A Modern IAM Built
for Distributed
Systems

FerrisKey is an open-source, cloud-native Identity & Access Management platform designed for Kubernetes, multi-tenancy, and modern security architectures.

Open source
Apache 2.0
Early Access · v0.4.2
CONSUMERS Web App Mobile App API / CLI End Users FerrisKey IAM PLATFORM Kubernetes ArgoCD Prometheus OpenTelemetry IAM as the single identity layer across your entire stack

Why FerrisKey

Identity infrastructure for cloud-native platforms, without legacy IAM complexity.

Identity & Access Management is the backbone of any secure platform. It controls who can authenticate, what they are authorized to do, and how every access event is tracked across every service, team, and environment in your infrastructure.

Without a solid IAM foundation, teams end up with fragmented auth logic scattered across services, no unified audit trail, and security gaps that grow with every new product. FerrisKey addresses this with a unified, operator-first approach designed for distributed systems from day one.

Rust-native performance

Built in Rust from the ground up — not ported or wrapped. A ~10MB binary, sub-10ms auth latency, and a predictable memory footprint that holds under sustained load.

~10MB binary <10ms latency No GC pauses Memory safe

Deploy & manage your way

FerrisKey ships with first-class tooling for every ops workflow — from local testing to production GitOps pipelines. No custom scripting required.

Helm chart Kubernetes Operator ArgoCD Docker Compose

Event-driven extensibility

Every identity event — login, token issuance, policy change, realm update — emits a structured event you can consume to trigger webhooks, sync to your data lake, or drive custom workflows without patching the core.

Webhooks Kafka / NATS (soon)

CNCF ecosystem integration

FerrisKey is designed to fit naturally into cloud-native stacks. Native integrations with the tools your platform team already runs — no adapters, no workarounds.

Prometheus OpenTelemetry OPA (soon) AuthZen

Interface

Built for clarity, designed for speed

A clean admin UI to manage your realms, clients, users and permissions — without getting lost.

Modules

Everything you need to build

Purpose-built systems for authentication, audit, federation, and more. Each module owns a specific aspect of identity — composable, extensible, and production-ready.

TOTP WebAuthn Magic Links Recovery Codes Google SSO GitHub SSO Discord SSO Custom OIDC Audit Events Event Streaming Conditional Flows Step-Up Auth JWT Claims Custom Scopes Protocol Mappers Webhooks Passkeys Token Introspection Realm Isolation PKCE TOTP WebAuthn Magic Links Recovery Codes Google SSO GitHub SSO Discord SSO Custom OIDC Audit Events Event Streaming Conditional Flows Step-Up Auth JWT Claims Custom Scopes Protocol Mappers Webhooks Passkeys Token Introspection Realm Isolation PKCE

Built for every identity scenario

From passwordless auth to enterprise federation — the primitives are there, composable by design.

Official modules, zero hunting

MFA, federation, audit, webhooks — every critical identity concern solved with a dedicated module. No glue code, no compatibility roulette.

View all modules

Team

Meet the core team

The people behind Ferriskey — building secure identity infrastructure in the open.

Nathael Bonnal

Nathael Bonnal

Co-Founder & Software Engineer

Baptiste Parmantier

Baptiste Parmantier

Co-Founder & Software Engineer

Guillaume Leroy

Guillaume Leroy

Platform Engineer

Joris Vilardell

Joris Vilardell

Software Engineer

Luis Rubiera

Luis Rubiera

CTO @ Cloud-IAM

Proudly supported by our partners

These companies and projects keep Ferriskey thriving. Their support funds development, maintenance, and community growth — allowing us to stay independent and focused on building the best IAM we can.

Become a partner

Blog

Latest articles

Stay up to date with the latest news and updates.

Who are you, and what are you doing here?
iamidentity

Who are you, and what are you doing here?

Understand IAM from scratch, and discover FerrisKey.

View all articles

Your identity layer, your rules.

Self-hosted, Apache 2.0, built in Rust. Deploy Ferriskey in minutes and own your authentication stack — no vendor, no lock-in.