7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

Apereo CAS

Open source

Apereo CAS is an enterprise identity provider and single sign-on server written in Java, supporting CAS, SAML2, OpenID Connect, OAuth2 and multifactor authentication.

Open-source alternative to

apereo.github.io
Apereo CAS homepage screenshot
GitHub stars
11k
Last commit
yesterday
Repository age
15 years
Version
v8.0.2
Licence
Apache-2.0
Self-hosted
Yes

About Apereo CAS

This entry covers Apereo CAS, the Central Authentication Service. CAS is both an open and well-documented authentication protocol and the primary open-source Java server implementing it, which works as a multilingual, enterprise-grade identity provider and web single sign-on solution.

Beyond its own protocol, the server supports additional authentication protocols and features, including SAML2, OpenID Connect, OAuth2, LDAP authentication and multifactor authentication, with topics also referencing FIDO and Duo Security. It is built on Spring Boot, Spring Webflow and Spring Cloud, and aims to be a comprehensive platform for authentication and authorization needs.

Apereo CAS is licensed under Apache-2.0. The recommended way to deploy it is the WAR Overlay method, and cloning the full codebase is only needed if you want to contribute. Documentation, release notes, a maintenance policy and a release schedule are published by the project. It is typically adopted by universities and other organizations that need centralized login across many applications.

Key features

  • Single sign-on for web applications
  • CAS protocol server
  • SAML2 and OpenID Connect support
  • OAuth2 and LDAP authentication
  • Multifactor authentication including FIDO
  • Spring Boot based Java server
  • WAR overlay deployment method

Good fit for

  • →Campus-wide single sign-on
  • →Central login for enterprise web apps
  • →Adding multifactor authentication to legacy apps
Built with
Java
Tags
sso
authentication
identity-provider
cas
saml
openid-connect
mfa
java
ldap

Apereo CAS: questions and answers

What is Apereo CAS used for?
Apereo CAS is an enterprise identity provider and single sign-on server written in Java, supporting CAS, SAML2, OpenID Connect, OAuth2 and multifactor authentication. It is a good fit for campus-wide single sign-on, central login for enterprise web apps and adding multifactor authentication to legacy apps.
Is Apereo CAS open source?
Yes. Apereo CAS is open source under the Apache-2.0 licence. Its source code is on GitHub at apereo/cas and is written mainly in Java.
Is Apereo CAS free?
Yes. Apereo CAS is open source, so the software itself is free to use.
Can I self-host Apereo CAS?
Yes. Apereo CAS can be self-hosted on your own server or infrastructure.
What is Apereo CAS an alternative to?
Apereo CAS is an open-source alternative to Ping Identity, OneLogin, Okta and IBM Verify. Other open-source alternatives to Ping Identity include Authentik, Keycloak and WSO2 Identity Server.
Is Apereo CAS actively maintained?
Yes. The most recent commit to Apereo CAS was on 2 October 2026, and the latest release is v8.0.2, published on 26 September 2026. The project has 11k stars on GitHub.

Open-source alternatives to Apereo CAS

See all

SaaS alternatives to Apereo CAS

See all