@cerberus-iam

Cerberus IAM

🛡️ Multi-tenant identity and access management: directory, local auth, OIDC, RBAC, admin console, and developer tooling for secure SaaS platforms.

Cerberus IAM

Enterprise-grade Identity and Access Management for modern SaaS applications.

Cerberus IAM delivers the complete identity infrastructure your product needs without building it from scratch. We provide secure authentication, fine-grained authorization, multi-tenant user directories, and standards-compliant OAuth 2.1/OpenID Connect—all built with TypeScript and designed for production.

What We're Building

Identity and access management shouldn't be something every team has to build from the ground up. Cerberus IAM gives you the foundational identity layer so you can focus on your product.

Core Capabilities

Authentication

  • Email/password authentication with Argon2id hashing
  • Session management with secure cookies and refresh token rotation
  • Password reset and email verification flows
  • Device and session controls with reuse detection
  • Multi-factor authentication (TOTP) — in development

User Directory

  • Multi-tenant organizations with complete data isolation
  • Users, teams, roles, and hierarchical permissions
  • Team-based grouping and access control
  • Comprehensive audit logs for compliance
  • Built on PostgreSQL with Prisma ORM

OAuth 2.1 & OpenID Connect

  • Full authorization server implementation
  • Authorization code flow with PKCE
  • Discovery, JWKS, token, userinfo, introspection, and revocation endpoints
  • Standards-compliant responses (RFC 6749, RFC 7662, RFC 7009, RFC 7517)
  • OAuth2 client management with secret rotation

Authorization

  • Role-Based Access Control (RBAC) with fine-grained permissions
  • Organization-level and team-level isolation
  • Permission wildcards for flexible policy definitions
  • Effective permission computation for policy enforcement
  • API key authentication for programmatic access

Admin Console

  • Web-based admin interface for tenant operators
  • User, team, and role management
  • OAuth2 client administration
  • Session monitoring and control
  • Audit log browsing
  • Modern UI with dark mode support

Developer Experience

  • TypeScript-first with comprehensive types
  • RESTful API with OpenAPI documentation
  • Zod schema validation
  • Result pattern for error handling
  • Extensive test coverage (unit, integration, e2e)

Why Cerberus IAM?

Security by Default

  • Argon2id password hashing
  • CSRF protection and rate limiting
  • HTTP-only secure cookies
  • Helmet.js security headers
  • Encrypted secret storage
  • Comprehensive audit trails

Standards Compliant

  • OAuth 2.1 authorization server
  • OpenID Connect 1.0 identity provider
  • PKCE required by default
  • Industry-standard token formats and flows

Production Ready

  • Multi-tenant architecture with tenant isolation
  • Structured logging with Pino
  • OpenTelemetry readiness
  • Docker containerization
  • Database migrations with Prisma
  • Comprehensive test suites

Modern Stack

  • TypeScript 5 throughout
  • Node.js + Express.js for the API
  • Next.js + React for admin console
  • PostgreSQL for data persistence
  • Railway-ready deployment

Project Status

Cerberus IAM is under active development. Core authentication, authorization, and user management features are functional and tested. The platform is suitable for development and evaluation but should undergo security review before production deployment.

Currently Available:

  • Multi-tenant user directory with RBAC
  • Email/password authentication
  • Session management with secure cookies
  • OAuth2/OIDC provider (authorization code + PKCE)
  • Admin console for user/team/client management
  • API key authentication
  • PostgreSQL with migrations
  • Comprehensive test suites

In Development:

  • User-facing authentication portal
  • Multi-factor authentication (TOTP)
  • Social login providers (Google, GitHub)
  • Webhook notifications
  • Advanced RBAC policy engine

Getting Started

Explore our repositories to get started:

  • api — Core IAM API and OAuth2/OIDC provider
  • app — Admin console web application
  • web — User-facing authentication portal

Each repository contains detailed setup instructions, documentation, and examples.

Community

We welcome contributions, feedback, and collaboration!

  • Documentation: Visit our comprehensive docs for API references, architecture guides, and deployment instructions
  • Issues: Report bugs and request features in the respective repository
  • Security: See SECURITY.md in each repository for responsible disclosure
  • Code of Conduct: We maintain a welcoming, inclusive community — see CODE_OF_CONDUCT.md

Philosophy

Secure identity should be attainable for every product team. Cerberus IAM is built with the belief that identity infrastructure should be:

  • Secure by default — Best practices baked in, not bolted on
  • Standards-compliant — OAuth 2.1, OIDC, and industry standards
  • Developer-friendly — TypeScript, great docs, and excellent DX
  • Production-ready — Multi-tenant, scalable, and observable

Built with ❤️ by Jerome Thayananthajothy

Popular repositories Loading

  1. laravel-sdk laravel-sdkPublic

    🛡️ Cerberus IAM Laravel Integration Package (PHP)

    PHP 1

  2. .github .githubPublic

    🛡️ Shared configuration and profile for the Cerberus IAM organization

Repositories

Showing 2 of 2 repositories

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
@cerberus-iam

Cerberus IAM

🛡️ Multi-tenant identity and access management: directory, local auth, OIDC, RBAC, admin console, and developer tooling for secure SaaS platforms.

