// the find
OpenIdentityPlatform/OpenAM
OpenAM is an open-source access management solution for identity authentication, authorization, and federation. It provides single sign-on, adaptive authentication, and centralized policy control, enabling secure access to web, mobile, and cloud applications
OpenAM is a full-blown Java IAM server — SSO, SAML2, OAuth2/OIDC, Kerberos, NTLM, WebAuthn — forked from the open-sourced remains of Sun's OpenSSO / ForgeRock's OpenAM after ForgeRock went commercial-only. It's for enterprises that need to bolt federated auth onto a pile of legacy and modern apps without paying for Okta/Ping, not for a startup that just wants login.
Genuinely broad protocol coverage in one deployable unit — SAML2, OAuth2/OIDC, Kerberos/NTLM, and WebAuthn all live in the same server, which matters if you have to bridge an old AD-based app and a new OIDC-based one simultaneously. The pluggable module system for custom auth chains, user data stores, and post-auth logic is real extensibility, not just config flags. CI is active with actual e2e tests (Playwright specs for OAuth2, SAML, and the XUI) rather than just unit tests. Docker images and versioned releases exist, so you're not forced to build from source to evaluate it.
The codebase carries three decades of lineage — jato-shaded module, extlib jars dated 2005-2008 — and it shows in the module count and structure; this is not something you read end-to-end in an afternoon. Build still requires JDK 11+, Maven, and a Windows longpaths git config just to clone, which is friction before you've even started evaluating it. CDDL is an uncommon license that will trigger a legal review at most companies before adoption. It's a volunteer-maintained fork of a product ForgeRock abandoned to the community — the commercial support listed is third-party vendors, not the core team, so you're betting on community maintenance depth for something that sits in your auth critical path.