<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: dmandreev</title>
    <description>The latest articles on DEV Community by dmandreev (@dmandreev).</description>
    <link>https://dev.to/dmandreev</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4161098%2Fa6db35f9-960e-466d-8703-b5c563d2a9f5.jpg</url>
      <title>DEV Community: dmandreev</title>
      <link>https://dev.to/dmandreev</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/dmandreev"/>
    <language>en</language>
    <item>
      <title>Issuerd: a Keycloak-compatible IAM in Rust — one binary, 3,907 OIDC conformance checks, zero failures</title>
      <dc:creator>dmandreev</dc:creator>
      <pubDate>Wed, 07 Oct 2026 09:24:03 +0000</pubDate>
      <link>https://dev.to/dmandreev/issuerd-a-keycloak-compatible-iam-in-rust-one-binary-3907-oidc-conformance-checks-zero-52g2</link>
      <guid>https://dev.to/dmandreev/issuerd-a-keycloak-compatible-iam-in-rust-one-binary-3907-oidc-conformance-checks-zero-52g2</guid>
      <description>&lt;p&gt;If you've operated Keycloak in production, you know the tax: a JVM that wants gigabytes before it serves a single login, container startup measured in tens of seconds, and clustering that means Infinispan whether you like it or not. It's a great IAM — arguably the de-facto open-source standard — but the operational profile is the price you pay on every deploy.&lt;/p&gt;

&lt;p&gt;For the past three months I've been building &lt;strong&gt;&lt;a href="https://github.com/issuerd/issuerd" rel="noopener noreferrer"&gt;issuerd&lt;/a&gt;&lt;/strong&gt;: an identity and access management server that keeps the Keycloak model — realms, clients, roles, client scopes, protocol mappers, authentication flows, Admin REST API — and drops the operational tax. It's written in Rust, ships as &lt;strong&gt;one self-contained binary&lt;/strong&gt; (the admin console, account console, and login pages are embedded), and it's open source under Apache-2.0.&lt;/p&gt;

&lt;p&gt;This is the launch post. I'll try to lead with proof rather than promises.&lt;/p&gt;

&lt;h2&gt;
  
  
  Proof point 1: conformance, measured by the official suite
&lt;/h2&gt;

&lt;p&gt;Anyone can claim "OIDC compliant". issuerd runs the &lt;strong&gt;official OpenID Foundation Conformance Suite&lt;/strong&gt; (release v5.2.4) in CI, the way it's meant to be run:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;3,907 conditions verified across the Basic OP, Form Post OP, and Config OP profiles — zero failures, zero warnings.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;The suite runs &lt;strong&gt;pristine&lt;/strong&gt; (unpatched JAR built in-docker from the pinned tag) in a &lt;strong&gt;hermetic TLS environment&lt;/strong&gt;: isolated network, own root CA, no internet.&lt;/li&gt;
&lt;li&gt;Per-module results are &lt;a href="https://github.com/issuerd/issuerd/blob/v0.1.12/tests/conformance/COVERAGE.md" rel="noopener noreferrer"&gt;checked into the repo&lt;/a&gt;, and the full evidence bundle is attached to every release.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The discovery document advertises exactly what is implemented and tested — nothing more. If issuerd doesn't do something, it says so instead of failing creatively at runtime.&lt;/p&gt;

&lt;h2&gt;
  
  
  Proof point 2: Keycloak compatibility as a test target, not a slogan
&lt;/h2&gt;

&lt;p&gt;"Compatible" is easy to write in a README. issuerd treats a live &lt;strong&gt;Keycloak 24.0&lt;/strong&gt; container as a test oracle: a dual-target suite runs the same protocol assertions against issuerd and Keycloak — JSON shapes, Admin API responses, error behavior — and &lt;a href="https://github.com/issuerd/issuerd/blob/v0.1.12/tests/KEYCLOAK_DIFFS.md" rel="noopener noreferrer"&gt;every deliberate difference is documented&lt;/a&gt;. Existing OIDC clients and Keycloak-hardened operational knowledge transfer directly.&lt;/p&gt;

&lt;p&gt;To be clear: issuerd is &lt;strong&gt;not&lt;/strong&gt; a rewrite or a fork. It's an independent implementation that uses Keycloak as the reference baseline.&lt;/p&gt;

&lt;h2&gt;
  
  
  Proof point 3: the operational numbers
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Up to 7.8× throughput, ~6× less memory, 8.7× smaller image&lt;/strong&gt; vs Keycloak 26.7 in our benchmarks (methodology and the k6 stack are in &lt;a href="https://github.com/issuerd/issuerd/blob/v0.1.12/docs/PERFORMANCE.md" rel="noopener noreferrer"&gt;docs/PERFORMANCE.md&lt;/a&gt; — reproducible, not a slide).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;100,003 users synced from a live Active Directory in ~30 seconds&lt;/strong&gt; (~3,300 users/s), with group-membership reconciliation.&lt;/li&gt;
&lt;li&gt;Access-token validation is &lt;strong&gt;stateless&lt;/strong&gt; — no database lookup on the hot path. Signing keys are shared cluster-wide through PostgreSQL, transient coordination state lives in Redis. No sticky sessions: any number of nodes behind any load balancer.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  The engineering under it
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;~152k lines of Rust&lt;/strong&gt; across a workspace of &lt;strong&gt;9 library crates + 1 binary&lt;/strong&gt; — ~131k of it in the crates, ~20k in tests — with a strictly acyclic dependency graph. Each crate compiles independently.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;&lt;code&gt;#![forbid(unsafe_code)]&lt;/code&gt;&lt;/strong&gt; everywhere — zero &lt;code&gt;unsafe&lt;/code&gt; by construction.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Typestate markers&lt;/strong&gt; make invalid authentication-state transitions fail at compile time, not at runtime.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;3,300+ automated tests&lt;/strong&gt;; every public function is testable without network or database.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Built for the agent era
&lt;/h2&gt;

