What is new in WSO2 Identity 7.0.0 release
Introduction to WSO2 Identity Server
What is new in WSO2 Identity 7.0.0 release
Introduction to WSO2 Identity Server
WSO2 Identity Server is an open-source Identity and Access Management (IAM) solution built on open standards such as SAML, OAuth, OIDC, XACML, SCIM, WS-Federation, and WS-Trust. First released in December 2007, WSO2 Identity Server has remained in the market for 16 years, with 32 versions released, including the latest WSO2 IS 7.0.0. Over time, it has evolved to include powerful features such as Single Sign-On (SSO), Entitlement and Access Control, Identity Governance and Administration, Identity Federation, Multi-Factor Authentication (MFA), Adaptive Authentication, and Organization Management.
A key reason for WSO2 Identity Server’s popularity is its extensive customization capabilities and ongoing commitment to open-source standards. Since it adheres closely to open protocols, users are not locked into proprietary systems, and the source code is publicly available for transparency.
In commercial deployments, WSO2 IS offers significant scalability with clustering support, handling an unlimited number of users, concurrent sessions, and incoming requests, making it well-suited for securing government-to-citizen (G2C) services. Additionally, its core-based pricing model allows for cost savings, as users pay based on resource usage rather than the number of monthly active users. Independent analyses have shown a 332% return on investment (ROI) over three years.
The aim of this article is to provide an overview of WSO2 Identity Server’s history, its evolution over the past decade, and its current market standing and features.
History of WSO2 Identity Server releases
A few days ago, I came across a Twitter post by Prabath Siriwardena, the “one of the founding members” of WSO2 Identity Server and former Deputy CTO at WSO2. Prabath has written an insightful article that details his journey from the release of WSO2 Identity Server 1.0.0 in 2007 to version 5.0.0 in 2014. The article highlights the key contributors who played significant roles in developing various features and the motivations driving certain customer deployments during that time.
In my 10 years of experience with WSO2 Identity Server (2014–2024), I’ve witnessed three major disruptions that shaped its evolution. The first was the introduction of federated authentication with IS 5.0.0 in 2014, which revolutionized how authentication was handled. The second was the inclusion of Adaptive Authentication capabilities in IS 5.7.0 in 2018, bringing advanced, context-aware security mechanisms. The third and most recent disruption was the organization management feature introduced with IS 7.0.0 in 2024, further enhancing the platform’s capabilities for managing complex organizational structures.
Also, you can refer to the below table to understand how WSO2 IS has evolved over the last 10 years with key features. If you are further interested in deep diving into WSO2 IS history, you can also refer to link.

Identity Server Market Today
Although WSO2 Identity Server is an open-source product, it has achieved more than 1,500 commercial deployments, a strong testament to the trust it has earned in the Identity and Access Management (IAM) domain. As seen in the above table, the accumulation across various categories amounts to nearly 900+ commercial deployments, highlighting its widespread adoption and credibility in enterprise environments. This success reflects the product’s ability to meet the demands of large-scale deployments while maintaining its open-source ethos.
You might be wondering how the additional 600+ commercial deployments come into the equation. These deployments are primarily from OEM (Original Equipment Manufacturer) partners, rather than from direct WSO2 customers. OEM partners integrate WSO2 Identity Server into their own solutions, which allows them to deploy the product across various industries and use cases. This further demonstrates the flexibility and adaptability of WSO2 Identity Server, as it not only serves direct customers but also empowers partners to extend its capabilities to a wider audience.
In the Identity and Access Management (IAM) domain, WSO2 Identity Server is a strong performer in the Customer Identity and Access Management (CIAM) ecosystem due to its rich features. These include social identity integration, federated authentication, multi-option/multi-step authentication, conditional authentication, adaptive authentication, organization management, as well as inbound and outbound provisioning capabilities.
While Workforce IAM is a more saturated market, WSO2 Identity Server is also fully equipped to handle enterprise-level IAM requirements in this space.
Another common use case for WSO2 IS is its role as a key manager for API management platforms. It provides first-class support for WSO2 API Manager (WSO2 APIM) as a key manager, and it can also integrate with other API management products, like Kong Gateway, by leveraging open standards such as OAuth 2.0 and OpenID Connect. This versatility makes it a robust solution across multiple IAM use cases.

