend-il en charge Time-based One-Time Password (TOTP) MFA ?
Gluu prend en charge Time-based One-Time Password (TOTP) MFA. TOTP one-time password authenticator, enrollable via Gluu Casa self-service portal. En savoir plus
Gluu prend-il en charge HMAC-based One-Time Password (HOTP) MFA ?
Gluu prend en charge HMAC-based One-Time Password (HOTP) MFA. OTP interception script supports both HOTP and TOTP modes. En savoir plus
Gluu prend-il en charge Universal 2nd Factor (U2F) MFA ?
Gluu prend partiellement en charge Universal 2nd Factor (U2F) MFA. Legacy FIDO U2F devices supported for migration; new enrollments use FIDO2/WebAuthn. En savoir plus
Gluu prend-il en charge WebAuthn MFA ?
Gluu prend en charge WebAuthn MFA. En savoir plus
Gluu prend-il en charge Email Code MFA ?
Gluu prend partiellement en charge Email Code MFA. Achievable via custom person authentication script; no built-in email-code authenticator.
Gluu prend-il en charge Phone Code MFA ?
Gluu prend partiellement en charge Phone Code MFA. SMS OTP as a second factor achievable via custom script/Agama flow rather than a built-in authenticator.
Gluu prend-il en charge Push Notification MFA ?
Gluu prend en charge Push Notification MFA. Super Gluu is Gluu's free mobile app providing out-of-band push-notification 2FA, backed by FIDO U2F key enrollment. En savoir plus
Gluu prend-il en charge Adaptive / Risk-Based MFA MFA ?
Gluu prend en charge Adaptive / Risk-Based MFA MFA. Context-based/risk-based authentication flows configurable through Agama low-code workflows and interception scripts. En savoir plus
Gluu prend-il en charge Cisco Duo MFA ?
Gluu prend en charge Cisco Duo MFA. Duo Security interception script available for MFA integration. En savoir plus
Gluu prend-il en charge Step-Up Authentication MFA ?
Gluu prend en charge Step-Up Authentication MFA. ACR (Authentication Context Class Reference) values let relying parties request a stronger authentication method for a given transaction. En savoir plus
Gluu prend-il en charge OpenID Connect (OIDC) protocole d'intégration ?
Gluu prend en charge OpenID Connect (OIDC) protocole d'intégration. En savoir plus
Gluu prend-il en charge SAML 2.0 protocole d'intégration ?
Gluu prend en charge SAML 2.0 protocole d'intégration. SAML 2.0 IdP support via the bundled Shibboleth Identity Provider module. En savoir plus
Gluu prend-il en charge WS-Federation protocole d'intégration ?
Gluu ne prend pas en charge WS-Federation protocole d'intégration.
Gluu prend-il en charge Machine-to-Machine (M2M) Authentication protocole d'intégration ?
Gluu prend en charge Machine-to-Machine (M2M) Authentication protocole d'intégration. OAuth 2.0 client credentials grant, plus UMA 2.0 for API resource protection. En savoir plus
Gluu prend-il en charge OpenID Connect (OIDC) Federation fédération d'identité ?
Gluu prend en charge OpenID Connect (OIDC) Federation fédération d'identité. Inbound OIDC identity provider federation configurable via Agama or interception scripts. En savoir plus
Gluu prend-il en charge SAML 2.0 Federation fédération d'identité ?
Gluu prend en charge SAML 2.0 Federation fédération d'identité. SAML federation via the Shibboleth IdP module, including third-party SP/IdP metadata exchange. En savoir plus
Gluu prend-il en charge Active Directory / LDAP fédération d'identité ?
Gluu prend en charge Active Directory / LDAP fédération d'identité. LDAP is one of the pluggable persistence backends, with direct Active Directory bind supported. En savoir plus
Gluu prend-il en charge Azure Active Directory (Entra ID) fédération d'identité ?
Gluu prend en charge Azure Active Directory (Entra ID) fédération d'identité. Azure AD/Entra ID federation via generic OIDC or SAML identity provider configuration. En savoir plus
Gluu prend-il en charge Bulk User Import gestion des utilisateurs ?
Gluu prend en charge Bulk User Import gestion des utilisateurs. Bulk user import via the SCIM 2.0 API or direct persistence-layer import (LDIF/SQL). En savoir plus
Gluu prend-il en charge Password Hash Import (Multiple Formats) gestion des utilisateurs ?