Cerberus IAM

Enterprise-grade Identity and Access Management for modern SaaS applications.

Cerberus IAM delivers the complete identity infrastructure your product needs without building it from scratch. We provide secure authentication, fine-grained authorization, multi-tenant user directories, and standards-compliant OAuth 2.1/OpenID Connect—all built with TypeScript and designed for production.

What We're Building

Identity and access management shouldn't be something every team has to build from the ground up. Cerberus IAM gives you the foundational identity layer so you can focus on your product.

Core Capabilities

Authentication

  • Email/password authentication with Argon2id hashing
  • Session management with secure cookies and refresh token rotation
  • Password reset and email verification flows
  • Device and session controls with reuse detection
  • Multi-factor authentication (TOTP) — in development

User Directory

  • Multi-tenant organizations with complete data isolation
  • Users, teams, roles, and hierarchical permissions
  • Team-based grouping and access control
  • Comprehensive audit logs for compliance
  • Built on PostgreSQL with Prisma ORM

OAuth 2.1 & OpenID Connect

  • Full authorization server implementation
  • Authorization code flow with PKCE
  • Discovery, JWKS, token, userinfo, introspection, and revocation endpoints
  • Standards-compliant responses (RFC 6749, RFC 7662, RFC 7009, RFC 7517)
  • OAuth2 client management with secret rotation

Authorization

  • Role-Based Access Control (RBAC) with fine-grained permissions
  • Organization-level and team-level isolation
  • Permission wildcards for flexible policy definitions
  • Effective permission computation for policy enforcement
  • API key authentication for programmatic access

Admin Console

  • Web-based admin interface for tenant operators
  • User, team, and role management
  • OAuth2 client administration
  • Session monitoring and control
  • Audit log browsing
  • Modern UI with dark mode support

Developer Experience

  • TypeScript-first with comprehensive types
  • RESTful API with OpenAPI documentation
  • Zod schema validation
  • Result pattern for error handling
  • Extensive test coverage (unit, integration, e2e)

Why Cerberus IAM?

Security by Default

  • Argon2id password hashing
  • CSRF protection and rate limiting
  • HTTP-only secure cookies
  • Helmet.js security headers
  • Encrypted secret storage
  • Comprehensive audit trails

Standards Compliant

  • OAuth 2.1 authorization server
  • OpenID Connect 1.0 identity provider
  • PKCE required by default
  • Industry-standard token formats and flows

Production Ready

  • Multi-tenant architecture with tenant isolation
  • Structured logging with Pino
  • OpenTelemetry readiness
  • Docker containerization
  • Database migrations with Prisma
  • Comprehensive test suites

Modern Stack

  • TypeScript 5 throughout
  • Node.js + Express.js for the API
  • Next.js + React for admin console
  • PostgreSQL for data persistence
  • Railway-ready deployment

Project Status

Cerberus IAM is under active development. Core authentication, authorization, and user management features are functional and tested. The platform is suitable for development and evaluation but should undergo security review before production deployment.

Currently Available:

  • Multi-tenant user directory with RBAC
  • Email/password authentication
  • Session management with secure cookies
  • OAuth2/OIDC provider (authorization code + PKCE)
  • Admin console for user/team/client management
  • API key authentication
  • PostgreSQL with migrations
  • Comprehensive test suites

In Development:

  • User-facing authentication portal
  • Multi-factor authentication (TOTP)
  • Social login providers (Google, GitHub)
  • Webhook notifications
  • Advanced RBAC policy engine

Getting Started

Explore our repositories to get started:

  • api — Core IAM API and OAuth2/OIDC provider
  • app — Admin console web application
  • web — User-facing authentication portal

Each repository contains detailed setup instructions, documentation, and examples.

Community

We welcome contributions, feedback, and collaboration!

  • Documentation: Visit our comprehensive docs for API references, architecture guides, and deployment instructions
  • Issues: Report bugs and request features in the respective repository
  • Security: See SECURITY.md in each repository for responsible disclosure
  • Code of Conduct: We maintain a welcoming, inclusive community — see CODE_OF_CONDUCT.md

Philosophy

Secure identity should be attainable for every product team. Cerberus IAM is built with the belief that identity infrastructure should be:

  • Secure by default — Best practices baked in, not bolted on
  • Standards-compliant — OAuth 2.1, OIDC, and industry standards
  • Developer-friendly — TypeScript, great docs, and excellent DX
  • Production-ready — Multi-tenant, scalable, and observable

Built with ❤️ by Jerome Thayananthajothy

Popular repositories Loading

  1. laravel-sdk laravel-sdkPublic

    🛡️ Cerberus IAM Laravel Integration Package (PHP)

    PHP 1

  2. .github .githubPublic

    🛡️ Shared configuration and profile for the Cerberus IAM organization

Repositories

Showing 2 of 2 repositories

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
@cerberus-iam

Cerberus IAM

🛡️ Multi-tenant identity and access management: directory, local auth, OIDC, RBAC, admin console, and developer tooling for secure SaaS platforms.

