Featured image of post Casdoor v4 Released: Console Rewritten in React, Built-in MCP Server and Agent Authentication, Officially Listed in CNCF Landscape

Casdoor v4 Released: Console Rewritten in React, Built-in MCP Server and Agent Authentication, Officially Listed in CNCF Landscape

Casdoor v4 is released with React-based console, built-in MCP Server and Agent authentication, and added to CNCF Provisioning section.

Casdoor v4.0 was officially released on September 1, 2026, and has since advanced to v4.3 as of September 9, 2026. Developed by the Casbin community under the Apache 2.0 license, Casdoor is an open-source identity and access management (IAM) solution built with Go for the backend and React for the frontend.

Key Highlights and Launch Details

  • Release date: September 1, 2026 (v4.0)
  • Current version: v4.3 (as of September 9, 2026)
  • License: Apache 2.0 (open-source, free for commercial use)
  • Tech stack: Backend in Go, frontend in React
  • Platform: GitHub (officially listed in CNCF)
  • CNCF status: Added to the CNCF Landscape on February 22, 2026, under the Security & Compliance category within the Provisioning section

Casdoor evolves from the CAS (Central Authentication Service) protocol into a modern IAM platform. The most significant change in v4 is the complete rewrite of the admin console using React, greatly enhancing interactivity and component maintainability. Additionally, v4 introduces built-in MCP Server and Agent authentication support, enabling fine-grained authorization for service-to-service calls in cloud-native microservices architectures. The MCP (Multi-Cloud Platform) Server facilitates unified authentication policy management across cloud environments, while the Agent component provides lightweight authentication integration for Sidecar or standalone proxy patterns.

Project Context and Notable Data

Casdoor originates from the well-established Casbin open-source community, inheriting Casbin’s robust policy models including RBAC and ABAC. Building upon traditional SSO capabilities, it has steadily expanded into service-level authorization. Though GitHub star counts are not disclosed in the source material, Casdoor has gained a growing GitHub following and ranks among the most active open-source IAM projects in the Chinese developer ecosystem.

A striking pattern emerges: Casdoor reached v4 approximately six months after its CNCF Landscape inclusion on February 22, 2026. Typically, projects admitted to the CNCF Landscape require extended stabilization before major releases, yet Casdoor accelerated its development pace. This contrasts with CNCF’s usual expectation of conservative iteration post-admission—most projects prioritize stability over rapid feature delivery, whereas Casdoor opted for aggressive feature rollout.

The CNCF Landscape categorizes IAM tools under Provisioning rather than Security, reflecting the shift in cloud-native thinking: identity is viewed as a “gatekeeper” preceding resource access. The emphasis lies in managing authentication workflows as infrastructure, not merely adding security features.

Feature Comparison (Based on Available Information)

Featurev4.xv3.x (inferred)
Frontend frameworkReact (console rewritten)Legacy framework (not specified)
Built-in MCP ServerYesNo
Agent authenticationYesNo
CNCF Landscape inclusionFebruary 22, 2026Not listed

Note: v3.x features are not explicitly detailed in the source material; comparisons are reverse-engineered from new v4 capabilities.

When to Adopt

  • Adopt v4 now if: You’re building or refactoring a Go-based microservices system; require unified authentication policy management across multi-cloud; or already use Casbin models and seek seamless migration to a full IAM platform.
  • Consider waiting if: Your team demands extensive UI customization (the React rewrite may require theme re-implementation); you need mobile SSO support (not mentioned in the report); or you run monolithic applications with no need for MCP/Agent functionality.

Final Thoughts

Casdoor’s rapid release cycle demonstrates how open-source IAM infrastructure is transitioning from “functional” to “production-grade.” Though the React console rewrite introduces short-term migration effort, it improves long-term community maintainability. Its CNCF inclusion further signals that IAM is evolving from a security add-on to a core provisioning infrastructure component in cloud-native environments.