Casdoor vs. Logto
Logto and Casdoor are both newer open-source identity platforms with a web console, hosted options, and an interest in AI agent authentication. Logto focuses on being developer infrastructure for SaaS products and customer identity. Casdoor covers that ground too and adds the workforce and legacy side: directories, more protocols, and more sign-in providers.
Summary
| Casdoor | Logto | |
|---|---|---|
| Backend | Go | TypeScript on Node.js |
| License | Apache-2.0 | MPL-2.0 |
| Database | MySQL, MariaDB, PostgreSQL, SQL Server, Oracle, SQLite, and others | PostgreSQL |
| OAuth 2.0, OIDC, SAML | Yes | Yes |
| CAS, LDAP server, RADIUS server, Kerberos | Built in | Not offered |
| Multi-tenancy | Organizations, each with its own users, applications, and theme | Organizations with organization roles |
| Sign-in providers | 70+ OAuth providers, SAML, LDAP, Web3 | Social and enterprise connectors |
| Directory sync | Syncers for Active Directory, Azure AD, Google Workspace, Okta, Keycloak, databases; SCIM | Enterprise SSO connectors |
| Authorization | Casbin models (ACL, RBAC, ABAC) | API resources with RBAC |
| AI agents and MCP | Built-in MCP server; OAuth 2.1 authorization server for MCP | OAuth 2.1 authorization server for MCP |
| Payments | Built in | No |
Stack and deployment
Logto is a Node.js service that requires PostgreSQL. Casdoor is a Go binary that works with most SQL databases, including SQLite for small installations. Which one is easier depends on what you already run; if your infrastructure standard is MySQL or SQL Server, Casdoor fits without adding another database engine.
docker run -p 8000:8000 casbin/casdoor-all-in-one
Developer experience
Logto invests heavily in quickstarts and framework SDKs for modern JavaScript stacks, and its console guides you through integrating a new application.
Casdoor provides SDKs for Go, Java, Node.js, Python, PHP, .NET, Rust, and more, guides for Next.js, Nuxt, and Vue, and works with any standard OIDC client. It also has a long list of ready-made integrations for existing software such as Grafana, GitLab, Jenkins, and Kubernetes.
Workforce and legacy needs
This is where the two differ most. Casdoor can:
- serve LDAP, RADIUS, and CAS to applications and devices that do not speak OIDC;
- sign users in with Kerberos on domain-joined machines;
- keep users in sync with Active Directory, Azure AD, Google Workspace, Okta, or a database through syncers, and provision through SCIM;
- offer WeChat, DingTalk, Lark, and other regional providers on the login page.
If your product only needs customer sign-in over OIDC, none of this matters. If the same system must also serve employees and older internal tools, it does.
AI agents and MCP
Both projects implement the OAuth 2.1 pieces the Model Context Protocol requires. Casdoor's documentation covers using Casdoor as the authorization server for your MCP server, including Dynamic Client Registration, PKCE, and resource indicators.
Casdoor additionally ships an MCP server for its own management API, so an assistant such as Claude or Cursor can list and update users or create and configure applications with a scoped token.
Authorization
Logto models API resources, scopes, and roles. Casdoor uses Casbin, which supports plain RBAC and also ACL, RBAC with domains, and ABAC, and exposes the enforcement API for your services to call.