Cerberus IAM

Enterprise-grade Identity and Access Management for modern SaaS applications.

Cerberus IAM delivers the complete identity infrastructure your product needs without building it from scratch. We provide secure authentication, fine-grained authorization, multi-tenant user directories, and standards-compliant OAuth 2.1/OpenID Connect—all built with TypeScript and designed for production.

What We're Building

Identity and access management shouldn't be something every team has to build from the ground up. Cerberus IAM gives you the foundational identity layer so you can focus on your product.

Core Capabilities

Authentication

  • Email/password authentication with Argon2id hashing
  • Session management with secure cookies and refresh token rotation
  • Password reset and email verification flows
  • Device and session controls with reuse detection
  • Multi-factor authentication (TOTP) — in development

User Directory

  • Multi-tenant organizations with complete data isolation
  • Users, teams, roles, and hierarchical permissions
  • Team-based grouping and access control
  • Comprehensive audit logs for compliance
  • Built on PostgreSQL with Prisma ORM

OAuth 2.1 & OpenID Connect

  • Full authorization server implementation
  • Authorization code flow with PKCE
  • Discovery, JWKS, token, userinfo, introspection, and revocation endpoints
  • Standards-compliant responses (RFC 6749, RFC 7662, RFC 7009, RFC 7517)
  • OAuth2 client management with secret rotation

Authorization

  • Role-Based Access Control (RBAC) with fine-grained permissions
  • Organization-level and team-level isolation
  • Permission wildcards for flexible policy definitions
  • Effective permission computation for policy enforcement
  • API key authentication for programmatic access

Admin Console

  • Web-based admin interface for tenant operators
  • User, team, and role management
  • OAuth2 client administration
  • Session monitoring and control
  • Audit log browsing
  • Modern UI with dark mode support

Developer Experience

  • TypeScript-first with comprehensive types
  • RESTful API with OpenAPI documentation
  • Zod schema validation
  • Result pattern for error handling
  • Extensive test coverage (unit, integration, e2e)

Why Cerberus IAM?

Security by Default

  • Argon2id password hashing
  • CSRF protection and rate limiting
  • HTTP-only secure cookies
  • Helmet.js security headers
  • Encrypted secret storage
  • Comprehensive audit trails

Standards Compliant

  • OAuth 2.1 authorization server
  • OpenID Connect 1.0 identity provider
  • PKCE required by default
  • Industry-standard token formats and flows

Production Ready

  • Multi-tenant architecture with tenant isolation
  • Structured logging with Pino
  • OpenTelemetry readiness
  • Docker containerization
  • Database migrations with Prisma
  • Comprehensive test suites

Modern Stack

  • TypeScript 5 throughout
  • Node.js + Express.js for the API
  • Next.js + React for admin console
  • PostgreSQL for data persistence
  • Railway-ready deployment

Project Status

Cerberus IAM is under active development. Core authentication, authorization, and user management features are functional and tested. The platform is suitable for development and evaluation but should undergo security review before production deployment.

Currently Available:

  • Multi-tenant user directory with RBAC
  • Email/password authentication
  • Session management with secure cookies
  • OAuth2/OIDC provider (authorization code + PKCE)
  • Admin console for user/team/client management
  • API key authentication
  • PostgreSQL with migrations
  • Comprehensive test suites

In Development:

  • User-facing authentication portal
  • Multi-factor authentication (TOTP)
  • Social login providers (Google, GitHub)
  • Webhook notifications
  • Advanced RBAC policy engine

Getting Started

Explore our repositories to get started:

  • api — Core IAM API and OAuth2/OIDC provider
  • app — Admin console web application
  • web — User-facing authentication portal

Each repository contains detailed setup instructions, documentation, and examples.

Community

We welcome contributions, feedback, and collaboration!

  • Documentation: Visit our comprehensive docs for API references, architecture guides, and deployment instructions
  • Issues: Report bugs and request features in the respective repository
  • Security: See SECURITY.md in each repository for responsible disclosure
  • Code of Conduct: We maintain a welcoming, inclusive community — see CODE_OF_CONDUCT.md

Philosophy

Secure identity should be attainable for every product team. Cerberus IAM is built with the belief that identity infrastructure should be:

  • Secure by default — Best practices baked in, not bolted on
  • Standards-compliant — OAuth 2.1, OIDC, and industry standards
  • Developer-friendly — TypeScript, great docs, and excellent DX
  • Production-ready — Multi-tenant, scalable, and observable

Built with ❤️ by Jerome Thayananthajothy

Popular repositories Loading

  1. laravel-sdk laravel-sdkPublic

    🛡️ Cerberus IAM Laravel Integration Package (PHP)

    PHP 1

  2. .github .githubPublic

    🛡️ Shared configuration and profile for the Cerberus IAM organization

Repositories

Showing 2 of 2 repositories

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
@cerberus-iam

Cerberus IAM

🛡️ Multi-tenant identity and access management: directory, local auth, OIDC, RBAC, admin console, and developer tooling for secure SaaS platforms.

