Back to discovery
Frameworks

Casdoor

An open-source Agent-first Identity and Access Management (IAM) /LLM MCP & agent gateway and auth server with web UI supporting OpenClaw, MCP, OAuth, OIDC, SAML, CAS, LDAP, SCIM, WebAuthn, TOTP, MFA, Face ID, Google Workspace, Azure AD

Worth exploring for

Building and shipping AI agents

In our collection

4 releases

Source

Official GitHub release feed

Follow the changes

The release trail

Atom feed

Original notes, ready to explore. Open a release to see what changed.

Casdoorv4.6.0

From the release notes

Changelog Features bb76eb6 feat: add magic link sign-in Bug fixes fbcb496 fix: keep empty forceLanguage empty so browser language detection works 0db629e fix: keep resolved RADIUS/push provider id through MFA setup enable step 4684d70 fix: read SAMLRequest case-insensitively in auth callback 91ae9d6 fix: redirect to the single OAuth provider only once instead of on every render 7bf924a fix: reset signin method rule when its name changes so WebAuthn stays visible

Casdoorv4.5.0

From the release notes

Changelog Features fb38eae feat: add group add/delete actions to group tree page 39a1bba feat: support popup mode for Captcha providers Bug fixes 0f629eb fix: URL-encode OAuth state on interactive login, consent, prompt, signup and post-logout redirects 1d65427 fix: allow only global admins to change applications' custom HTML f82480a fix: allow org admins to import groups, roles and permissions via xlsx 15e3c21 fix: authorize get-permissions-by-submitter against the signed-in user d484bf5 fix: bind token exchange to the audience and organization of the target application f88e92c fix: block intranet addresses in non-built-in organizations' webhooks d8c06ad fix: check token revocation in token exchange, enforce MFA and verified email when binding social logins 1f4e299 fix: enforce SAML audience, validity window, InResponseTo and replay protection in SP 4c27d13 fix: index token by organization and user to speed up forbidding a user 7fc8c7f fix: mask global cert private keys from org admins 322f84d fix: move password history out of user table to avoid MySQL row size limit cd938de fix: restore Edit LDAP, organization transactions and MCP Store buttons missing from the new frontend 6a99ac7 fix: restrict email, SMS and notification providers to the caller's organization 0af4692 fix: restrict resource storage providers and file paths to the caller's organization and user f81531b fix: scope application credentials to their own organization 47558d3 fix: scope get-resources to the caller and restrict direct listing to admins 0aafb57 fix: scope rename triggers to their own organization 58aa959 fix: scope user rename to the user's own organization

Casdoorv4.4.0

From the release notes

Changelog Features d60b5ae feat: add configurable password history check e1aa116 feat: add organization-level defaultTokenFields for new applications d6f2cb6 feat: show device, IP and last active time for each session e7f2799 feat: support app-level dark logo fbacaea feat: support group-level subscriptions ed417c1 feat: support invite-only pricing Bug fixes 3eb9231 fix(web): keep draft rows in key-value tables 0920d5d fix: carry the OAuth provider's email_verified through to the user (#5828) 251c76b fix: don't mark every group as having children in GetGroups() 6d6587d fix: keep CORS headers for concrete origins in proxy 991a5f1 fix: keep MFA providers in masked application so users can set up RADIUS MFA 0123751 fix: let RFC 7592 DCR endpoints bypass AutoSigninFilter 145f4c8 fix: only expire the logging-out user's tokens on session logout 5dd3de0 fix: record syncer errors instead of panicking at startup 4054ad5 fix: skip CORS headers when request has no Origin

Casdoorv4.3.0

From the release notes

Changelog Features 8e48365 feat: fall back to user/list_id in WeCom syncer a61599b feat: support department sync in WeCom syncer Bug fixes 311f4d1 fix(auth): drop the panel card on a phone 0b1a605 fix: keep LDAP auto-sync alive after a connection panic e8db3f9 fix: list all organizations' rows when "All" is selected f886a09 fix: report the real reason when uploading users fails 1f86f4c fix: report why WeCom department names are missing 05ea63a fix: run LDAP auto-sync on only one node 3d51fc2 fix: send back-channel logout before expiring tokens 870ab7f fix: show organization display name in provider's org select Build & CI 2708822 ci: retry go mod vendor on proxy HTTP/2 resets

A collected snapshot, not the complete archive.

Keep connecting the dots

Pydantic AI

Bring type safety to your agent stack. Build Python agents with structured outputs and a familiar developer experience.

Frameworks
smolagents

Small library, big possibilities. Let agents solve tasks by writing and executing code with Hugging Face’s toolkit.

Frameworks
Google ADK

A code-first toolkit for building, evaluating, and deploying agents, from a single task to a multi-agent system.

Frameworks