A Modern IAM Built for Distributed Systems

FerrisKey is an open-source, cloud-native Identity & Access Management platform designed for Kubernetes, multi-tenancy, and modern security architectures.

Open source
Apache 2.0
Early Access · v0.7.1
IdP
SSO
Organizations
MFA
FerrisKey
Branding
RBAC
Audits
Webhooks

Why now

Every IAM was built for the monolith era. Cloud-native needs more.

Wiring identity into a modern stack means stitching together password storage, MFA, OIDC, sessions, audit, federation, and policy across fragmented systems, with no unified audit trail and no consistent policy. FerrisKey unifies everything behind one Rust-native service.

Compare with:

Built in-house

7+
Code paths your app owns
Auth code lives in every app Audit and policy stay scattered Full control, full ownership Long-term maintenance load

With FerrisKey

1
Service to call
One IAM service Unified audit trail Consistent policy One API to integrate

Why FerrisKey

Identity infrastructure for cloud-native platforms, without legacy IAM complexity.

Identity & Access Management is the backbone of any secure platform. It controls who can authenticate, what they are authorized to do, and how every access event is tracked across every service, team, and environment in your infrastructure.

Without a solid IAM foundation, teams end up with fragmented auth logic scattered across services, no unified audit trail, and security gaps that grow with every new product. FerrisKey addresses this with a unified, operator-first approach designed for distributed systems from day one.

Single sign-on, everywhere.

Give every user one identity across every application, service, and team. Standards-based federation means your engineers stop reinventing password storage and login screens for every new product.

Identity Federation Single Sign-On Social & Enterprise Login Passwordless

Multi-tenant by design.

Run one platform for every customer. Each organization gets its own isolated realm, its own admins, and its own branded login page, all without spinning up a single extra instance.

Isolated Organizations Custom Branding White-Label Ready Delegated Admins

Access control that scales with you.

Define exactly who can do what, down to the resource. Role-based permissions and enforced multi-factor authentication keep every organization secure by default, not by configuration.

Role-Based Access Multi-Factor Auth Fine-Grained Permissions Zero Trust Ready

Every action, accounted for.

Every login, token, and policy change becomes a structured event, streamed in real time and kept in a tamper-evident trail. Compliance becomes a side effect, not a separate project.

Full Audit Trail Real-Time Webhooks Compliance-Ready SIEM Integration

Compare

How FerrisKey stacks up against the IAM you already know.

Quick, factual comparison with the IAM tools teams reach for first. Same protocols on the surface, very different shapes underneath.

Compare vs
Criteria
FerrisKey
Keycloak
Runtime Rust Java / JVM
Memory footprint ~10 MB ~500 MB
Cold start < 1 s 10-30 s
Modular architecture Yes SPI extensions
AuthZen-ready planned No
License Apache 2.0 Apache 2.0
Self-hosted Yes Yes
Multi-tenancy Realms Realms
Kubernetes operator Yes Yes
Memory and cold-start figures are typical for a small production instance. Last reviewed May 2026.

Live

Every identity event, streamed and auditable.

Sign-ins, MFA challenges, token issuance, role changes, federation events: FerrisKey writes them all to one structured stream. Tail it, ship it to your SIEM, or replay it.

12.4k
events / sec at p50
realms watched in parallel
< 5 ms
audit write p99
  • OIDC alice@acme.com signed in via Google 12 ms
  • MFA bob@globex.com authenticated with WebAuthn 8 ms
  • TOKEN service:billing received access_token 4 ms
  • ROLE admin granted editor → carol@globex.com 11 ms
  • FED alice@acme.com linked Google identity 87 ms
  • AUDIT charlie@acme.com viewed user list 3 ms
  • WARN 3 failed logins for eve@acme.com blocked
  • PASSKEY dan@acme.com registered a passkey 145 ms
format: jsonl · ndjson → webhooks · siem · s3

Interface

Built for clarity, designed for speed

A clean admin UI to manage your realms, clients, users and permissions, without getting lost.

Modules

Everything you need to build

Purpose-built systems for authentication, audit, federation, and more. Each module owns one specific aspect of identity, so you can compose, extend, or ship it on its own.

TOTP WebAuthn Magic Links Recovery Codes Google SSO GitHub SSO Discord SSO Custom OIDC Audit Events Event Streaming Conditional Flows Step-Up Auth JWT Claims Custom Scopes Protocol Mappers Webhooks Passkeys Token Introspection Realm Isolation PKCE TOTP WebAuthn Magic Links Recovery Codes Google SSO GitHub SSO Discord SSO Custom OIDC Audit Events Event Streaming Conditional Flows Step-Up Auth JWT Claims Custom Scopes Protocol Mappers Webhooks Passkeys Token Introspection Realm Isolation PKCE

Built for every identity scenario

From passwordless auth to enterprise federation, the primitives are there, composable by design.

Official modules, zero hunting

MFA, federation, audit, webhooks: each one is a dedicated module, not a pile of glue code you end up maintaining yourself.

View all modules

Open source

Released in the open, with every change in plain sight.

Public release notes, a public roadmap, and public contributors. Nothing about how Ferriskey grows happens behind closed doors.

Team

Meet the core team

The people behind Ferriskey, building secure identity infrastructure in the open.

Nathael Bonnal

Nathael Bonnal

Co-Founder & Software Engineer

Baptiste Parmantier

Baptiste Parmantier

Co-Founder & Software Engineer

Guillaume Leroy

Guillaume Leroy

Platform Engineer

Joris Vilardell

Joris Vilardell

Software Engineer

Luis Rubiera

Luis Rubiera

CTO @ Cloud-IAM

Sponsoring

Backed by companies who share our vision

Our financial partners fund full-time development, infrastructure, and the long-term roadmap. That's what keeps Ferriskey independent and moving fast.

Become a partner

Supporters

Backed by the community

Schools, studios and programs that back Ferriskey with credits, infrastructure, and time.

Blog

Latest articles

Stay up to date with the latest news and updates.

Who are you, and what are you doing here?
iamidentity

Who are you, and what are you doing here?

Understand IAM from scratch, and discover FerrisKey.

View all articles

Ready when you are

Your identity layer, your rules.

Self-hosted, Apache 2.0, built in Rust. Deploy Ferriskey in minutes and own your authentication stack outright, with no vendor holding the keys.