Cerberus IAM

Enterprise-grade Identity and Access Management for modern SaaS applications.

Cerberus IAM delivers the complete identity infrastructure your product needs without building it from scratch. We provide secure authentication, fine-grained authorization, multi-tenant user directories, and standards-compliant OAuth 2.1/OpenID Connect—all built with TypeScript and designed for production.

What We're Building

Identity and access management shouldn't be something every team has to build from the ground up. Cerberus IAM gives you the foundational identity layer so you can focus on your product.

Core Capabilities

Authentication

  • Email/password authentication with Argon2id hashing
  • Session management with secure cookies and refresh token rotation
  • Password reset and email verification flows
  • Device and session controls with reuse detection
  • Multi-factor authentication (TOTP) — in development

User Directory

  • Multi-tenant organizations with complete data isolation
  • Users, teams, roles, and hierarchical permissions
  • Team-based grouping and access control
  • Comprehensive audit logs for compliance
  • Built on PostgreSQL with Prisma ORM

OAuth 2.1 & OpenID Connect

  • Full authorization server implementation
  • Authorization code flow with PKCE
  • Discovery, JWKS, token, userinfo, introspection, and revocation endpoints
  • Standards-compliant responses (RFC 6749, RFC 7662, RFC 7009, RFC 7517)
  • OAuth2 client management with secret rotation

Authorization

  • Role-Based Access Control (RBAC) with fine-grained permissions
  • Organization-level and team-level isolation
  • Permission wildcards for flexible policy definitions
  • Effective permission computation for policy enforcement
  • API key authentication for programmatic access

Admin Console

  • Web-based admin interface for tenant operators
  • User, team, and role management
  • OAuth2 client administration
  • Session monitoring and control
  • Audit log browsing
  • Modern UI with dark mode support

Developer Experience

  • TypeScript-first with comprehensive types
  • RESTful API with OpenAPI documentation
  • Zod schema validation
  • Result pattern for error handling
  • Extensive test coverage (unit, integration, e2e)

Why Cerberus IAM?

Security by Default

  • Argon2id password hashing
  • CSRF protection and rate limiting
  • HTTP-only secure cookies
  • Helmet.js security headers
  • Encrypted secret storage
  • Comprehensive audit trails

Standards Compliant

  • OAuth 2.1 authorization server
  • OpenID Connect 1.0 identity provider
  • PKCE required by default
  • Industry-standard token formats and flows

Production Ready

  • Multi-tenant architecture with tenant isolation
  • Structured logging with Pino
  • OpenTelemetry readiness
  • Docker containerization
  • Database migrations with Prisma
  • Comprehensive test suites

Modern Stack

  • TypeScript 5 throughout
  • Node.js + Express.js for the API
  • Next.js + React for admin console
  • PostgreSQL for data persistence
  • Railway-ready deployment

Project Status

Cerberus IAM is under active development. Core authentication, authorization, and user management features are functional and tested. The platform is suitable for development and evaluation but should undergo security review before production deployment.

Currently Available:

  • Multi-tenant user directory with RBAC
  • Email/password authentication
  • Session management with secure cookies
  • OAuth2/OIDC provider (authorization code + PKCE)
  • Admin console for user/team/client management
  • API key authentication
  • PostgreSQL with migrations
  • Comprehensive test suites

In Development:

  • User-facing authentication portal
  • Multi-factor authentication (TOTP)
  • Social login providers (Google, GitHub)
  • Webhook notifications
  • Advanced RBAC policy engine

Getting Started

Explore our repositories to get started:

  • api — Core IAM API and OAuth2/OIDC provider
  • app — Admin console web application
  • web — User-facing authentication portal

Each repository contains detailed setup instructions, documentation, and examples.

Community

We welcome contributions, feedback, and collaboration!

  • Documentation: Visit our comprehensive docs for API references, architecture guides, and deployment instructions
  • Issues: Report bugs and request features in the respective repository
  • Security: See SECURITY.md in each repository for responsible disclosure
  • Code of Conduct: We maintain a welcoming, inclusive community — see CODE_OF_CONDUCT.md

Philosophy

Secure identity should be attainable for every product team. Cerberus IAM is built with the belief that identity infrastructure should be:

  • Secure by default — Best practices baked in, not bolted on
  • Standards-compliant — OAuth 2.1, OIDC, and industry standards
  • Developer-friendly — TypeScript, great docs, and excellent DX
  • Production-ready — Multi-tenant, scalable, and observable

Built with ❤️ by Jerome Thayananthajothy

Popular repositories Loading

  1. laravel-sdk laravel-sdkPublic

    🛡️ Cerberus IAM Laravel Integration Package (PHP)

    PHP 1

  2. .github .githubPublic

    🛡️ Shared configuration and profile for the Cerberus IAM organization

Repositories

Showing 2 of 2 repositories

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
@cerberus-iam

Cerberus IAM

🛡️ Multi-tenant identity and access management: directory, local auth, OIDC, RBAC, admin console, and developer tooling for secure SaaS platforms.

