finds.dev← search

// the find

apereo/cas

★ 11,380 · Java · Apache-2.0 · updated Sep 2026

Apereo CAS - Identity & Single Sign On for all earthlings and beyond.

CAS is a Java-based enterprise SSO and identity provider that speaks nearly every auth protocol you can name — SAML, OAuth2, OIDC, WS-Fed, plus its own CAS protocol. It's aimed at large organizations (universities, government, big enterprise) that need one identity gateway in front of dozens of internal apps with wildly different auth requirements.

Protocol breadth is genuinely built-in, not bolted on: SAML2, OAuth2, OIDC, and WS-Federation all live in the same codebase with shared session/ticket infrastructure. Nearly every backend integration (LDAP, JPA, MongoDB, Redis, DynamoDB, Hazelcast) is swappable via configuration rather than forking code. It's been in production at large institutions for two decades, so the edge cases in SSO ticket handling and clustering are genuinely worked out. CI is serious — native-image tests, performance and functional test workflows, Develocity build scans, codecov — for a project this size that actually matters.

Deployment is still WAR-overlay based, which is a dated pattern most Java devs under 35 have never touched; expect a real onboarding tax before you write your first line of config. The configuration surface is enormous (CasConfigurationProperties.java alone backs a dedicated configuration-model module) — finding the three properties you actually need among thousands is a genuine chore, not just a documentation gap. It's Spring Boot/Spring Cloud coupled and Java-only, so the runtime footprint and JVM startup cost rule it out for anything lightweight. The contributing guide's stance that 'the pull request IS the issue' with no separate issue tracking is unusual and makes it harder to gauge open problems before committing to adopt it.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →