LIVE NEWS
  • Ascendant Paris to hold European-flavored Bastille Day flyover with nuclear undertones
  • Ghana flooding: At least 13 people killed in Accra after torrential rains
  • Supreme Court rulings; Iran-US talks; Murder rates : NPR
  • JPMorgan’s Kinexys Blockchain Hits $4 Trillion, Adds Five APAC Currencies
  • Insurance giant Aflac discloses data breach after subsidiary hack
  • Apptronik’s Humanoid Robots Are Practicing for Their First Real Jobs
  • Manhunt under way after bomb injures Ukrainian oligarch and family in Monaco
  • Dietitian, Nutrition Scientist’s 3 Lazy Ways to Eat More Fiber
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Artificial Intelligence»IdentityServer4 is dead. Here’s what comes next.
Artificial Intelligence

IdentityServer4 is dead. Here’s what comes next.

primereportsBy primereportsJune 30, 2026No Comments6 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
IdentityServer4 is dead. Here’s what comes next.
Share
Facebook Twitter LinkedIn Pinterest Email


Developers weren’t happy when identity and access control software company Duende commercialized its open source IdentityServer product in December 2022, while also initially deleting its supporting documentation from GitHub.

Rock Solid Knowledge (RSK), a software development company based in Bristol, UK, is a longstanding contributor to the IdentityServer community and is now dedicated to ensuring that open authentication infrastructure platform services continue to live on. 

RSK decided to fork the project and maintain an open source identity security offering with the same (but now expanded) set of authentication technologies as the original project; the new Open.IdentityServer platform was released on Tuesday. 

Open source means adoption first, not monetization first

RSK’s founder, Andrew Clymer, tells The New Stack that “free software doesn’t have to mean abandoned software” and that IdentityServer4 left behind a huge community that still deserves a future. 

“Open.IdentityServer gives those abandoned developers a modern, supported path without forcing a commercial decision on day one. Open source succeeds when adoption comes before monetization,” Clymer says. “Open.IdentityServer demonstrates you can have a professionally maintained platform that’s free forever while still building a sustainable business around commercial extensions and services. We think that’s a healthier model for everyone.”

A manifesto by RSK published this month states that Open.IdentityServer will remain free and open source. It said that commercial offerings will remain optional and will “finance the free core,” but that the open source community will “always have a voice” in the direction of the project.

“Free software doesn’t have to mean abandoned software. Open.IdentityServer gives abandoned developers a modern, supported path without forcing a commercial decision on day one. Open source succeeds when adoption comes before monetization.” —Andrew Clymer, Rock Solid Knowledge.

Based on the Apache 2.0-licensed IdentityServer4 codebase, the platform provides an OpenID Connect and OAuth 2.0 framework for .NET applications, supporting token-based authentication, single sign-on, and API access control. The first release, Open.IdentityServer v1.0.0, was published on June 1.

Why was IdentityServer4 decommissioned?

The DuendeArchive page on GitHub has stated that IdentityServer4 contains “multiple known security vulnerabilities and bugs” and has outdated documentation.

Head of customer success at Duende Software, Maarten Balliauw, blogged on his company’s own pages to confirm that IdentityServer4 went out of support when .NET Core 3.1 reached its end-of-support date, as previously stated back in December 2022.

“IdentityServer4 contains several known security vulnerabilities and bugs, while at the same time providing outdated documentation and information,” writes Balliauw in a post published in March of last year. 

According to Balliauw, the repository displayed a warning about these issues for many years alongside similar flags related to its NuGet packages (zip files containing compiled code and libraries used to share and reuse code in .NET applications). However, Duende saw that the “source code was still being cloned”, so the packages were being used by developers and put into production.

A Duende IdentityServer Community Edition with the same features as the Enterprise Edition remains available for use by individuals, not-for-profit companies with less than 1M USD projected annual gross revenue, and non-profits with less than 1M USD annual budget.