Cerberus IAM

Enterprise-grade Identity and Access Management for modern SaaS applications.

Cerberus IAM delivers the complete identity infrastructure your product needs without building it from scratch. We provide secure authentication, fine-grained authorization, multi-tenant user directories, and standards-compliant OAuth 2.1/OpenID Connect—all built with TypeScript and designed for production.

What We're Building

Identity and access management shouldn't be something every team has to build from the ground up. Cerberus IAM gives you the foundational identity layer so you can focus on your product.

Core Capabilities

Authentication

  • Email/password authentication with Argon2id hashing
  • Session management with secure cookies and refresh token rotation
  • Password reset and email verification flows
  • Device and session controls with reuse detection
  • Multi-factor authentication (TOTP) — in development

User Directory

  • Multi-tenant organizations with complete data isolation
  • Users, teams, roles, and hierarchical permissions
  • Team-based grouping and access control
  • Comprehensive audit logs for compliance
  • Built on PostgreSQL with Prisma ORM

OAuth 2.1 & OpenID Connect

  • Full authorization server implementation
  • Authorization code flow with PKCE
  • Discovery, JWKS, token, userinfo, introspection, and revocation endpoints
  • Standards-compliant responses (RFC 6749, RFC 7662, RFC 7009, RFC 7517)
  • OAuth2 client management with secret rotation

Authorization

  • Role-Based Access Control (RBAC) with fine-grained permissions
  • Organization-level and team-level isolation
  • Permission wildcards for flexible policy definitions
  • Effective permission computation for policy enforcement
  • API key authentication for programmatic access

Admin Console

  • Web-based admin interface for tenant operators
  • User, team, and role management
  • OAuth2 client administration
  • Session monitoring and control
  • Audit log browsing
  • Modern UI with dark mode support

Developer Experience

  • TypeScript-first with comprehensive types
  • RESTful API with OpenAPI documentation
  • Zod schema validation
  • Result pattern for error handling
  • Extensive test coverage (unit, integration, e2e)

Why Cerberus IAM?

Security by Default

  • Argon2id password hashing
  • CSRF protection and rate limiting
  • HTTP-only secure cookies
  • Helmet.js security headers
  • Encrypted secret storage
  • Comprehensive audit trails

Standards Compliant

  • OAuth 2.1 authorization server
  • OpenID Connect 1.0 identity provider
  • PKCE required by default
  • Industry-standard token formats and flows

Production Ready

  • Multi-tenant architecture with tenant isolation
  • Structured logging with Pino
  • OpenTelemetry readiness
  • Docker containerization
  • Database migrations with Prisma
  • Comprehensive test suites

Modern Stack

  • TypeScript 5 throughout
  • Node.js + Express.js for the API
  • Next.js + React for admin console
  • PostgreSQL for data persistence
  • Railway-ready deployment

Project Status

Cerberus IAM is under active development. Core authentication, authorization, and user management features are functional and tested. The platform is suitable for development and evaluation but should undergo security review before production deployment.

Currently Available:

  • Multi-tenant user directory with RBAC
  • Email/password authentication
  • Session management with secure cookies
  • OAuth2/OIDC provider (authorization code + PKCE)
  • Admin console for user/team/client management
  • API key authentication
  • PostgreSQL with migrations
  • Comprehensive test suites

In Development:

  • User-facing authentication portal
  • Multi-factor authentication (TOTP)
  • Social login providers (Google, GitHub)
  • Webhook notifications
  • Advanced RBAC policy engine

Getting Started

Explore our repositories to get started:

  • api — Core IAM API and OAuth2/OIDC provider
  • app — Admin console web application
  • web — User-facing authentication portal

Each repository contains detailed setup instructions, documentation, and examples.

Community

We welcome contributions, feedback, and collaboration!

  • Documentation: Visit our comprehensive docs for API references, architecture guides, and deployment instructions
  • Issues: Report bugs and request features in the respective repository
  • Security: See SECURITY.md in each repository for responsible disclosure
  • Code of Conduct: We maintain a welcoming, inclusive community — see CODE_OF_CONDUCT.md

Philosophy

Secure identity should be attainable for every product team. Cerberus IAM is built with the belief that identity infrastructure should be:

  • Secure by default — Best practices baked in, not bolted on
  • Standards-compliant — OAuth 2.1, OIDC, and industry standards
  • Developer-friendly — TypeScript, great docs, and excellent DX
  • Production-ready — Multi-tenant, scalable, and observable

Built with ❤️ by Jerome Thayananthajothy

Popular repositories Loading

  1. laravel-sdk laravel-sdkPublic

    🛡️ Cerberus IAM Laravel Integration Package (PHP)

    PHP 1

  2. .github .githubPublic

    🛡️ Shared configuration and profile for the Cerberus IAM organization

Repositories

Showing 2 of 2 repositories

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
@cerberus-iam

Cerberus IAM

🛡️ Multi-tenant identity and access management: directory, local auth, OIDC, RBAC, admin console, and developer tooling for secure SaaS platforms.