Gluu prend en charge Password Hash Import (Multiple Formats) gestion des utilisateurs. Legacy password hash/credential migration supported via a custom person authentication ("lazy migration") script. En savoir plus
Gluu prend-il en charge Bulk User Export gestion des utilisateurs ?
Gluu prend en charge Bulk User Export gestion des utilisateurs. Bulk user export via the SCIM 2.0 API. En savoir plus
Gluu prend-il en charge Bulk User Update / Delete gestion des utilisateurs ?
Gluu prend en charge Bulk User Update / Delete gestion des utilisateurs. SCIM 2.0 PATCH/DELETE operations for bulk update and delete. En savoir plus
Gluu prend-il en charge Upsert on Import gestion des utilisateurs ?
Gluu prend en charge Upsert on Import gestion des utilisateurs. SCIM 2.0 PATCH supports upsert-style updates. En savoir plus
Gluu prend-il en charge Legacy Username Import (Non-Allowed Characters) gestion des utilisateurs ?
Gluu prend partiellement en charge Legacy Username Import (Non-Allowed Characters) gestion des utilisateurs. Username constraints depend on the configured persistence backend; no universal normalization built in.
Gluu prend-il en charge Inbound SCIM Provisioning gestion des utilisateurs ?
Gluu prend en charge Inbound SCIM Provisioning gestion des utilisateurs. SCIM 2.0 server (RFC 7642/7643/7644) exposes CRUD endpoints for Users and Groups. En savoir plus
Gluu prend-il en charge SCIM Groups Provisioning gestion des utilisateurs ?
Gluu prend en charge SCIM Groups Provisioning gestion des utilisateurs. En savoir plus
Gluu prend-il en charge Just-In-Time (JIT) User Provisioning gestion des utilisateurs ?
Gluu prend en charge Just-In-Time (JIT) User Provisioning gestion des utilisateurs. Just-in-time user creation on first federated (social/SAML/OIDC) login via interception scripts or Agama flows. En savoir plus
Gluu prend-il en charge Lazy / Trickle Migration from Legacy Database gestion des utilisateurs ?
Gluu prend en charge Lazy / Trickle Migration from Legacy Database gestion des utilisateurs. Custom person authentication script pattern validates credentials against a legacy system and migrates the user on first login. En savoir plus
Gluu prend-il en charge Self-Service Profile Management Portal gestion des utilisateurs ?
Gluu prend en charge Self-Service Profile Management Portal gestion des utilisateurs. Gluu Casa is a self-service portal for password reset and credential (FIDO2, TOTP, Super Gluu, SMS, X.509) management. En savoir plus
Gluu prend-il en charge User Account Linking gestion des utilisateurs ?
Gluu prend partiellement en charge User Account Linking gestion des utilisateurs. Achievable via custom interception scripts during federated login; no built-in account-linking UI.
Gluu prend-il en charge User Blocking / Banning gestion des utilisateurs ?
Gluu prend en charge User Blocking / Banning gestion des utilisateurs. User accounts can be disabled via SCIM (active=false) or the admin UI/TUI. En savoir plus
Gluu prend-il en charge User Metadata gestion des utilisateurs ?
Gluu prend en charge User Metadata gestion des utilisateurs. Custom user attributes stored in the configured persistence backend and exposed via SCIM. En savoir plus
Gluu prend-il en charge Application Metadata gestion des utilisateurs ?
Gluu prend en charge Application Metadata gestion des utilisateurs. Custom client attributes configurable via the Config API/TUI. En savoir plus
Gluu prend-il en charge User Search gestion des utilisateurs ?
Gluu prend en charge User Search gestion des utilisateurs. User search via SCIM 2.0 filter queries. En savoir plus
Gluu prend-il en charge Role-Based Access Control (RBAC) gestion des utilisateurs ?
Gluu prend en charge Role-Based Access Control (RBAC) gestion des utilisateurs. Role-based access via OAuth scopes and Cedarling Cedar policies. En savoir plus
Gluu prend-il en charge Password Strength Policies gestion des utilisateurs ?
Gluu prend en charge Password Strength Policies gestion des utilisateurs. En savoir plus
Gluu prend-il en charge Username Restrictions gestion des utilisateurs ?
