Skip to content
OIDC Server · License

Free for most, paid when your business grows

OIDC Server is distributed with its source code open on GitHub - you can read and audit it without contacting us, follow the development of new versions, open issues, raise concerns and suggest ideas for the library. The practical benefit is transparency: you can verify every line instead of trusting a black box. This page explains in plain language who can use the library for free, when a paid license is required and what the license does not allow.

Some packages are under an open license (Apache-2.0)

This agreement does not cover them: no purchase, no thresholds, nothing on this page applies. The Apache-2.0 terms cover them completely.

  • Abblix.SecurityEvents with the CAEP and RISC vocabularies and its Minimal API adapter - Security Event Tokens, the receiving side of their delivery, and the receiving half of Back-Channel Logout
  • Abblix.JWT, the JWT and JWE engine, together with the utility packages it rests on

An application that only needs to be told when a session ended elsewhere takes these and nothing else, whoever its identity provider is. The Shared Signals layer - Abblix.SharedSignals with its adapter and its Redis storage - is licensed by this agreement, as is the OpenID Provider itself.

Free of charge

This applies to:

  • Companies with under $1M in annual revenue and under $1M raised in outside funding (investment, grants, sale of a stake)
  • Non-profits, educational institutions and personal projects - whatever their size; open-source projects, as long as the project itself is non-commercial
  • Deployments in development, test and staging environments - for everyone, at any size

A paid license is required

Once the business passes the free thresholds:

  • Commercial production use by a company above either threshold - revenue or funds raised
  • Guaranteed support response: 3 business days on Pro; on Enterprise - 1 business day plus a priority bug-fix queue
  • Several independent production entry points (issuers) - Enterprise only

What you may not do

On any tier, paid or free, for the components this agreement covers - everything except the Apache-2.0 packages above:

  • Publishing it as your own product or removing the license terms
  • Building wrappers and reselling it to third parties as an authentication service
  • Using the source code, in whole or in part, to develop competing products of your own

True on every tier

All supported protocols and OpenID profiles available, nothing switched off
Unlimited client applications and users
Any number of servers behind one entry point
Certification and feature completeness are never restricted

Shipping it inside your own product

Internal use is not redistribution: even a large company with dozens of its own applications behind a single SSO is covered by Pro or Enterprise. A separate license applies when the library reaches third parties inside something you sell or deploy for clients - and it is meant for products where authentication is one function among many, not the product itself. Wrapping the library and reselling it as an authentication service is not allowed.

Which text prevails
This page is a plain-language summary of the license terms. If anything differs, your signed agreement comes first, then the license text on GitHub, and only then this page.

Evaluate our products against your architecture

Want a closer look at how they fit your stack, your compliance requirements or your scale? Our engineering team will help you.