In terms of industry recognition, WSO2 Identity Server has been highly regarded by analysts. KuppingerCole named WSO2 IS the Overall Product Leader in CIAM Platforms in 2022, the Overall Leader in Identity API Platforms in 2019, and the Product Leader in Access Management/Federation in 2018. Additionally, Forrester Wave identified WSO2 IS as a strong performer in 2022.
You might wonder why WSO2 IS is not listed in the Gartner Magic Quadrant for Access Management. The reason is that, to be listed, a product must have at least 1,100 direct license customers. While WSO2 IS boasts a customer base of over 1,500, more than 500 of those customers come from OEM partners, not direct licenses, which explains why it doesn’t meet the criteria for inclusion in Gartner’s Magic Quadrant despite its strong market presence.
Why is the WSO2 Identity Server 7.0.0 release so special ?
In the Identity and Access Management (IAM) domain, one of the key challenges is achieving logical separation of identities. Up until the release of WSO2 Identity Server 7.0.0, the solution for this challenge was Multi-Tenancy. Multi-Tenancy provides a fully isolated environment for each tenant, allowing them to maintain their own distinct set of applications, identity providers, authentication flows, and customized branding for login pages. This ensures that each tenant operates independently within a shared infrastructure, addressing the need for identity separation while maintaining scalability and security.
Let’s examine some of the drawbacks of the multi-tenancy model when addressing B2B organization management requirements:
- No Relationship Between Tenants: In the multi-tenancy model, tenants are fully isolated from one another, meaning there’s no way to define relationships between them. Even the super tenant does not have any inherent relationship with other tenants.
- Limited Delegation in User Management: Tenant admin users with user management permissions are granted full control over the user lifecycle, but there is no way to delegate fine-grained authorization or control over specific aspects of user management.
- Flat Structure: Multi-tenancy follows a flat horizontal structure, which means that defining sub-organizations or creating a hierarchical organizational model is not possible.
Thanks to the WSO2 Identity Server 7.0.0 release, these limitations have been addressed through a comprehensive organization management feature. This new capability offers a more sophisticated way to handle the logical separation of identities, allowing organizations to define relationships, manage hierarchical structures, and delegate more granular permissions.
Vodafone was the first customer to utilize the organization management capabilities of WSO2 Identity Server, even before any general availability (GA) release of the feature.In this setup, Vodafone acts as the root organization and establishes a parent-child relationship with all its sub-organizations. This allows for full delegation of user lifecycle management to the admin users of the child organizations, while the parent organization retains overall control. Additionally, the hierarchical nature of the organization management feature enables child organizations to onboard their partners as another layer of child organizations, facilitating a more structured and efficient approach to managing identities and access across various levels of the organization.
All these rich features combined provide a comprehensive business value by enabling seamless onboarding of partner organizations into your identity and access management ecosystem. Once the platform is deployed for a partner organization, they can further extend the platform to onboard their own partner organizations, effectively creating a secondary business. This multi-level partnership capability adds significant flexibility and scalability, empowering organizations to expand their IAM infrastructure while maintaining control and security across all levels of the business hierarchy.
What is new with WSO2 IS 7.0.0 ?
All new features coming out of WSO2 IS 7.0.0 release can be categorized into 4 main areas as mentioned in the below quadrant.
Let’s have detailed analysis on each feature category with respective information
Optimized developer experience
To enhance the developer experience, four new features will be introduced with the product release:
- No-Code / Low-Code Visual Editor: This feature enables developers to create and manage applications with minimal coding requirements. The visual editor simplifies the design process, allowing users to build workflows, configure settings, and manage user interfaces through a drag-and-drop interface. This approach reduces development time and lowers the barrier to entry for those who may not have extensive programming knowledge.
- API for In-App Authentication: This feature provides developers with an API specifically designed for in-app authentication, allowing them to integrate authentication seamlessly into their applications. This API simplifies the process of user authentication within mobile or web apps, providing a consistent and secure way to manage user sessions and credentials without requiring extensive backend changes.