Cerberus IAM

Enterprise-grade Identity and Access Management for modern SaaS applications.

Cerberus IAM delivers the complete identity infrastructure your product needs without building it from scratch. We provide secure authentication, fine-grained authorization, multi-tenant user directories, and standards-compliant OAuth 2.1/OpenID Connect—all built with TypeScript and designed for production.

What We're Building

Identity and access management shouldn't be something every team has to build from the ground up. Cerberus IAM gives you the foundational identity layer so you can focus on your product.

Core Capabilities

Authentication

  • Email/password authentication with Argon2id hashing
  • Session management with secure cookies and refresh token rotation
  • Password reset and email verification flows
  • Device and session controls with reuse detection
  • Multi-factor authentication (TOTP) — in development

User Directory

  • Multi-tenant organizations with complete data isolation
  • Users, teams, roles, and hierarchical permissions
  • Team-based grouping and access control
  • Comprehensive audit logs for compliance
  • Built on PostgreSQL with Prisma ORM

OAuth 2.1 & OpenID Connect

  • Full authorization server implementation
  • Authorization code flow with PKCE
  • Discovery, JWKS, token, userinfo, introspection, and revocation endpoints
  • Standards-compliant responses (RFC 6749, RFC 7662, RFC 7009, RFC 7517)
  • OAuth2 client management with secret rotation

Authorization

  • Role-Based Access Control (RBAC) with fine-grained permissions
  • Organization-level and team-level isolation
  • Permission wildcards for flexible policy definitions
  • Effective permission computation for policy enforcement
  • API key authentication for programmatic access

Admin Console

  • Web-based admin interface for tenant operators
  • User, team, and role management
  • OAuth2 client administration
  • Session monitoring and control
  • Audit log browsing
  • Modern UI with dark mode support

Developer Experience

  • TypeScript-first with comprehensive types
  • RESTful API with OpenAPI documentation
  • Zod schema validation
  • Result pattern for error handling
  • Extensive test coverage (unit, integration, e2e)

Why Cerberus IAM?

Security by Default

  • Argon2id password hashing
  • CSRF protection and rate limiting
  • HTTP-only secure cookies
  • Helmet.js security headers
  • Encrypted secret storage
  • Comprehensive audit trails

Standards Compliant

  • OAuth 2.1 authorization server
  • OpenID Connect 1.0 identity provider
  • PKCE required by default
  • Industry-standard token formats and flows

Production Ready

  • Multi-tenant architecture with tenant isolation
  • Structured logging with Pino
  • OpenTelemetry readiness
  • Docker containerization
  • Database migrations with Prisma
  • Comprehensive test suites

Modern Stack

  • TypeScript 5 throughout
  • Node.js + Express.js for the API
  • Next.js + React for admin console
  • PostgreSQL for data persistence
  • Railway-ready deployment

Project Status

Cerberus IAM is under active development. Core authentication, authorization, and user management features are functional and tested. The platform is suitable for development and evaluation but should undergo security review before production deployment.

Currently Available:

  • Multi-tenant user directory with RBAC
  • Email/password authentication
  • Session management with secure cookies
  • OAuth2/OIDC provider (authorization code + PKCE)
  • Admin console for user/team/client management
  • API key authentication
  • PostgreSQL with migrations
  • Comprehensive test suites

In Development:

  • User-facing authentication portal
  • Multi-factor authentication (TOTP)
  • Social login providers (Google, GitHub)
  • Webhook notifications
  • Advanced RBAC policy engine

Getting Started

Explore our repositories to get started:

  • api — Core IAM API and OAuth2/OIDC provider
  • app — Admin console web application
  • web — User-facing authentication portal

Each repository contains detailed setup instructions, documentation, and examples.

Community

We welcome contributions, feedback, and collaboration!

  • Documentation: Visit our comprehensive docs for API references, architecture guides, and deployment instructions
  • Issues: Report bugs and request features in the respective repository
  • Security: See SECURITY.md in each repository for responsible disclosure
  • Code of Conduct: We maintain a welcoming, inclusive community — see CODE_OF_CONDUCT.md

Philosophy

Secure identity should be attainable for every product team. Cerberus IAM is built with the belief that identity infrastructure should be:

  • Secure by default — Best practices baked in, not bolted on
  • Standards-compliant — OAuth 2.1, OIDC, and industry standards
  • Developer-friendly — TypeScript, great docs, and excellent DX
  • Production-ready — Multi-tenant, scalable, and observable

Built with ❤️ by Jerome Thayananthajothy

Popular repositories Loading

  1. laravel-sdk laravel-sdkPublic

    🛡️ Cerberus IAM Laravel Integration Package (PHP)

    PHP 1

  2. .github .githubPublic

    🛡️ Shared configuration and profile for the Cerberus IAM organization

Repositories

Showing 2 of 2 repositories

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
@cerberus-iam

Cerberus IAM

🛡️ Multi-tenant identity and access management: directory, local auth, OIDC, RBAC, admin console, and developer tooling for secure SaaS platforms.

