thunder-id/thunderid
ThunderID is a high-performance, open-source identity stack designed for developers to secure and manage access for humans, AI agents, and machines through fully composable identity flows.
What it solves
ThunderID is an identity and access management (IAM) stack designed to secure access for humans, AI agents, and machines. It addresses the need for agent-native identity, allowing AI agents to be managed as first-class identities with delegated authority and traceability, while also preparing for future security threats through post-quantum-safe cryptography.
How it works
It provides a lightweight, containerized runtime that supports both traditional and decentralized identity ecosystems. The system uses declarative YAML resource definitions for configuration, making it compatible with GitOps practices. It integrates standard protocols like OAuth 2.1, OpenID Connect, and WebAuthn, and supports Verifiable Credentials (OpenID4VCI and OpenID4VP) to bridge the gap between decentralized identity and real-world applications.
Who it’s for
Developers building applications, APIs, and agent-driven workflows who need a secure, flexible IAM solution that supports AI agents, decentralized identity, and post-quantum security.
Highlights
- Agent-native identity: Treats AI agents as first-class identities with consent-aware access and support for verifiable credentials.
- Post-quantum-safe: Built on a crypto-agile foundation to support evolving post-quantum-safe algorithms.
- Decentralized identity support: Practical implementation of DIDs, verifiable credentials, and digital wallets.
- GitOps-ready: Uses YAML definitions and an immutable runtime for automated versioning and deployment.
- Agent-centric tooling: Includes an MCP server for AI agents to manage and query IAM capabilities programmatically.
Related
- Project
- Dispatch
- Project
- Project
- Dispatch