← All BaaS products
OAuth 2.0 / OIDC

Identity.Server

Kanject.Identity.Server

A standards-compliant OAuth 2.0 and OpenID Connect server, built from the ground up — your own identity provider, deployed natively on AWS.

CLIENT REGISTRATION
Client ID
Grant types
authorization_coderefresh_tokenclient_credentials
Scopes
openidprofilewallet.read
GET/.well-known/openid-configuration200
POST/token200
POST/introspect200 · active
6
CAPABILITIES
AWS
YOUR ACCOUNT
.NET
NATIVE C#
DOCKER NATIVE

A full auth backend, built from scratch — 100% AWS-compatible.

01

OAuth 2.0 flows

Authorization Code, PKCE, Client Credentials, Device Code.

02

OIDC discovery

Full .well-known/openid-configuration endpoint.

03

Client management

Admin UI for apps, secrets, redirect URIs, scopes.

04

Token introspection

RFC 7662 endpoint for resource servers.

05

Federation

Delegate to upstream IdPs (Azure AD, Okta, etc.).

06

Consent screens

Customizable, brandable user consent experience.

Docker native

Built in .NET.
Spoken in every language.

Every Identity.Server module ships as both a NuGet package and an official Docker image — runs on ECS, EKS, Fargate, App Runner, or your laptop. Call its HTTP/gRPC API from Python, Go, Node, Java, Rust, or anything else that speaks the wire.

  • Multi-arch images: amd64 + arm64 from the same tag
  • OpenAPI + gRPC reflection enabled out of the box
  • Same configuration surface — env vars, Parameter Store, file
$ docker pull kanject/identity.server:latest
One NuGet install. Zero glue code.

Kanject.Identity.Server ships into your AWS, registers itself with one line in Program.cs, and exposes a typed API the rest of your service can use immediately.

Read the deployment guide →
Ready to ship?

Simplify your cloud
journey today.

Join forward-thinking developers and businesses who trust Kanject to eliminate cloud complexity and accelerate innovation.