Casdoor v4.0 was officially released on September 1, 2026, and has since advanced to v4.3 as of September 9, 2026. Developed by the Casbin community under the Apache 2.0 license, Casdoor is an open-source identity and access management (IAM) solution built with Go for the backend and React for the frontend.
Key Highlights and Launch Details
- Release date: September 1, 2026 (v4.0)
- Current version: v4.3 (as of September 9, 2026)
- License: Apache 2.0 (open-source, free for commercial use)
- Tech stack: Backend in Go, frontend in React
- Platform: GitHub (officially listed in CNCF)
- CNCF status: Added to the CNCF Landscape on February 22, 2026, under the Security & Compliance category within the Provisioning section
Casdoor evolves from the CAS (Central Authentication Service) protocol into a modern IAM platform. The most significant change in v4 is the complete rewrite of the admin console using React, greatly enhancing interactivity and component maintainability. Additionally, v4 introduces built-in MCP Server and Agent authentication support, enabling fine-grained authorization for service-to-service calls in cloud-native microservices architectures. The MCP (Multi-Cloud Platform) Server facilitates unified authentication policy management across cloud environments, while the Agent component provides lightweight authentication integration for Sidecar or standalone proxy patterns.
Project Context and Notable Data
Casdoor originates from the well-established Casbin open-source community, inheriting Casbin’s robust policy models including RBAC and ABAC. Building upon traditional SSO capabilities, it has steadily expanded into service-level authorization. Though GitHub star counts are not disclosed in the source material, Casdoor has gained a growing GitHub following and ranks among the most active open-source IAM projects in the Chinese developer ecosystem.
A striking pattern emerges: Casdoor reached v4 approximately six months after its CNCF Landscape inclusion on February 22, 2026. Typically, projects admitted to the CNCF Landscape require extended stabilization before major releases, yet Casdoor accelerated its development pace. This contrasts with CNCF’s usual expectation of conservative iteration post-admission—most projects prioritize stability over rapid feature delivery, whereas Casdoor opted for aggressive feature rollout.
The CNCF Landscape categorizes IAM tools under Provisioning rather than Security, reflecting the shift in cloud-native thinking: identity is viewed as a “gatekeeper” preceding resource access. The emphasis lies in managing authentication workflows as infrastructure, not merely adding security features.
Feature Comparison (Based on Available Information)
| Feature | v4.x | v3.x (inferred) |
|---|---|---|
| Frontend framework | React (console rewritten) | Legacy framework (not specified) |
| Built-in MCP Server | Yes | No |
| Agent authentication | Yes | No |
| CNCF Landscape inclusion | February 22, 2026 | Not listed |
Note: v3.x features are not explicitly detailed in the source material; comparisons are reverse-engineered from new v4 capabilities.
When to Adopt
- Adopt v4 now if: You’re building or refactoring a Go-based microservices system; require unified authentication policy management across multi-cloud; or already use Casbin models and seek seamless migration to a full IAM platform.
- Consider waiting if: Your team demands extensive UI customization (the React rewrite may require theme re-implementation); you need mobile SSO support (not mentioned in the report); or you run monolithic applications with no need for MCP/Agent functionality.
Final Thoughts
Casdoor’s rapid release cycle demonstrates how open-source IAM infrastructure is transitioning from “functional” to “production-grade.” Though the React console rewrite introduces short-term migration effort, it improves long-term community maintainability. Its CNCF inclusion further signals that IAM is evolving from a security add-on to a core provisioning infrastructure component in cloud-native environments.
