
The identity layer your company owns end to end
OIDC Server is a certified OpenID Connect & OAuth 2.0 library for .NET - deployed inside your perimeter, on keys only you hold, with no vendor lock-in and no geopolitical risk. Built for banks, telecoms and enterprises where compliance isn't optional.
The modern standard for authentication
One login across web, mobile, Smart TV and IoT. Unlike ageing protocols like SAML or WS-Federation, OpenID Connect is the de-facto standard - broadly supported, secure and built to scale.
Modern standard, broad support
The most widely supported authentication standard, with libraries and tools on every major platform.
Compatibility
Integrates cleanly with the systems you already run, with no rip-and-replace of your current infrastructure.
Flexibility & scale
Add new domains and adapt to architecture changes without heavy cost.
Security & separation of concerns
Separates authentication from resource management, hardening the whole system against unauthorized access.
Built for organisations that can't outsource trust
When you authenticate millions of customers under regulatory scrutiny, identity is too critical to rent. Abblix puts the standard-compliant core in your hands and leaves everything sensitive inside your walls.
Data sovereignty & compliance
You decide where data lives, how it's stored and backed up, and which data centres and regions it touches. Keeping the user base inside your infrastructure simplifies GDPR, HIPAA and local regulatory compliance - by design, not by contract.
Financial-grade security
The building blocks regulated sectors require: mutual-TLS & certificate-bound tokens, PAR, JAR, JARM, PKCE and CIBA for decoupled, backchannel authentication - ideal for banking and high-assurance flows.
No lock-in, no geopolitical risk
No dependence on a third-party cloud's availability, pricing or policy. No exposure to sanctions or cross-border service disruption. Your authentication stays fully under your control - and stays running.
Why a server library beats a hosted identity provider
A library runs where you run. That single difference is what makes Abblix viable for enterprises that have already invested in their own stack.
Integration flexibility
Reuse your existing user database, UI and auth factors - OTP, biometrics, hardware keys, any combination. Add OpenID Connect to what you already run.
Runs inside your application
Authentication happens in your own process - no extra network hop at login, no dependency on a third party's uptime or latency.
You control versions
You decide when to upgrade. Nothing changes in your sign-in flow on somebody else's release schedule.
Costs don't scale with users
Licensed per deployment - never per user, per token or per active account.
Engineered to extend, not to constrain
Many libraries implement OpenID Connect. Few are built from the architecture up to be adapted, audited and trusted in production.
Hexagonal, framework-agnostic architecture
Ready for ASP.NET Core out of the box - controllers, model binding and routing included. Thanks to a hexagonal core, OIDC Server adapts to any current or future framework for building an OpenID Connect Web API.
Modular design & open source
Validation, request processing and response formatting are cleanly separated and wired through standard .NET dependency injection. Source is on GitHub for full transparency and third-party security audits.
Cross-platform & .NET-native
Built for .NET 8, 9 and 10. Runs on Windows and Linux, ships happily in Docker and orchestrates with Kubernetes - deployment and scaling stay simple.
Certified & secure
Certified by the OpenID Foundation across all profiles - passed every conformance test with zero remarks or warnings. Security and standards compliance are the product, not an afterthought.
One compliant core. Everything else stays yours
Abblix takes on one responsibility - strict, certified compliance with the OpenID Connect standard. Your data, keys, UI and systems remain exactly where they are.
The certified OpenID Connect & OAuth 2.0 core - connected to your systems through clean, documented ports.
Built for the flows real products need
From enterprise SSO to financial-grade and input-constrained devices - one certified core covers them all.
Enterprise SSO
One login across every web, mobile and internal application your organisation runs.
Banking & financial-grade
High-assurance flows (mTLS, PAR, JAR/JARM, CIBA) for regulated financial services.
IoT & Smart TV
Device Authorization Grant for input-constrained devices, with built-in brute-force protection.
Decoupled & backchannel
CIBA for call centres and out-of-band approval - poll, ping and push delivery modes.
Runs where you already run
No exotic dependencies - deploy OIDC Server on the stack you already operate.
Platform
Web server
Hardware
Certified by the OpenID Foundation. Every profile
Flexible pricing for businesses of any size
From evaluation to enterprise-wide deployment - licensing that scales with you, not against you.
Evaluate our products against your architecture
Want a closer look at how they fit your stack, your compliance requirements or your scale? Our engineering team will help you.