Cerberus IAM

Enterprise-grade Identity and Access Management for modern SaaS applications.

Cerberus IAM delivers the complete identity infrastructure your product needs without building it from scratch. We provide secure authentication, fine-grained authorization, multi-tenant user directories, and standards-compliant OAuth 2.1/OpenID Connect—all built with TypeScript and designed for production.

What We're Building

Identity and access management shouldn't be something every team has to build from the ground up. Cerberus IAM gives you the foundational identity layer so you can focus on your product.

Core Capabilities

Authentication

  • Email/password authentication with Argon2id hashing
  • Session management with secure cookies and refresh token rotation
  • Password reset and email verification flows
  • Device and session controls with reuse detection
  • Multi-factor authentication (TOTP) — in development

User Directory

  • Multi-tenant organizations with complete data isolation
  • Users, teams, roles, and hierarchical permissions
  • Team-based grouping and access control
  • Comprehensive audit logs for compliance
  • Built on PostgreSQL with Prisma ORM

OAuth 2.1 & OpenID Connect

  • Full authorization server implementation
  • Authorization code flow with PKCE
  • Discovery, JWKS, token, userinfo, introspection, and revocation endpoints
  • Standards-compliant responses (RFC 6749, RFC 7662, RFC 7009, RFC 7517)
  • OAuth2 client management with secret rotation

Authorization

  • Role-Based Access Control (RBAC) with fine-grained permissions
  • Organization-level and team-level isolation
  • Permission wildcards for flexible policy definitions
  • Effective permission computation for policy enforcement
  • API key authentication for programmatic access

Admin Console

  • Web-based admin interface for tenant operators
  • User, team, and role management
  • OAuth2 client administration
  • Session monitoring and control
  • Audit log browsing
  • Modern UI with dark mode support

Developer Experience

  • TypeScript-first with comprehensive types
  • RESTful API with OpenAPI documentation
  • Zod schema validation
  • Result pattern for error handling
  • Extensive test coverage (unit, integration, e2e)

Why Cerberus IAM?

Security by Default

  • Argon2id password hashing
  • CSRF protection and rate limiting
  • HTTP-only secure cookies
  • Helmet.js security headers
  • Encrypted secret storage
  • Comprehensive audit trails

Standards Compliant

  • OAuth 2.1 authorization server
  • OpenID Connect 1.0 identity provider
  • PKCE required by default
  • Industry-standard token formats and flows

Production Ready

  • Multi-tenant architecture with tenant isolation
  • Structured logging with Pino
  • OpenTelemetry readiness
  • Docker containerization
  • Database migrations with Prisma
  • Comprehensive test suites

Modern Stack

  • TypeScript 5 throughout
  • Node.js + Express.js for the API
  • Next.js + React for admin console
  • PostgreSQL for data persistence
  • Railway-ready deployment

Project Status

Cerberus IAM is under active development. Core authentication, authorization, and user management features are functional and tested. The platform is suitable for development and evaluation but should undergo security review before production deployment.

Currently Available:

  • Multi-tenant user directory with RBAC
  • Email/password authentication
  • Session management with secure cookies
  • OAuth2/OIDC provider (authorization code + PKCE)
  • Admin console for user/team/client management
  • API key authentication
  • PostgreSQL with migrations
  • Comprehensive test suites

In Development:

  • User-facing authentication portal
  • Multi-factor authentication (TOTP)
  • Social login providers (Google, GitHub)
  • Webhook notifications
  • Advanced RBAC policy engine

Getting Started

Explore our repositories to get started:

  • api — Core IAM API and OAuth2/OIDC provider
  • app — Admin console web application
  • web — User-facing authentication portal

Each repository contains detailed setup instructions, documentation, and examples.

Community

We welcome contributions, feedback, and collaboration!

  • Documentation: Visit our comprehensive docs for API references, architecture guides, and deployment instructions
  • Issues: Report bugs and request features in the respective repository
  • Security: See SECURITY.md in each repository for responsible disclosure
  • Code of Conduct: We maintain a welcoming, inclusive community — see CODE_OF_CONDUCT.md

Philosophy

Secure identity should be attainable for every product team. Cerberus IAM is built with the belief that identity infrastructure should be:

  • Secure by default — Best practices baked in, not bolted on
  • Standards-compliant — OAuth 2.1, OIDC, and industry standards
  • Developer-friendly — TypeScript, great docs, and excellent DX
  • Production-ready — Multi-tenant, scalable, and observable

Built with ❤️ by Jerome Thayananthajothy

Popular repositories Loading

  1. laravel-sdk laravel-sdkPublic

    🛡️ Cerberus IAM Laravel Integration Package (PHP)

    PHP 1

  2. .github .githubPublic

    🛡️ Shared configuration and profile for the Cerberus IAM organization

Repositories

Showing 2 of 2 repositories

Top languages

Loading…

Most used topics

Loading…

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
@cerberus-iam

Cerberus IAM

🛡️ Multi-tenant identity and access management: directory, local auth, OIDC, RBAC, admin console, and developer tooling for secure SaaS platforms.

