{"type":"blog_post","title":"casdoor: AI-First IAM & LLM MCP Client Gateway","description":"casdoor is an open-source, Go-based Identity and Access Management (IAM) and LLM gateway, specifically designed with an AI-first approach. It acts as an MCP Client, providing robust authentication and authorization for AI applications and agent-to-agent communication. Developers building AI systems needing comprehensive identity services and MCP integration will find it particularly useful.","content":"# casdoor: An AI-First IAM and LLM MCP Gateway\n\ncasdoor, an open-source Identity and Access Management (IAM) system written in Go, distinguishes itself as an \"Agent-first\" solution with a strong focus on AI applications. It functions as both an LLM gateway and an authentication server, providing comprehensive identity services while integrating directly with the Model Context Protocol.\n\n## MCP Gateway for AI Applications\n\nAt its core, casdoor is engineered for the AI ecosystem. It provides direct Model Context Protocol support, acting as an MCP Gateway. This means it's built to handle the unique context and communication requirements of AI models and agents. Furthermore, its support for the A2A Protocol facilitates direct Agent-to-Agent communication, a critical component for orchestrating complex AI workflows. The entire design philosophy is \"AI-First,\" ensuring that identity and access controls are inherently optimized for autonomous and collaborative AI systems.\n\n## Comprehensive Identity and Access Management\n\nBeyond its MCP capabilities, casdoor offers a full suite of IAM features, making it a versatile choice for managing users and access in any application, especially those with an AI component.\n\nFor authentication, it supports a wide array of protocols and methods:\n*   **OAuth 2.0 / OIDC**: Standardized authorization for web, mobile, and desktop applications.\n*   **SAML 2.0**: Enterprise-grade Single Sign-On (SSO).\n*   **CAS**: Central Authentication Service integration.\n*   **LDAP**: Directory service integration.\n*   **WebAuthn / Passkeys**: Modern passwordless authentication.\n*   **TOTP / MFA**: Multi-factor authentication for enhanced security.\n*   **Face ID**: Biometric authentication support.\n\nEnterprise features include SCIM 2.0 for user provisioning, RBAC for granular access control, and multi-tenancy support for organizations. It also facilitates social logins (Google, GitHub, Azure AD), custom identity providers, and offers a web UI for user management and audit logs.\n\n## Developer Experience and Extensibility\n\nDevelopers integrating casdoor will find a robust set of tools and features designed for ease of use. It provides a complete RESTful API, interactive API documentation via Swagger UI, and webhooks for event-driven integrations. SDKs are available for popular languages including Go, Java, Python, and Node.js, streamlining client-side integration. The UI is also customizable, allowing for brand theming.\n\nFor AI developers building agentic systems or LLM-powered applications, casdoor offers a centralized identity and access layer that understands and speaks MCP. This allows for secure, managed access to models and context, with built-in support for agent communication, all while leveraging a mature, feature-rich IAM platform.\n\n## References\n- [casdoor on GitHub](https://github.com/casdoor/casdoor)\n- [Model Context Protocol Documentation](https://modelcontextprotocol.io/introduction)\n- [casdoor on model-context-protocol.com](https://model-context-protocol.com/clients/)","keywords":["casdoor","mcp-client","iam","ai-gateway","agent-to-agent"],"published_at":"2026-07-25T12:00:35.6+00:00","related_repository":{"slug":"casdoor","type":"Client","url":"https://model-context-protocol.com/clients/casdoor"},"source_url":"https://model-context-protocol.com/blog/casdoor-ai-first-iam-llm-mcp-client-gateway-mcp-client-guide"}