Top AI Repos — open-source AI, indexed and scored
Top AI Repos tracks AI repositories on GitHub and answers two different questions about each one: is it moving right now, and would you bet a product on it.
Top AI Repos tracks AI repositories on GitHub and answers two different questions about each one: is it moving right now, and would you bet a product on it.
ThunderID is a high-performance, open-source identity stack designed for developers to secure and manage access for humans, AI agents, and workloads through fully composable identity flows.
| Date | Stars |
|---|---|
| 2026-07-31 | 384 |
| 2026-08-06 | 384 |
Today
— stars today
This week
— stars this week
This month
— stars this month
Momentum
35.0
growth rate 0.00%/day
<img src="https://thunderid.dev/assets/images/readme/repo-banner.png" alt="ThunderID" width="100%" />
###
[](https://opensource.org/licenses/Apache-2.0)
[](https://github.com/thunder-id/thunderid/commits/main)
[](https://github.com/thunder-id/thunderid/issues)
[](https://codecov.io/github/thunder-id/thunderid?branch=main)
[](https://github.com/thunder-id/thunderid/releases/latest)
ThunderID is a lightweight, open-source Identity and Access Management (IAM) engine built to secure access for humans, AI agents, and machines.
Designed for the agentic era, ThunderID provides a developer-first IAM platform and supporting tools for securing applications, APIs, services, and agent-driven workflows. It works across traditional and decentralized identity ecosystems, with post-quantum-ready security built in from the start.
Core design goals of ThunderID include:
- **Agent-native identity:** Manage AI agents as first-class identities with delegated authority, consent-aware access, traceability, and support for issuing verifiable credentials to agents. ThunderID also aims to expose IAM capabilities through interfaces that agents can use safely and programmatically.
- **Decentralized identity:** Bridge the adoption gap for relying parties by making it practical for service providers to consume, verify, and trust decentralized identity in real-world applications, including DIDs, verifiable credentials, digital wallets, trust registries, and issuer-verifier-holder interaction models.
- **Cloud-native IAM:** Provide a lightweight, containerized identity product that can run across on-premises and cloud environments, with declarative identity flows, policies, and configuration suitable for automation, versioning, and GitOps practices.
- **Post-quantum-safe security:** Build on a crypto-agile foundation where algorithms, key types, signing methods, and token protection mechanisms can evolve over time, including support for post-quantum-safe algorithms and hybrid transition approaches across key management, credential issuance, assertions, and secure service-to-service communication.
## Getting Started
Get started by exploring how ThunderID can be used to secure:
* Applications - by following [Securing B2C Application Guide](https://thunderid.dev/docs/next/use-cases/b2c/try-it-out)
* AI Agents - by following [Securing AI Agents Guide](https://thunderid.dev/docs/next/use-cases/ai-agents/try-it-out)
* MCP - by following [Securing MCP Guide](https://thunderid.dev/docs/next/use-cases/ai-agents/mcp-authorization/try-it-out)
To learn more about overall requirements, solution patterns of these scenarios, refer to the [Use Cases](https://thunderid.dev/docs/next/use-cases/overview/) section.
Visit [Get ThunderID](https://thunderid.dev/docs/next/guides/getting-started/get-thunderid/) to learn more about installation methods.
## Architecture
<img src="https://thunderid.dev/assets/images/readme/architecture.png" alt="ThunderID Architecture" width="100%" />
## Features
* **Identity Management**
* Humans, AI agents, and workloads as first-class identity types
* Hierarchical organizational units (OUs) and groups
* **Standards**
* OAuth 2.1 and OpenID Connect, with PAR and PKCE
* Verifiable Credentials — OpenID4VCI (issuance) and OpenID4VP (verification)
* WebAuthn / passkeys
* IdP federation — Google, Microsoft, GitHub, and any OIDC or SAML provider
* **Decentralized Identity**
* Issue Verifiable Credentials to user wallets from configurable credential templates
* Verify presented credentials against prExcerpt of 5,493 characters
Read on GitHubWould you bet a product on this? Bounded 0–100 and slow moving.
matched fp:4635d055afc80e3d, topic:ai-agents, desc:ai agents