Casdoor v4 Targets MCP and Agent Authentication
As MCP Servers and AI Agents become part of application architectures, identity systems must manage more than human users and conventional applications. They also need to account for software agents that call tools, access data, and perform tasks. Casdoor’s v4 release responds to that shift by extending its identity and access management focus toward AI-oriented workflows.
What changed in v4
According to the available material, Casdoor v4.0 was released on September 1, 2026, and the project had reached v4.3 by September 9. The headline changes include:
- A fully rewritten console: The administration console is the main operating surface for an identity platform. Rebuilding it suggests an effort to improve the management experience and establish a more suitable foundation for future capabilities.
- An integrated MCP Server: MCP provides a more standardized way for models and agents to connect with tools and external resources. Including an MCP Server in the platform brings identity management closer to the architecture of emerging AI workflows.
- Authentication for Agents: Conventional authentication is usually designed around users signing in and applications accessing services. Agent-based systems introduce additional questions about the calling entity, resource boundaries, and task-specific permissions. By explicitly addressing Agent authentication, Casdoor is responding to that change in the access-control landscape.
Casdoor is developed by the Casbin community, uses Go and React, and is released under the Apache 2.0 license. The project was also added to the CNCF Cloud Native Landscape on February 22, 2026, under the Security & Compliance category of the Provisioning section. Inclusion in the landscape should not be interpreted as a certification of the project’s capabilities or quality by CNCF; it primarily improves the project’s visibility within the cloud-native ecosystem.
Why it matters
For teams running microservices, cloud-native platforms, or AI applications, identity management is expanding from “letting users sign in” to governing relationships among people, applications, tools, and Agents. When authentication and authorization remain scattered across business code, gateways, and plugins, policy maintenance becomes harder. Casdoor’s direction reflects an attempt to bring these new calling entities into a common identity platform.
The practical value of MCP Server and Agent authentication will depend on details such as the permission model, credential lifecycle, audit support, and integration with existing systems. The available material does not provide enough information to assess the exact implementation scope. Teams evaluating the release should therefore consult the complete release notes, documentation, and source code before considering production use.
Casdoor v4 is more than a console redesign: it signals an effort to adapt identity management to tool-calling and Agent-based applications. Whether later releases can turn that direction into a clear and operational governance model for Agent permissions will be an important area to watch.
Source: OSChina
Comments
Checking sign-in status...
Loading comments...