Identity infrastructure for Cloudflare
Build identity at the edge, without giving up control
XID brings Hosted Auth, OIDC, organizations, enterprise federation, directory sync, and SDKs into one MIT-licensed platform running on Cloudflare Workers.
- License
- MIT
- Runtime
- 3 Workers
- Public locales
- 8
- Self-hosting
- Complete edition
The product surface
One control plane from sign-in to enterprise access
Use the complete platform or adopt the protocol, UI, and SDK layers that fit your architecture.
Hosted sign-in, passkeys, password, MFA, session management, consent, and account self-service share one tenant-aware Core.
Organizations and accessModel organizations, OrgUnits, projects, roles, grants, approval policies, and access requests without creating a separate admin tenant.
Federation and provisioningConnect inbound SAML and OIDC, downstream SaaS SSO, SCIM, directory sync, and domain discovery behind explicit policy boundaries.
Protocols and developer experienceShip OIDC and OAuth flows, Management APIs, webhooks, framework SDKs, localized docs, and networkless token verification from one repository.
Pre-1.0 status
Evidence before compatibility claims
The protocol matrix separates implemented behavior, local conformance evidence, and production support. SAML is not described as production-ready until it is validated against a real identity provider.
Inspect the protocol matrixOpen source, inspectable, and self-hostable
The MIT-licensed repository includes the complete feature set. Security posture and project governance remain visible through OpenSSF and the public source.
View source on GitHub