As admirable as this appears, RSK’s Clymer isn’t won over.

“This approach only works for a small number of organizations and early startups,” he says. “When your startup business starts to take off, you don’t want to get hit with a bill or face an expensive migration to another platform. Businesses need certainty, no large annual price rises. Open.IdentityServer provides this ‘for free, forever’, and that’s a pledge we’ve made in our manifesto; this is not a short-term initiative, we are here to invest in the platform, protect it and grow it.”

“A fork is only viable if a team of developers is prepared to own it for the long term… and we are.”

Going back to open source roots

RSK is buoyant about open source purity; the company says the launch of Open.IdentityServer brings the kernel of IdentityServer closer to its original open source roots. The open-source model provides organizations with a free, production-ready core that can be supplemented with optional commercial products, services, and enterprise support.

Should we take this forking of a decommissioned open-source project as an exemplar beacon to guide other scenarios of this kind, if and when they occur? Is this method now a viable long-term strategy for sustaining critical developer infrastructure in the face of proprietary lock-in?

“Absolutely, that’s what it is,” confirms Clymer. “A fork is only viable if a team of developers is prepared to own it for the long term… and we are. Open.IdentityServer isn’t a side project; it’s the foundation of our business, which gives us every incentive to keep it secure, modern, and actively maintained.”

Migration frustrations, or foundation affirmation celebrations?

But Open.IdentityServer is bright, shiny, and new, so the team is naturally bullish about ease of use and platform purity. Teams currently locked into Duende’s commercial core license or still running unsupported IdentityServer4 might think it’s not a straightforward task to migrate their existing IdentityServer deployments to Open.IdentityServer primarily because there’s not usually such a thing as a free lunch.

“We’ve catered for that consideration, fully and comprehensively,” assures Clymer. “It’s super straightforward, and our team has produced explainer videos that show how it can be done in less than 10 minutes when software engineers migrate from Duende. Open.IdentityServer schema is compatible with Duende, so there are no database migrations; just change the NuGet packages, and you are pretty much done.”

Clymer asserts that these mechanics make it “very easy to evaluate” whether this platform is right for any given deployment. For new builds, there’s a template that gets developers up and running in less than 30 minutes, with a UI for managing configuration.

In terms of open-source model pedigree, RSK is also a longstanding contributor to ecosystems such as IdentityServer, OpenIddict, and the Umbraco CMS.

Open.IdentityServer is available on GitHub, where Rock Solid Knowledge maintains the public repository and documentation and welcomes contributions from the wider community. 


Group Created with Sketch.

IdentityServer4 is dead. Here’s what comes next.

Adrian Bridgwater is a technology journalist with three decades of press experience. He has an extensive background in communications, starting in print media, newspapers and also television. Primarily working as an analysis writer dedicated to a software application development ‘beat’,…

Read more from Adrian Bridgwater



Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCost to rewire Great Britain’s electricity network could reach £90bn in 2030s | Energy industry
Next Article Starmer to set out long-delayed defence spending plans – BBC
primereports
  • Website

Related Posts

Artificial Intelligence

I always keep these 3 devices plugged into my power station – here’s why

June 30, 2026
Artificial Intelligence

HP accelerates enterprise workflows with OpenAI Frontier

June 30, 2026
Artificial Intelligence

OCRmyPDF Tutorial: Convert Scanned Documents into Searchable PDF/A Files with Sidecar Text Extraction and Batch Processing

June 29, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Paxton’s win over Cornyn sets up high-stakes Texas clash with Talarico

May 28, 202616 Views

Global Resources Outlook 2024 | UNEP

December 6, 202510 Views

Texas Democrat Talarico claims voting laws are rigged ahead of Paxton race

May 28, 20269 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Ascendant Paris to hold European-flavored Bastille Day flyover with nuclear undertones
  • Ghana flooding: At least 13 people killed in Accra after torrential rains
  • Supreme Court rulings; Iran-US talks; Murder rates : NPR
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.