Janssen Project
Digital IdentityThe Janssen Project is an open-source identity and access management server providing OAuth 2.0, OpenID Connect, SAML, FIDO2/WebAuthn and SCIM, with low-code flow orchestration (Agama) and a policy engine (Cedarling). Governed by the Linux Foundation and built on the Gluu Server heritage, it is a certified, standards-complete identity building block.
- DPG Profile: https://www.digitalpublicgoods.net/r/janssen-project
- Website: https://docs.jans.io
- Source code: https://github.com/JanssenProject/jans
All DPGs in the DPGs for DPI Collection are assessed by the DPGA Secretariat against the DPGs for DPI criteria v2.0. Assessments use publicly available documentation and link to their evidence below. Assessed September 2026.
18 of 18 checks met
Layer 1
Recognised DPG
Layer 2
DPI Relevance
Layer 3
DPI Architecture Alignment
Layer 1 Recognised Digital Public Good
Listed in the DPG Registry.
Layer 2 DPI Relevance
Does it provide a foundational DPI function, reusable across sectors, at population scale?
It provides authentication, authorisation and single sign-on, spanning the Digital Identity and Trust Infrastructure domains. Identity infrastructure of this kind is usable by any sector — health, finance, government, enterprise — and the Kubernetes-native design with auto-scaling targets enterprise and national scale.
- Documentation: https://docs.jans.io/v1.11.0/
- Source code: https://github.com/JanssenProject/jans
- Security best practices: https://docs.jans.io/head/janssen-server/planning/security-best-practices/
Layer 3 DPI Architecture Alignment
How the solution's architecture reflects the principles that distinguish DPI from conventional digitisation.
A · Interoperability
3/3Can other systems connect without modifying the core, using documented open standards?
A full REST API with OpenAPI documentation covers every endpoint, alongside standards-defined discovery endpoints. The project implements the full identity standards suite — OAuth 2.0, certified OpenID Connect, SAML 2.0, FIDO2, SCIM and UMA 2.0 — exchanging JSON in standard JWT, JWK, JWE and SCIM formats.
- Documentation & API: https://docs.jans.io/v1.11.0/
- OpenID features: https://docs.jans.io/head/janssen-server/auth-server/openid-features/
- Token formats: https://docs.jans.io/head/janssen-server/auth-server/tokens/oauth-access-tokens/
B · Minimalist & Reusable Design
3/3Is it a modular building block that does one thing well, rather than a monolithic platform?
The Auth Server, Agama orchestration and Cedarling policy engine are independent components. Janssen is the identity infrastructure and relying-party applications sit on top of it; Agama's low-code orchestration lets a country build its own authentication flows without modifying the core.
- Source code & architecture: https://github.com/JanssenProject/jans
- Documentation: https://docs.jans.io/v1.11.0/
C · Ecosystem Enablement
3/3Can other public and private actors build on top of it?
Because it is standards-based, any OIDC or OAuth relying party can integrate without coordination, and Agama scripts support custom flows. Enterprise deployments worldwide date from its Gluu Server heritage, and Apache 2.0 licensing under Linux Foundation governance removes single-vendor dependency.
- Documentation: https://docs.jans.io/v1.11.0/
- Source code (Apache 2.0): https://github.com/JanssenProject/jans
D · Federation Readiness
3/3Can it run in distributed or federated deployments suited to national infrastructure?
Kubernetes-native, cloud-agnostic and multi-cluster capable, with service mesh compatibility. Self-hosting on any cloud or on premise leaves data fully under the deployer's control, and auto-scaling and service mesh support give high availability by design.
- Security best practices & deployment: https://docs.jans.io/head/janssen-server/planning/security-best-practices/
E · Security & Privacy at Scale
3/3Does it meet the security and privacy bar for population-scale infrastructure?
Security covers brute-force protection, account lockout, encryption, detailed audit logging and security event monitoring, with security best practices published and regular patch releases through GitHub security advisories. Consent management via UMA 2.0, data minimisation through claims and per-jurisdiction configuration give privacy by design.
- Security best practices: https://docs.jans.io/head/janssen-server/planning/security-best-practices/
Criteria: DPGs for DPI Collection criteria v2.0 · Co-stewarded by CDPI, Co-Develop and the DPGA Secretariat.
Spot something out of date? Contact the DPGA