{"repo":"kawasima/bouncr","free":true,"listed":false,"github":"https://github.com/kawasima/bouncr","clone":"git clone https://github.com/kawasima/bouncr.git","description":"A reverse proxy with authentication and authorization","language":"HTML","stars":24,"topics":["authorization","authentication","permissions","audit","reverse-proxy"],"license":"EPL-2.0","category":"auth-billing-email","readme_excerpt":"Bouncr An authentication gateway and OIDC Identity Provider for backend applications, powered by Envoy ext proc. Why Bouncr - Stateless backend applications by design — authentication state is handled at the proxy/gateway layer, and backend apps receive request-scoped identity via x-bouncr-credential - Easier testing and operations — apps can be tested without session stores/sticky sessions, and auth behavior can be reproduced by header-based credentials in integration tests - Pragmatic self-hosted auth core — combines OIDC/OAuth2 identity endpoints with a clear Group → Role → Permission → Realm model for service-to-service and backend authorization Features Authentication Gateway - Transparent auth proxy — Envoy ext proc injects x-bouncr-credential JWT into every request; backend apps need zero auth code - Multiple credential types — Password, OpenID Connect (RP), TOTP two-factor authentication - BFF session management — Short-lived access cache (15 min) + long-lived refresh marker (7 days) with transparent refresh via bouncr-proxy - Fine-grained authorization — Group → Role → Permission model with per-Realm scope - Cross-application session reuse (current Phase 3 behavior) — one Bouncr session token is reused across applications; proxy filters permissionsByRealm into realm-specific permissions before forwarding OIDC Identity Provider Bouncr acts as a full OIDC Identity Provider (comparable to Kanidm): Endpoint Path RFC --- --- --- Authorization GET /oauth2/authorize RFC 674","default_branch":null,"files":null,"tree":[],"storefront":"/r/kawasima","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/kawasima/bouncr/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}