Gluu prend en charge Username Restrictions gestion des utilisateurs. En savoir plus
Gluu prend-il en charge Attribute-Based Access Control (ABAC) contrôle d'accès ?
Gluu prend en charge Attribute-Based Access Control (ABAC) contrôle d'accès. Cedarling is an embeddable Policy Decision Point built on the Rust Cedar engine, supporting attribute-based access control policies. En savoir plus
Gluu prend-il en charge Fine-Grained Authorization (FGA / ReBAC) contrôle d'accès ?
Gluu prend en charge Fine-Grained Authorization (FGA / ReBAC) contrôle d'accès. Cedarling delivers fine-grained authorization decisions in under 50 microseconds, embeddable client- or server-side. En savoir plus
Gluu prend-il en charge API Authorization (Scopes / Permissions) contrôle d'accès ?
Gluu prend en charge API Authorization (Scopes / Permissions) contrôle d'accès. OAuth 2.0 scopes and UMA 2.0 for centralized API/resource access management, a founding use case of the platform. En savoir plus
Gluu prend-il en charge Audit Log Retention fonctionnalité de sécurité ?
Gluu prend en charge Audit Log Retention fonctionnalité de sécurité. Server and authorization decision logging; retention is operator-configured. En savoir plus
Gluu prend-il en charge Audit Log Streaming fonctionnalité de sécurité ?
Gluu prend en charge Audit Log Streaming fonctionnalité de sécurité. Cedarling decision logs can be connected to ITDR/SIEM platforms for real-time monitoring. En savoir plus
Gluu prend-il en charge Security Center (Threat Monitoring Dashboard) fonctionnalité de sécurité ?
Gluu ne prend pas en charge Security Center (Threat Monitoring Dashboard) fonctionnalité de sécurité.
Gluu prend-il en charge Encryption at Rest fonctionnalité de sécurité ?
Gluu prend partiellement en charge Encryption at Rest fonctionnalité de sécurité. Depends on the configured persistence backend's own encryption-at-rest support; not a built-in Janssen feature.
Gluu prend-il en charge Encryption in Transit fonctionnalité de sécurité ?
Gluu prend en charge Encryption in Transit fonctionnalité de sécurité. TLS enforced for all endpoints; mutual TLS supported for client authentication. En savoir plus
Gluu prend-il en charge Customer Managed Keys (BYOK) fonctionnalité de sécurité ?
Gluu prend en charge Customer Managed Keys (BYOK) fonctionnalité de sécurité. Full key management control via self-hosted deployment. En savoir plus
Gluu prend-il en charge Brute Force Protection fonctionnalité de sécurité ?
Gluu prend en charge Brute Force Protection fonctionnalité de sécurité. Account lockout and rate-limiting configuration for authentication endpoints. En savoir plus
Gluu prend-il en charge Suspicious IP Throttling fonctionnalité de sécurité ?
Gluu prend partiellement en charge Suspicious IP Throttling fonctionnalité de sécurité. Rate limiting configurable at the endpoint level; no dedicated IP-reputation engine documented.
Gluu prend-il en charge Per-Organization Branding multi-tenant ?
Gluu prend partiellement en charge Per-Organization Branding multi-tenant. Login page and templates are customizable per deployment; no multi-organization branding model.
Gluu prend-il en charge Per-Organization MFA Policy multi-tenant ?
Gluu prend partiellement en charge Per-Organization MFA Policy multi-tenant. MFA/ACR policy configurable per client via scopes and interception scripts; not scoped to a multi-org model.
Gluu prend-il en charge Hosted / Universal Login Page fonctionnalité de branding ?
Gluu prend en charge Hosted / Universal Login Page fonctionnalité de branding. En savoir plus
Gluu prend-il en charge White-Label / Full Brand Removal fonctionnalité de branding ?
Gluu prend en charge White-Label / Full Brand Removal fonctionnalité de branding. Login pages, Casa portal, and email templates are fully themeable. En savoir plus
Gluu prend-il en charge Localization / i18n fonctionnalité de branding ?
Gluu prend en charge Localization / i18n fonctionnalité de branding. Multi-language login pages and email templates. En savoir plus
Gluu prend-il en charge Prebuilt UI Components (SDK) fonctionnalité de branding ?