Cerberus IAM

Enterprise-grade Identity and Access Management for modern SaaS applications.

Cerberus IAM delivers the complete identity infrastructure your product needs without building it from scratch. We provide secure authentication, fine-grained authorization, multi-tenant user directories, and standards-compliant OAuth 2.1/OpenID Connect—all built with TypeScript and designed for production.

What We're Building

Identity and access management shouldn't be something every team has to build from the ground up. Cerberus IAM gives you the foundational identity layer so you can focus on your product.

Core Capabilities

Authentication

  • Email/password authentication with Argon2id hashing
  • Session management with secure cookies and refresh token rotation
  • Password reset and email verification flows
  • Device and session controls with reuse detection
  • Multi-factor authentication (TOTP) — in development

User Directory

  • Multi-tenant organizations with complete data isolation
  • Users, teams, roles, and hierarchical permissions
  • Team-based grouping and access control
  • Comprehensive audit logs for compliance
  • Built on PostgreSQL with Prisma ORM

OAuth 2.1 & OpenID Connect

  • Full authorization server implementation
  • Authorization code flow with PKCE
  • Discovery, JWKS, token, userinfo, introspection, and revocation endpoints
  • Standards-compliant responses (RFC 6749, RFC 7662, RFC 7009, RFC 7517)
  • OAuth2 client management with secret rotation

Authorization

  • Role-Based Access Control (RBAC) with fine-grained permissions
  • Organization-level and team-level isolation
  • Permission wildcards for flexible policy definitions
  • Effective permission computation for policy enforcement
  • API key authentication for programmatic access

Admin Console

  • Web-based admin interface for tenant operators
  • User, team, and role management
  • OAuth2 client administration
  • Session monitoring and control
  • Audit log browsing
  • Modern UI with dark mode support

Developer Experience

  • TypeScript-first with comprehensive types
  • RESTful API with OpenAPI documentation
  • Zod schema validation
  • Result pattern for error handling
  • Extensive test coverage (unit, integration, e2e)

Why Cerberus IAM?

Security by Default

  • Argon2id password hashing
  • CSRF protection and rate limiting
  • HTTP-only secure cookies
  • Helmet.js security headers
  • Encrypted secret storage
  • Comprehensive audit trails

Standards Compliant

  • OAuth 2.1 authorization server
  • OpenID Connect 1.0 identity provider
  • PKCE required by default
  • Industry-standard token formats and flows

Production Ready

  • Multi-tenant architecture with tenant isolation
  • Structured logging with Pino
  • OpenTelemetry readiness
  • Docker containerization
  • Database migrations with Prisma
  • Comprehensive test suites

Modern Stack

  • TypeScript 5 throughout
  • Node.js + Express.js for the API
  • Next.js + React for admin console
  • PostgreSQL for data persistence
  • Railway-ready deployment

Project Status

Cerberus IAM is under active development. Core authentication, authorization, and user management features are functional and tested. The platform is suitable for development and evaluation but should undergo security review before production deployment.

Currently Available:

  • Multi-tenant user directory with RBAC
  • Email/password authentication
  • Session management with secure cookies
  • OAuth2/OIDC provider (authorization code + PKCE)
  • Admin console for user/team/client management
  • API key authentication
  • PostgreSQL with migrations
  • Comprehensive test suites

In Development:

  • User-facing authentication portal
  • Multi-factor authentication (TOTP)
  • Social login providers (Google, GitHub)
  • Webhook notifications
  • Advanced RBAC policy engine

Getting Started

Explore our repositories to get started:

  • api — Core IAM API and OAuth2/OIDC provider
  • app — Admin console web application
  • web — User-facing authentication portal

Each repository contains detailed setup instructions, documentation, and examples.

Community

We welcome contributions, feedback, and collaboration!

  • Documentation: Visit our comprehensive docs for API references, architecture guides, and deployment instructions
  • Issues: Report bugs and request features in the respective repository
  • Security: See SECURITY.md in each repository for responsible disclosure
  • Code of Conduct: We maintain a welcoming, inclusive community — see CODE_OF_CONDUCT.md

Philosophy

Secure identity should be attainable for every product team. Cerberus IAM is built with the belief that identity infrastructure should be:

  • Secure by default — Best practices baked in, not bolted on
  • Standards-compliant — OAuth 2.1, OIDC, and industry standards
  • Developer-friendly — TypeScript, great docs, and excellent DX
  • Production-ready — Multi-tenant, scalable, and observable

Built with ❤️ by Jerome Thayananthajothy

Popular repositories Loading

  1. laravel-sdk laravel-sdkPublic

    🛡️ Cerberus IAM Laravel Integration Package (PHP)

    PHP 1

  2. .github .githubPublic

    🛡️ Shared configuration and profile for the Cerberus IAM organization

Repositories

Showing 2 of 2 repositories

Top languages

Loading…

Most used topics

Loading…