Roadmap

Where Ferriskey is going next.

A directional view of what is being worked on now, what is coming next, and which longer-term bets matter most.

Current capabilities (10)
Next steps (11)
Long term (6)

Current capabilities

What Ferriskey already provides today across IAM, deployment, security, and operations.

Realms and IAM objects

available

Manage realms, clients, users, roles, organizations, client scopes, and protocol mappers from the IAM surface.

#851

Identity federation

available

Act as an OIDC and SAML 2.0 identity provider, and federate with OIDC, LDAP, and social identity providers.

#1260

Authentication methods

available

Cover Magic Link, Passkeys, reset password, TOTP, and the password, client credentials, refresh token, and Token Exchange (RFC 8693) grant types.

#1050

Sessions and SSO

available

Keep a login alive across applications with SSO sessions, and list or revoke active sessions through the session management API.

#1143

Account security

available

Lock accounts after repeated failed logins, and let users manage their own password, TOTP, and passkeys.

#1479

Mail and token controls

available

Configure mail templates, token lifetimes, and authentication-related communication flows.

Cloud-native deployment

available

Ship with Helm, Docker, and Kubernetes support, plus a maintenance mode for planned downtime.

#927

Audit and debugging modules

available

Use Compass and SeaWatch to audit authentication flows, debug behavior, and inspect IAM event logs.

Events and permissions

available

Expose durable webhooks with a persistent outbox, retries, and delivery history, and bitwise permissions for fine-grained IAM administration rights.

#1332

Localized admin console

available

Store a locale per realm and per user, and serve the admin console in English, French, and Simplified Chinese.

#1351

Next steps

The next product areas being shaped to make Ferriskey more complete and easier to operate.

Server-side listings

v0.10 planned

Paginate, sort, and filter every listing on the server so large realms stay fast in the console and the API.

#1531

GDPR self-service

v0.10 planned

Give users /me endpoints, personal data export, account deletion with a grace period, and consent management.

#992

Account chooser

v0.10 planned

Let a user pick between signed-in accounts on the login page, honouring prompt=select_account and login_hint.

#671

Pooled realms

planned

Host many tenants as realms on one instance, with quotas and stronger tenant isolation semantics.

#1610

Device authorization grant

planned

Support RFC 8628 so CLIs, TVs, and devices without a browser can sign in.

#1020

Portal builder and auth flow

planned

Build a configurable portal experience and a clearer way to define authentication journeys.

Authorization service

planned

Define and specify the dedicated authorization service before turning it into a stable product surface.

Security hardening

planned

Introduce rate limiting and OAuth 2.1 compliance.

Client operations

planned

Deliver client evaluation tooling and a CLI for operators and developers.

Migration strategies

planned

Document and support migration paths from Supabase, Keycloak, Auth0, and other existing identity stacks.

Passwordless-first security

planned

Explore device trust and device binding as first-class building blocks for passwordless authentication.

Long term

Longer-horizon bets for policy, authorization, secrets, identity standards, and adaptive security.

Policy-driven auth flows

exploring

Use OPA to attach policy rules directly to authentication flow decisions.

Vault-backed secrets

exploring

Store critical material such as keys and client secrets in a Vault-backed architecture.

Authorization standards

exploring

Evaluate AuthZEN compliance and fine-grained authorization as the authorization surface matures.

MCP Server

exploring

Expose Ferriskey capabilities through an MCP server for agentic and automation-oriented workflows.

Decentralized identity

exploring

Explore DID and Verifiable Credentials for decentralized identity use cases.

Adaptive authentication

exploring

Use risk scoring to adapt authentication requirements to context and suspicious behavior.