Gluu prend partiellement en charge Prebuilt UI Components (SDK) fonctionnalité de branding. Casa provides a prebuilt self-service UI; no separate general-purpose UI component library. En savoir plus
Gluu prend-il en charge Login / Auth Analytics Dashboard analytique ?
Gluu prend partiellement en charge Login / Auth Analytics Dashboard analytique. Structured audit/decision logs feed external SIEM/ITDR tools; no built-in analytics dashboard.
Gluu prend-il en charge GDPR: Data Export (Portability) conformité ?
Gluu prend en charge GDPR: Data Export (Portability) conformité. User data export via the SCIM 2.0 API. En savoir plus
Gluu prend-il en charge GDPR: Right to be Forgotten (User Deletion) conformité ?
Gluu prend en charge GDPR: Right to be Forgotten (User Deletion) conformité. User deletion via SCIM DELETE. En savoir plus
Gluu prend-il en charge Consent Management conformité ?
Gluu prend en charge Consent Management conformité. OAuth 2.0 consent screen plus post-authentication consent workflows configurable via Agama. En savoir plus
Gluu prend-il en charge Region Deployment conformité ?
Gluu prend en charge Region Deployment conformité. Self-hosted deployment in any region; Flex hosting supports multiple geographic locations per plan. En savoir plus
Gluu prend-il en charge Private Cloud Deployment conformité ?
Gluu prend en charge Private Cloud Deployment conformité. Self-hosted via VM installers, Docker, or Helm charts for Kubernetes. En savoir plus
Gluu prend-il en charge SDK Coverage intégration développeur ?
Gluu prend en charge SDK Coverage intégration développeur. jans-client libraries plus Cedarling SDKs (Rust core with WASM, Python, Java, and mobile bindings). En savoir plus
Gluu prend-il en charge Management API intégration développeur ?
Gluu prend en charge Management API intégration développeur. Config REST API, CLI, and Text-based UI (TUI) for server configuration and client management. En savoir plus
Gluu prend-il en charge Authentication API Rate Limits intégration développeur ?
Gluu prend partiellement en charge Authentication API Rate Limits intégration développeur. Rate limiting configurable per endpoint; no dedicated per-tenant quota system.
Gluu prend-il en charge Actions / Extensibility Pipeline intégration développeur ?
Gluu prend en charge Actions / Extensibility Pipeline intégration développeur. Interception scripts (Python/Java via Jython) and Agama low-code flows for custom authentication and authorization logic. En savoir plus
Gluu prend-il en charge TypeScript Support in Extensibility intégration développeur ?
Gluu ne prend pas en charge TypeScript Support in Extensibility intégration développeur. Custom logic is written in Python/Java (interception scripts) or the Agama DSL, not TypeScript/JavaScript.
Gluu prend-il en charge Custom Domain intégration développeur ?
Gluu prend en charge Custom Domain intégration développeur. Self-hosted deployment supports any custom domain. En savoir plus
Gluu prend-il en charge Deploy CLI (Infrastructure as Code) intégration développeur ?
Gluu prend en charge Deploy CLI (Infrastructure as Code) intégration développeur. Janssen CLI and Text-based UI (TUI) for scripted configuration; Helm charts for Kubernetes CI/CD. En savoir plus
Gluu prend-il en charge Terraform Provider intégration développeur ?
Gluu prend en charge Terraform Provider intégration développeur. Official JanssenProject/terraform-provider-jans manages auth server configuration, clients, scopes, users, and scripts as code. En savoir plus
Gluu prend-il en charge Custom Database Connections intégration développeur ?
Gluu prend en charge Custom Database Connections intégration développeur. Pluggable persistence layer supports LDAP, MySQL, PostgreSQL, Couchbase, and Spanner, including hybrid combinations per data category. En savoir plus
Gluu prend-il en charge Universal Login / Hosted Login Page Customization intégration développeur ?
Gluu prend en charge Universal Login / Hosted Login Page Customization intégration développeur. Full HTML/CSS customization of the hosted login pages. En savoir plus
Gluu prend-il en charge Custom Email Provider (SMTP) intégration développeur ?
Gluu prend en charge Custom Email Provider (SMTP) intégration développeur. Configurable SMTP server for outbound notifications. En savoir plus
Gluu prend-il en charge Email Templates intégration développeur ?
