Open source
Nothing builds trust like open source
Community-governed open source supercharges innovation. The Janssen Project is chartered directly under the Linux Foundation, and Gluu is its lead maintainer.
How the project is put together
- The Janssen Project is chartered directly under the Linux Foundation
- Gluu is the lead maintainer of the Janssen Project
- Janssen distributions include community-governed components such as Keycloak, a CNCF project
- The Agama ecosystem includes third-party connectors to authentication providers, fraud detection and AI
- GitHub is home to everything: code, releases, discussions and project management
Governance
The project charter tethers the Janssen Project to a Delaware limited liability company. It defines how Collaborators work together, guided by a Technical Steering Committee. The TSC provides strategic oversight rather than micro-managing code development, and stewards the Janssen Project trademark.
Releases, docs and security
Releases
Janssen releases include source, containers, Linux packages, cloud-native deployment assets, tools and demos. Nightly builds make it easy to try the latest features. Releases ship at least monthly.
Documentation
Janssen docs cover installation, configuration, operation and reference material such as database schema and OpenAPI endpoint definitions.
Security
The project follows the Linux Foundation vulnerability disclosure policy and publishes container scans on ArtifactHub. Identity is about trust — transparency is a security advantage.
Agama
Agama is a domain-specific language and project archive format for orchestrating web authentication journeys. The core stack is developed at Janssen; Agama projects are published by third parties and discoverable through the project.
Recognition and licensing
The Digital Public Goods Alliance, a multi-stakeholder UN-endorsed initiative, has recognized the Janssen Project as a Digital Public Good — external validation that the project is well constructed, governed and maintained.
All source code and binaries published in the Janssen Project are licensed under the Apache License 2.0.
Get involved
Gluu runs an open Zulip. Ask the maintainers a question, follow a release, or see what people are building.

