Realms and IAM objects
Manage realms, clients, users, roles, organizations, client scopes, and protocol mappers from the IAM surface.
#851Roadmap
A directional view of what is being worked on now, what is coming next, and which longer-term bets matter most.
Current capabilities
What Ferriskey already provides today across IAM, deployment, security, and operations.
Manage realms, clients, users, roles, organizations, client scopes, and protocol mappers from the IAM surface.
#851Act as an OIDC and SAML 2.0 identity provider, and federate with OIDC, LDAP, and social identity providers.
#1260Cover Magic Link, Passkeys, reset password, TOTP, and the password, client credentials, refresh token, and Token Exchange (RFC 8693) grant types.
#1050Keep a login alive across applications with SSO sessions, and list or revoke active sessions through the session management API.
#1143Lock accounts after repeated failed logins, and let users manage their own password, TOTP, and passkeys.
#1479Configure mail templates, token lifetimes, and authentication-related communication flows.
Ship with Helm, Docker, and Kubernetes support, plus a maintenance mode for planned downtime.
#927Use Compass and SeaWatch to audit authentication flows, debug behavior, and inspect IAM event logs.
Expose durable webhooks with a persistent outbox, retries, and delivery history, and bitwise permissions for fine-grained IAM administration rights.
#1332Store a locale per realm and per user, and serve the admin console in English, French, and Simplified Chinese.
#1351Next steps
The next product areas being shaped to make Ferriskey more complete and easier to operate.
Paginate, sort, and filter every listing on the server so large realms stay fast in the console and the API.
#1531Give users /me endpoints, personal data export, account deletion with a grace period, and consent management.
#992Let a user pick between signed-in accounts on the login page, honouring prompt=select_account and login_hint.
#671Host many tenants as realms on one instance, with quotas and stronger tenant isolation semantics.
#1610Support RFC 8628 so CLIs, TVs, and devices without a browser can sign in.
#1020Build a configurable portal experience and a clearer way to define authentication journeys.
Define and specify the dedicated authorization service before turning it into a stable product surface.
Introduce rate limiting and OAuth 2.1 compliance.
Deliver client evaluation tooling and a CLI for operators and developers.
Document and support migration paths from Supabase, Keycloak, Auth0, and other existing identity stacks.
Explore device trust and device binding as first-class building blocks for passwordless authentication.
Long term
Longer-horizon bets for policy, authorization, secrets, identity standards, and adaptive security.
Use OPA to attach policy rules directly to authentication flow decisions.
Store critical material such as keys and client secrets in a Vault-backed architecture.
Evaluate AuthZEN compliance and fine-grained authorization as the authorization surface matures.
Expose Ferriskey capabilities through an MCP server for agentic and automation-oriented workflows.
Explore DID and Verifiable Credentials for decentralized identity use cases.
Use risk scoring to adapt authentication requirements to context and suspicious behavior.