Casdoor MCP Server
Officialβ€οΈ Sponsors
Related MCP server: production-grade-mcp-agentic-system
π Try it in 30 seconds
No database and no config file needed. This runs Casdoor on SQLite with sample data:
docker run -p 8000:8000 casbin/casdoor-all-in-oneOpen http://localhost:8000 and sign in:
Field | Value |
Organization |
|
Username |
|
Password |
|
The sign-in form has separate organization and username fields. Docs sometimes write this pair as
built-in/adminβ that is the same thing, not a username containing a slash.
Prefer not to install anything? Use the hosted demos:
Demo | URL | Notes |
Writable | Full access, so you can click through everything. All data resets about every 5 minutes. | |
Read-only | Stable global demo. Every write operation fails by design. |
Both accept the same built-in / admin / 123 credentials.
π€ Why Casdoor
Casdoor is a complete identity provider, not an authentication proxy and not a library you embed. It stores your users, issues the tokens, and gives you an admin console to manage all of it β so your applications can delegate login entirely and never handle a password themselves.
One server, many protocols. The same user directory is reachable over OAuth 2.0, OIDC, SAML 2.0, CAS, LDAP and SCIM, so a modern SPA and a legacy CAS-only app can share one set of accounts.
Everything is editable in the UI. Organizations, applications, providers, sign-in methods, email and SMS templates, and login-page branding are configured in the web console instead of in files you have to redeploy.
Policy-based authorization built in. Access rules are expressed with Casbin β ACL, RBAC, ABAC and custom models β rather than a fixed permission scheme.
Straightforward to self-host. A single Go binary plus a database. No JVM, no operator, no cluster required.
If all you need is a login screen in front of an existing reverse proxy, a smaller tool may suit you better. Casdoor is for when you want to own the user directory itself.
π¦ Installation
Four supported paths, fastest first. All of them end up at http://localhost:8000.
Docker β all-in-one (evaluation)
docker run -p 8000:8000 casbin/casdoor-all-in-oneBundles SQLite and demo data into a single container. Ideal for a first look, but not intended for production: the data lives inside the container and disappears with it.
Guide: Try with Docker
Docker Compose β Casdoor with MySQL
docker-compose.yml starts Casdoor next to a MySQL 8 container.
Two things to know before running it:
Compose builds the image from source (Go backend plus React frontend). The first
docker compose uptakes several minutes, so it is not the quick-trial path β use the all-in-one image above for that.You have to point Casdoor at the bundled database first.
Set the MySQL settings in conf/app.conf to match the db service:
driverName = mysql
dataSourceName = root:123456@tcp(localhost:3306)/
dbName = casdoorUse localhost here even though MySQL runs in a separate container: the compose file sets RUNNING_IN_DOCKER=true, and Casdoor rewrites localhost to the Docker host address at startup (see conf/conf.go). Then start everything:
docker compose upThe compose entrypoint already passes --createDatabase=true, so the casdoor database is created for you.
Guide: Try with Docker
Kubernetes β Helm
Requires Helm v3 and a running cluster:
helm install casdoor oci://registry-1.docker.io/casbin/casdoor-helm-chartsThe chart does not expose Casdoor outside the cluster by default. To reach it, find the service and forward a port:
kubectl get svckubectl port-forward svc/<service-name-from-above> 8000:8000For a real deployment, configure an Ingress and an external database through the chart's values. k8s.yaml in this repo is a minimal plain-manifest example if you would rather not use Helm.
Guide: Try with Helm
From source β for development
Use this if you intend to modify Casdoor. Prerequisites: Go 1.25+ (see go.mod), Node.js 20 LTS, Yarn 1.x, and a supported database (MySQL, PostgreSQL, SQLite, SQL Server and others).
git clone https://github.com/casdoor/casdoor.git
cd casdoorSet driverName, dataSourceName and dbName in conf/app.conf. For MySQL, create the casdoor database first, or start the server with --createDatabase=true. Then build the frontend and run the server:
cd web && yarn install && yarn build && cd .. && go run main.goWhile working on the frontend, run yarn start in web/ instead of yarn build to get hot reload on port 7001, with go run main.go serving the API from a second terminal.
Guide: Server installation
π After you sign in
At this point you have a running identity provider with nothing connected to it yet. Next:
Change the
adminpassword.123is a demo credential and must not survive contact with production.Connect your first application β create an Application in the console, copy its Client ID and Client Secret, and point your app's OAuth/OIDC client at Casdoor.
Add an identity provider if you want Google, GitHub or Entra ID sign-in.
Pick an SDK for your language, or call the Public API directly.