Gluu prend en charge Email Templates intégration développeur. En savoir plus
Gluu prend-il en charge Custom OIDC Claims / Token Enrichment intégration développeur ?
Gluu prend en charge Custom OIDC Claims / Token Enrichment intégration développeur. Custom scopes and claims via dynamic scopes and interception scripts. En savoir plus
Gluu prend-il en charge No-Code Auth Flow Builder / Orchestration fonctionnalité ?
Gluu prend en charge No-Code Auth Flow Builder / Orchestration fonctionnalité. Agama Lab provides a drag-and-drop designer for building multi-step, multi-factor authentication workflows without coding. En savoir plus
Gluu prend-il en charge Built-in Billing / Subscription Management fonctionnalité ?
Gluu ne prend pas en charge Built-in Billing / Subscription Management fonctionnalité.
Gluu prend-il en charge Agentic AI / MCP Server Authentication fonctionnalité ?
Gluu prend en charge Agentic AI / MCP Server Authentication fonctionnalité. Gluu Flex mints scoped JWTs for both workload and person identity, and Cedarling is positioned for AI agent authorization decisions as part of a Token-Based Access Control (TBAC) model. En savoir plus
Gluu prend-il en charge Post-Quantum Hybrid TLS Key Exchange fonctionnalité de cryptographie post-quantique ?
Gluu ne prend pas en charge Post-Quantum Hybrid TLS Key Exchange fonctionnalité de cryptographie post-quantique. The Janssen auth-server (Gluu's open-source successor) runs on Java. Java's own hybrid PQC TLS 1.3 support (JEP 527) only reached JDK 27 early-access builds in 2026 and is not yet GA; even once available it would be a JVM/runtime capability, not a documented Janssen/Gluu vendor feature, and TLS termination is typically handled by an operator-controlled reverse proxy in front of the auth server. En savoir plus
Gluu prend-il en charge Post-Quantum Digital Signature Algorithms fonctionnalité de cryptographie post-quantique ?
Gluu ne prend pas en charge Post-Quantum Digital Signature Algorithms fonctionnalité de cryptographie post-quantique. No PQC JWA signing support is shipped. There is one open GitHub feature request in the Janssen Project repo (issue #14253, 'enable post quantum algorithms on AS', milestone 2.6.0), but it has no linked PR, no specified algorithms, and is unimplemented. En savoir plus
Gluu prend-il en charge Post-Quantum Migration Roadmap fonctionnalité de cryptographie post-quantique ?
Gluu prend partiellement en charge Post-Quantum Migration Roadmap fonctionnalité de cryptographie post-quantique. The only public roadmap signal is GitHub issue #14253 in JanssenProject/jans, an open, milestone-tagged (2.6.0) feature request to enable post-quantum algorithms on the Auth Server. This is a maintainer-filed backlog item, not a published roadmap document, blog post, or whitepaper; no timeline or algorithm scope has been disclosed. En savoir plus
Gluu prend-il en charge Post-Quantum Token & Data Encryption fonctionnalité de cryptographie post-quantique ?
Gluu ne prend pas en charge Post-Quantum Token & Data Encryption fonctionnalité de cryptographie post-quantique. No public evidence found that the provider supports ML-KEM or HPKE (RFC 9180) for encrypting JWE tokens, SAML assertions, or user secrets.
Gluu prend-il en charge Post-Quantum Certificate & mTLS Support fonctionnalité de cryptographie post-quantique ?
Gluu ne prend pas en charge Post-Quantum Certificate & mTLS Support fonctionnalité de cryptographie post-quantique. No public evidence found of post-quantum or hybrid X.509 digital certificate support for mTLS client authentication or federation endpoints.
Gluu prend-il en charge Post-Quantum Stateful Hash Signatures fonctionnalité de cryptographie post-quantique ?
Gluu ne prend pas en charge Post-Quantum Stateful Hash Signatures fonctionnalité de cryptographie post-quantique. No public evidence found of NIST SP 800-208 stateful hash-based signature scheme support (LMS/HSS, XMSS).
Comparer avec d'autres fournisseurs
Remarque : Les données actuelles sont basées sur la documentation/l'expérience des fournisseurs et peuvent ne pas être exactes à 100 %. Veuillez ouvrir un ticket si vous avez constaté des incohérences.