&lt;p&gt;AI agents acting on behalf of users break the assumptions bearer tokens were designed around. issuerd already ships the three standards the industry has converged on:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;DPoP (RFC 9449)&lt;/strong&gt; — access tokens cryptographically bound to their holder's key; a stolen token is scrap metal.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;RFC 8693 token exchange&lt;/strong&gt; — each tool call mints a fresh, audience-narrowed, scope-&lt;em&gt;attenuated&lt;/em&gt; token. Scope can only ever shrink across an exchange.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CIBA (poll mode)&lt;/strong&gt; — human-in-the-loop step-up approval for dangerous actions, with a binding message.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;There's a runnable end-to-end demo in the repo (&lt;a href="https://github.com/issuerd/issuerd/tree/v0.1.12/examples/agentic-mcp" rel="noopener noreferrer"&gt;&lt;code&gt;examples/agentic-mcp/&lt;/code&gt;&lt;/a&gt;): a scripted chat agent → MCP server → PostgreSQL row-level security, including the attacks (prompt injection, stolen-token replay, unapproved refund) and the refusals.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9rdf63lletjnwvo1uma9.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9rdf63lletjnwvo1uma9.png" alt="Human step-up approval (CIBA): the agent asks, the human approves — with a binding message" width="800" height="450"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Honest scope
&lt;/h2&gt;

&lt;p&gt;This is &lt;strong&gt;v0.1&lt;/strong&gt;. What's deliberately &lt;strong&gt;not&lt;/strong&gt; in scope today: &lt;strong&gt;SAML, UMA, FGAP, Organizations&lt;/strong&gt;. If you need those, Keycloak is the right answer today, and I'd rather say that here than in a GitHub issue six weeks from now.&lt;/p&gt;

&lt;p&gt;What is in scope: SSO, MFA and passkeys, user federation (LDAP / Kerberos / SPNEGO against Samba AD, OpenLDAP, MS AD), social login and OIDC identity brokering, themable login pages, per-realm i18n with localized emails, declarative YAML provisioning, one-command OpenAPI export, Prometheus metrics, health/readiness probes, TLS.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try it
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git clone https://github.com/issuerd/issuerd &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nb"&gt;cd &lt;/span&gt;issuerd
docker compose up   &lt;span class="c"&gt;# pulls issuerd/issuerd:latest — no build tools needed&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;ul&gt;
&lt;li&gt;Admin console: &lt;a href="http://localhost:8080/admin/console" rel="noopener noreferrer"&gt;http://localhost:8080/admin/console&lt;/a&gt; (&lt;code&gt;admin&lt;/code&gt;/&lt;code&gt;admin&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;Demo realm &lt;code&gt;myrealm&lt;/code&gt;: &lt;code&gt;alice&lt;/code&gt;/&lt;code&gt;changeme&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Pre-built binaries (Linux x86_64/aarch64, Windows, macOS arm64) with SBOMs and the conformance-evidence bundle are on the &lt;a href="https://github.com/issuerd/issuerd/releases" rel="noopener noreferrer"&gt;releases page&lt;/a&gt;; also on &lt;a href="https://hub.docker.com/r/issuerd/issuerd" rel="noopener noreferrer"&gt;Docker Hub&lt;/a&gt; and &lt;a href="https://crates.io/crates/issuerd" rel="noopener noreferrer"&gt;crates.io&lt;/a&gt;. Docs: &lt;a href="https://issuerd.org" rel="noopener noreferrer"&gt;issuerd.org&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fo1gvex2sea388gblhidw.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fo1gvex2sea388gblhidw.png" alt="The admin console dashboard" width="800" height="500"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  What's next
&lt;/h2&gt;

&lt;p&gt;OIDF certification (the open-source track — the suite already passes, it's mostly paperwork), a v0.2.0 in a few weeks, and comparison/benchmark deep-dives. If you try the quickstart and hit friction, I want to know — issues and discussions are open, and there are a few &lt;a href="https://github.com/issuerd/issuerd/labels/good%20first%20issue" rel="noopener noreferrer"&gt;&lt;code&gt;good first issue&lt;/code&gt;&lt;/a&gt; tickets if you'd like to contribute.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;I'm the author. Ask me anything — including the uncomfortable questions.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>rust</category>
      <category>opensource</category>
      <category>security</category>
      <category>oauth</category>
    </item>
  </channel>
</rss>
