
cerbos
Authorization engine for context-aware access control with YAML policies, RBAC/ABAC support, check/plan APIs, and GitOps-friendly deployment.

Authorization engine for context-aware access control with YAML policies, RBAC/ABAC support, check/plan APIs, and GitOps-friendly deployment.

Open-source sandboxed agent harness for teams. Giving every employee a secured personal agent.

A secure persistent personal agent server in Rust. One binary, sandboxed execution, multi-provider LLMs, voice, memory, Telegram, WhatsApp, Discord,…

Authentication, authorization, traceability and auditability for SSH accesses.

HardeningKitty - Checks and hardens your Windows configuration

Protects software supply chain integrity by verifying each step is performed by authorized functionaries, using signed layout and link metadata.

A binary and file access authorization system for macOS.

Automated HTTP Request Repeating With Burp Suite

Open source Dropbox-like file sharing with full client encryption !

Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and…

FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

Better PHP rate limiting using Redis.

Declarative authorization library with a DSL for writing policy rules, conditions, and caching. Enables scalable, DRY permission management for Ruby…

SecDim Challenge Builder repro inspired by CVE-2026-88861: AAL1 MFA bypass at privileged credential boundary

Zero-knowledge privacy platform for confidential API key management, encrypted vault, and secure chat. Built on Oasis Sapphire TEEs

Proof-of-concept exploit for Apache ShenYu Admin JWT authentication bypass (CVE-2021-37580). Includes a scanning script to detect vulnerable…

Proof-of-concept for CVE-2026-59243 demonstrating JWT signature bypass in Apache Airflow FAB Auth Manager's Azure AD OAuth callback due to insecure…