Skip to content
Abblix
OpenID Certified · OAuth 2.0 & OpenID Connect server for .NET

The identity layer your company owns end to end

OIDC Server is a certified OpenID Connect & OAuth 2.0 library for .NET - deployed inside your perimeter, on keys only you hold, with no vendor lock-in and no geopolitical risk. Built for banks, telecoms and enterprises where compliance isn't optional.

All OpenID profiles certified30+ RFCs implemented.NET 8 · 9 · 10Financial-grade ready
You're adding sign-in and want it secure and effortless
Your users move between several apps and expect to log in once
You'd rather run your own identity provider than rent one
We have been there. And we have the answer.
Why OpenID Connect

The modern standard for authentication

One login across web, mobile, Smart TV and IoT. Unlike ageing protocols like SAML or WS-Federation, OpenID Connect is the de-facto standard - broadly supported, secure and built to scale.

Modern standard, broad support

The most widely supported authentication standard, with libraries and tools on every major platform.

Compatibility

Integrates cleanly with the systems you already run, with no rip-and-replace of your current infrastructure.

Flexibility & scale

Add new domains and adapt to architecture changes without heavy cost.

Security & separation of concerns

Separates authentication from resource management, hardening the whole system against unauthorized access.

Why OIDC Server

Built for organisations that can't outsource trust

When you authenticate millions of customers under regulatory scrutiny, identity is too critical to rent. Abblix puts the standard-compliant core in your hands and leaves everything sensitive inside your walls.

Data sovereignty & compliance

You decide where data lives, how it's stored and backed up, and which data centres and regions it touches. Keeping the user base inside your infrastructure simplifies GDPR, HIPAA and local regulatory compliance - by design, not by contract.

Financial-grade security

The building blocks regulated sectors require: mutual-TLS & certificate-bound tokens, PAR, JAR, JARM, PKCE and CIBA for decoupled, backchannel authentication - ideal for banking and high-assurance flows.

No lock-in, no geopolitical risk

No dependence on a third-party cloud's availability, pricing or policy. No exposure to sanctions or cross-border service disruption. Your authentication stays fully under your control - and stays running.

Library vs. cloud or SaaS

Why a server library beats a hosted identity provider

A library runs where you run. That single difference is what makes Abblix viable for enterprises that have already invested in their own stack.

Integration flexibility

Reuse your existing user database, UI and auth factors - OTP, biometrics, hardware keys, any combination. Add OpenID Connect to what you already run.

Runs inside your application

Authentication happens in your own process - no extra network hop at login, no dependency on a third party's uptime or latency.

You control versions

You decide when to upgrade. Nothing changes in your sign-in flow on somebody else's release schedule.

Costs don't scale with users

Licensed per deployment - never per user, per token or per active account.

Why choose OIDC Server

Engineered to extend, not to constrain

Many libraries implement OpenID Connect. Few are built from the architecture up to be adapted, audited and trusted in production.

Hexagonal, framework-agnostic architecture

Ready for ASP.NET Core out of the box - controllers, model binding and routing included. Thanks to a hexagonal core, OIDC Server adapts to any current or future framework for building an OpenID Connect Web API.

Modular design & open source

Validation, request processing and response formatting are cleanly separated and wired through standard .NET dependency injection. Source is on GitHub for full transparency and third-party security audits.

Cross-platform & .NET-native

Built for .NET 8, 9 and 10. Runs on Windows and Linux, ships happily in Docker and orchestrates with Kubernetes - deployment and scaling stay simple.

Certified & secure

Certified by the OpenID Foundation across all profiles - passed every conformance test with zero remarks or warnings. Security and standards compliance are the product, not an afterthought.

In your infrastructure

One compliant core. Everything else stays yours

Abblix takes on one responsibility - strict, certified compliance with the OpenID Connect standard. Your data, keys, UI and systems remain exactly where they are.

Your existing assets
User databaseYour store of user identities
Key storageYour cryptographic key management
Logging & monitoringYour event tracking and audit trail
OIDC Server

The certified OpenID Connect & OAuth 2.0 core - connected to your systems through clean, documented ports.

PhysicalVirtualDockerKubernetes
Connected through clean ports
Frontend (UI)Your authentication forms
API & servicesYour internal & external systems
Any deploymentOn-prem, private or hybrid cloud
Use cases

Built for the flows real products need

From enterprise SSO to financial-grade and input-constrained devices - one certified core covers them all.

Enterprise SSO

One login across every web, mobile and internal application your organisation runs.

Banking & financial-grade

High-assurance flows (mTLS, PAR, JAR/JARM, CIBA) for regulated financial services.

IoT & Smart TV

Device Authorization Grant for input-constrained devices, with built-in brute-force protection.

Decoupled & backchannel

CIBA for call centres and out-of-band approval - poll, ping and push delivery modes.

Technical requirements

Runs where you already run

No exotic dependencies - deploy OIDC Server on the stack you already operate.

Platform

.NET 8.0, 9.0 and 10.0
Windows & Linux
Docker & Kubernetes

Web server

Kestrel (built into ASP.NET Core)
Behind a reverse proxy: Nginx, Apache HTTP Server
Microsoft IIS

Hardware

No special CPU or memory requirements
Scales with your operational load
OpenID Certified
Certification & assurance

Certified by the OpenID Foundation. Every profile

100% compliant with the standards - certified across all OpenID Provider profiles, including logout profiles.
Passed every conformance test flawlessly - not a single remark or warning.
Certified alongside Google, Microsoft, IBM, Okta and Auth0 - the company your security team expects.
Open source on GitHub, enabling independent third-party security audits.
All
OpenID profiles certified by the Foundation
30+
RFCs & specifications implemented in full
0
remarks or warnings in conformance testing
3
supported runtimes - .NET 8, 9 and 10

Flexible pricing for businesses of any size

From evaluation to enterprise-wide deployment - licensing that scales with you, not against you.

See pricing plans

Evaluate our products against your architecture

Want a closer look at how they fit your stack, your compliance requirements or your scale? Our engineering team will help you.