- Role-Based Access Control (RBAC) for APIs: With RBAC, developers can implement granular access control for their APIs based on user roles. This feature allows organizations to define specific permissions for different user roles, ensuring that users only have access to the resources and functionalities relevant to their roles. This enhances security by minimizing the risk of unauthorized access and simplifies user management.
- App Templates with Authentication Methods (Connections): This feature offers pre-built application templates that include various authentication methods and connection settings. Developers can quickly start new projects by using these templates, which come pre-configured with best practices for authentication and integration. This accelerates the development process and ensures a consistent approach to authentication across applications.
Comprehensive support for IAM requirements of B2B applications
As outlined in Chapter 2.0, the organization-management feature with B2B application support is a primary objective of the Identity Server 7.0.0 release. In this chapter, we will evaluate the B2B organization management features across three key areas:
- Empower Developers:
The new organization management capabilities provide developers with the tools needed to create flexible, scalable, and secure B2B applications. By leveraging intuitive APIs and the no-code/low-code visual editor, developers can efficiently implement organizational structures, manage user roles, and customize workflows without extensive coding efforts. This empowerment leads to faster development cycles and improved agility in responding to business needs.
2. Enhance Customer Experience:
The organization management features contribute significantly to enhancing the customer experience. With the ability to create tailored onboarding processes for partner organizations, users can access a seamless and cohesive experience when interacting with B2B applications. Customizable login journeys and in-app authentication capabilities ensure that end-users encounter a consistent interface, reducing confusion and improving satisfaction.
3. Optimize Digital Operations:
Optimizing digital operations is crucial for organizations aiming to improve efficiency and scalability. The B2B organization management features enable companies to automate user lifecycle management, delegate administrative tasks, and enforce role-based access controls. This streamlining of processes allows organizations to focus on their core operations while maintaining robust security and compliance measures.

In summary, the B2B organization management features in WSO2 IS 7.0.0 are designed to empower developers by providing them with intuitive tools and APIs for building scalable B2B applications. These features enhance customer experiences by enabling seamless onboarding and consistent user interfaces across applications. Additionally, they optimize digital operations through automated user lifecycle management and role-based access controls. Collectively, these advancements drive significant value and effectiveness in B2B environments, positioning organizations for success in a competitive landscape.
Financial-grade API security (FAPI)
FAPI (Financial-grade API) was first introduced with the WSO2 Open Banking solution, where WSO2 API Manager serves as a FAPI-compliant gateway. FAPI is crucial for Open Banking, as it ensures a higher level of security when exchanging financial data through open APIs. For example, the Consumer Data Standards in Australia mandates FAPI compliance for Open Banking initiatives.
Beyond regional regulations and specific industry verticals, IAM experts have recognized FAPI as a strong standard for enhancing API security across the board. With the release of WSO2 IS 7.0.0, you will achieve FAPI 1.0 compliance, enabling you to enhance the security of your APIs without the need for additional extensions or modifications. This compliance ensures that your API transactions meet the necessary security standards, making it a reliable choice for organizations prioritizing secure API management.
The primary challenge that FAPI aims to address is the security concerns associated with bearer tokens. There are two main security issues related to bearer tokens:
- Access Token Acquisition: Unintended parties can potentially obtain an access token by simply providing the necessary parameters to the authorization server. This highlights the need for strong verification of the consumer application requesting the token.
- Token Misuse: Once someone obtains an access token, they can use it just like the original user, which necessitates additional security validation from the resource server to prevent unauthorized access.
To tackle these issues, WSO2 Identity Server leverages key features such as:
- Mutual Transport Layer Security (MTLS): Ensures that both the client and server authenticate each other, providing a secure channel for communication.
- Private Key JWT Authentication: Enhances security by using a private key to sign JSON Web Tokens (JWTs), allowing for more secure and tamper-proof authentication.
- Proof Key for Code Exchange (PKCE): Adds an additional layer of security to the OAuth 2.0 authorization code flow, protecting against interception and authorization code attacks.
By implementing these features, WSO2 IS strengthens the security of bearer tokens, ensuring that only authorized applications can obtain and use them effectively.
