FerrisKey is an open-source, cloud-native Identity & Access Management platform designed for Kubernetes, multi-tenancy, and modern security architectures.
Why now
Wiring identity into a modern stack means stitching together password storage, MFA, OIDC, sessions, audit, federation, and policy across fragmented systems, with no unified audit trail and no consistent policy. FerrisKey unifies everything behind one Rust-native service.
Built in-house
Keycloak + extensions
Auth0 (SaaS)
With FerrisKey
Why FerrisKey
Identity & Access Management is the backbone of any secure platform. It controls who can authenticate, what they are authorized to do, and how every access event is tracked across every service, team, and environment in your infrastructure.
Without a solid IAM foundation, teams end up with fragmented auth logic scattered across services, no unified audit trail, and security gaps that grow with every new product. FerrisKey addresses this with a unified, operator-first approach designed for distributed systems from day one.
Give every user one identity across every application, service, and team. Standards-based federation means your engineers stop reinventing password storage and login screens for every new product.
Run one platform for every customer. Each organization gets its own isolated realm, its own admins, and its own branded login page, all without spinning up a single extra instance.
Define exactly who can do what, down to the resource. Role-based permissions and enforced multi-factor authentication keep every organization secure by default, not by configuration.
Every login, token, and policy change becomes a structured event, streamed in real time and kept in a tamper-evident trail. Compliance becomes a side effect, not a separate project.
Compare
Quick, factual comparison with the IAM tools teams reach for first. Same protocols on the surface, very different shapes underneath.
| Criteria | FerrisKey | Keycloak | Auth0 | Authentik | Ory |
|---|---|---|---|---|---|
| Runtime | Rust | Java / JVM | SaaS only | Python | Go |
| Memory footprint | ~10 MB | ~500 MB | N/A | ~200 MB | ~80 MB / svc |
| Cold start | < 1 s | 10-30 s | N/A | ~5 s | ~2 s |
| Modular architecture | Yes | SPI extensions | No | No | Split services |
| AuthZen-ready | planned | No | No | No | Keto ReBAC |
| License | Apache 2.0 | Apache 2.0 | Commercial | MIT | Apache 2.0 |
| Self-hosted | Yes | Yes | No | Yes | Yes |
| Multi-tenancy | Realms | Realms | Tenants | Brands | Projects |
| Kubernetes operator | Yes | Yes | No | partial | helm only |
Live
Sign-ins, MFA challenges, token issuance, role changes, federation events: FerrisKey writes them all to one structured stream. Tail it, ship it to your SIEM, or replay it.
Interface
A clean admin UI to manage your realms, clients, users and permissions, without getting lost.
Modules
Purpose-built systems for authentication, audit, federation, and more. Each module owns one specific aspect of identity, so you can compose, extend, or ship it on its own.
From passwordless auth to enterprise federation, the primitives are there, composable by design.
Open source
Public release notes, a public roadmap, and public contributors. Nothing about how Ferriskey grows happens behind closed doors.
No lock-in, no black boxes. Audit the code, contribute, or fork it: Ferriskey belongs to the community.
Sponsoring
Our financial partners fund full-time development, infrastructure, and the long-term roadmap. That's what keeps Ferriskey independent and moving fast.
Supporters
Schools, studios and programs that back Ferriskey with credits, infrastructure, and time.
Blog
Stay up to date with the latest news and updates.
Ready when you are
Self-hosted, Apache 2.0, built in Rust. Deploy Ferriskey in minutes and own your authentication stack outright, with no vendor holding the keys.