β¨ Features
π Authentication
OAuth 2.0 / OIDC β full authorization server and OpenID Connect provider
SAML 2.0 β enterprise SSO, as both IdP and SP
CAS β Central Authentication Service for legacy applications
LDAP β sync from a directory, or serve as one
WebAuthn / passkeys β passwordless sign-in
TOTP / MFA β multi-factor authentication, including email and SMS codes
Face ID β biometric sign-in
π’ Organizations and access control
Multi-tenancy β independent organizations, each with its own users and branding
RBAC and beyond β roles, permissions and Casbin policy models
SCIM 2.0 β automated user provisioning and de-provisioning
Social login β Google, GitHub, Entra ID (Azure AD) and many more
Custom providers β plug in your own identity, email, SMS, storage or payment backends
Audit logs β a record of sign-ins and administrative changes
π€ AI and agents
MCP gateway β expose Model Context Protocol servers and control access to them
A2A β agent-to-agent communication support
π οΈ Developer experience
REST API β every console action is also an API call
SDKs β Go, Java, Python, Node.js, .NET, PHP, Rust and more
Swagger UI β live API explorer
Webhooks β push user and sign-in events into your own systems
Customizable UI β theme the login page and console per organization
π§± Technology stack
Casdoor is a frontendβbackend separated application:
Backend β Go with the Beego framework, exposing REST APIs (repository root)
Frontend β React 18 with shadcn/ui on Tailwind CSS, built with Vite (
web/). The previous Ant Design console is kept for reference atweb-old/and is no longer built or served.Database β MySQL, PostgreSQL, SQLite, SQL Server and others through XORM
Cache β Redis, optional; needed if you run more than one Casdoor replica
π Documentation
The full documentation lives at casdoor.ai/docs. Common starting points:
I want to⦠| Go to |
Install Casdoor | From source · Docker · Helm |
Connect my application | |
Use the API | Public API · Swagger UI |
Choose an SDK | |
Deploy to production |
π SDKs and integrations
Official SDKs and framework integrations, by language:
Go β casdoor-go-sdk
Java β casdoor-java-sdk · Spring Boot starter
Python β casdoor-python-sdk
Node.js β casdoor-nodejs-sdk
JavaScript β casdoor-js-sdk · React · Vue · Angular
.NET β casdoor-dotnet-sdk
PHP β casdoor-php-sdk
Rust β casdoor-rust-sdk
The complete list, including reverse proxies and third-party applications, is in the Integrations documentation.
π Security
Please do not report security vulnerabilities in public GitHub issues. Email admin@casdoor.org instead β SECURITY.md has the full policy and disclosure process.
Before exposing a Casdoor instance to the internet:
Change the built-in
adminpassword. Never ship the demo credential123.Serve Casdoor over HTTPS only, and set
origininconf/app.confto your public URL.Review
conf/app.conffor values inherited from the sample file, especiallydataSourceNameand any provider secrets.Set
runmode = prodand keepshowSql = falsein production.
π€ Community and support
Discord β join the community for questions and help
GitHub Discussions β ask and search here
GitHub Issues β bug reports and feature requests
Commercial support β casdoor.ai/help
π Contributing
Contributions are welcome. For anything larger than a small fix, please open an issue first so you can agree on the approach with the maintainers before writing code.
Read the contribution guidelines before you start.
Translations. User-facing strings in the web console go through i18next. When you add or change one under web/, update the English catalog at web/src/locales/en/data.json. The other languages are translated on Crowdin and should not be edited by hand.
π Support Casdoor
Casdoor is free and open source. If it saves you time, consider supporting its development on Open Collective.
π License
Casdoor is licensed under the Apache License 2.0.
If Casdoor is useful to you, a star helps other people find it.
Β© 2026 Casdoor · Apache License 2.0
This server cannot be deployed
Maintenance
Related MCP Connectors
MCP server connecting AI agents to 100+ apps (Gmail, Slack, Notion, GitHub) via one-click OAuth.
The Remote MCP server acts as a standardized bridge between LLM applications (like Claude, ChatGPT, and Cursor) and external services, enabling AI agents to access external tools and resources. Its primary capability is providing a centralized search tool to discover other MCP servers and their respective tools. Unlike local implementations, it runs remotely with OAuth authentication and permission controls for security.
MCP server for mandates, delegation, policy-gated execution, credential grants, and audit.
MCP server for progressive tool usage at any scale (see https://klavis.ai)
Related MCP Servers
- FlicenseAqualityFmaintenanceMCP server that exposes 300+ AI agents as tools via a single API key. Supports listing agents, invoking any agent with chat-completion style messages, checking agent health, and retrieving platform statistics.53-
- AlicenseNot gradedqualityDmaintenanceA production-grade MCP server designed for multi-tenant, authenticated, and observable AI agent systems, enabling secure tool execution across heterogeneous data sources.64MIT
- AlicenseNot gradedqualityDmaintenanceEnables AI agents to discover and execute tools via a secure MCP server with JWT authentication, RBAC, rate limiting, and audit logging.1MIT
- AlicenseNot gradedqualityAmaintenanceA spec-compliant remote MCP server with built-in OAuth 2.1 and Dynamic Client Registration, enabling Notion Custom Agents to connect via 'Sign in with OAuth' without bearer tokens. It supports SSO federation to Google and Microsoft Entra, and includes basic tools like whoami, echo, and slow_task.MIT