Unified IAM experience across all WSO2 IAM products — SaaS, Self-Hosted and Private cloud
Regardless of the deployment type, the core functional components and UI elements of WSO2 Identity Server are shared, providing developers with a unified user experience across all platforms. Typically, customers begin their journey with the open-source self-hosted version of WSO2 IS. This open-source version receives nearly 500 downloads each month, even though downloads are restricted to corporate email addresses.
Once the product is downloaded, the first step is to explore a few key use cases within your IAM ecosystem, which will help build confidence in leveraging WSO2 IS for your specific needs. In the next step, you have multiple options: you can continue with the self-hosted version along with a WSO2 subscription, transition to a SaaS solution (like Asgardio), or opt for a Private Cloud deployment to ensure that resources are not shared across different deployments.
Thanks to the unified developer experience across these platforms, transitioning between different deployment options is seamless and straightforward.
Deployment options
In Chapter 3.0, we briefly discussed the various deployment options for WSO2 Identity Server (IS). In this chapter, we will compare the pros and cons of each deployment option to help organizations make informed decisions based on their specific needs and circumstances.

1. Self-Hosted Deployment
Pros:
- Full Control: Organizations have complete control over the deployment environment, allowing for tailored configurations and customizations.
- Data Privacy: Sensitive data remains within the organization’s infrastructure, ensuring compliance with data protection regulations.
- Cost-Effective: Depending on the scale, a self-hosted solution can be more cost-effective in the long term compared to subscription models.
Cons:
- Management Overhead: Organizations are responsible for maintaining the infrastructure, including updates, security patches, and backups.
- Resource Intensive: Requires dedicated IT resources and expertise to manage and troubleshoot the system effectively.
2. SaaS Deployment (Asgardio)
Pros:
- Ease of Use: Quick setup and minimal management responsibilities, allowing organizations to focus on core business activities.
- Scalability: SaaS solutions can easily scale with the organization’s needs without significant upfront investments in infrastructure.
- Automatic Updates: The service provider manages updates and maintenance, ensuring that the system is always up-to-date with the latest features and security patches.
Cons:
- Less Control: Organizations have limited control over configurations and customizations compared to self-hosted solutions.
- Data Security Concerns: Storing sensitive data off-site may raise security and compliance concerns for some organizations.
3. Private Cloud Deployment
Pros:
- Customization and Control: Offers more customization options compared to SaaS while still providing some level of managed service.
- Improved Security: Data remains in a controlled environment, reducing risks associated with public cloud services.
- Hybrid Capability: Can be integrated with other cloud services or on-premises solutions, providing flexibility in deployment strategies.
Cons:
- Higher Costs: Private cloud solutions can be more expensive than SaaS options due to infrastructure and management costs.
- Complex Management: Organizations may still need dedicated resources to manage and maintain the private cloud environment.
Conclusion
After reviewing the previous four chapters, you should have a solid understanding of the past, present, and future direction of WSO2 Identity Server. The release of WSO2 IS 7.0.0 marks a significant milestone, as it introduces the capability to manage not only the identities of your direct customers but also those of your partners. This advancement opens up new revenue streams for your primary business, while also allowing partners to offer Identity and Access Management platforms to their own partner organizations, creating additional business opportunities.
Furthermore, the new model for organization management features enables hierarchical structures to extend across multiple levels, ensuring that each child organization has equal access to these features.
In conclusion, if you are currently using a JDBC user store with version 6.X.X, migrating to IS 7.0.0 is relatively straightforward thanks to available migration scripts. However, if you are on an older version of WSO2 IS and utilizing an LDAP user store, you may need to follow a few extra steps to facilitate the migration process.
메타데이터
- post_id
- 8fd4bfdd88b7
- slug
- what-is-new-in-wso2-identity-7-0-0-release-8fd4bfdd88b7
- url
- https://medium.com/@oneiam/what-is-new-in-wso2-identity-7-0-0-release-8fd4bfdd88b7
- canonical_url
- https://medium.com/@oneiam/what-is-new-in-wso2-identity-7-0-0-release-8fd4bfdd88b7
- author_url
- https://medium.com/@oneiam
- status
- ok
- fetched_at
- 2026-06-27 07:40:21