The identity platform behind cboxid.com, and the app you can run
yourself. Sign-in for your apps, your customers' organizations, Enterprise SSO (SAML and
OIDC), Directory Sync (SCIM), roles and permissions, API keys, App audit logs, an Admin
Portal for your customers' IT admins, and a tamper-evident Audit log — every change
reachable from the console, a REST API, an MCP server and the cbox CLI.
It is the deployable app built on the cboxdk/laravel-id
framework, which provides the identity engine (crypto, tenancy, OAuth 2.1 and OpenID
Connect, SAML, SCIM, CIBA, audit). This repository adds the consoles, the hosted pages,
onboarding, the action layer and the hosted-cloud concerns.
Source-available under the Elastic License 2.0 (see License).
| Sign in to your first app | Quickstarts: Next.js, React, Laravel, Nuxt, Go, Python |
| Understand the model | Concepts, starting with Workspaces & organizations |
| Wire up an AI agent | Agents and MCP, Actions reference |
| Administer an environment | Admin guides |
| Hand a customer's IT admin a setup link | Admin Portal, For IT admins |
| Run it yourself | Self-hosting, Upgrading |
| Report a vulnerability | SECURITY.md |
All documentation starts at docs/index.md.
Workspace → project → environment → organizations → users. Your workspace is your own Cbox account; it owns projects (one identity product each), each project has environments (production, sandbox), and each environment is a fully isolated identity provider on its own host, holding your customers' organizations and their people. More.
Two kinds of host. The platform root (cboxid.com) serves the workspace console, the
workspace and platform APIs, and one MCP server for your whole workspace. Each
environment's own host (<environment>.cboxid.com, or a custom domain) is the OpenID
Connect issuer your apps use, with its hosted sign-in pages, its console at /admin, its
management API and its own MCP server. More.
One action, four doors. Every change the console can make is an action: one class in
app/Actions declaring its name, REST route, scope, danger and input. The console, the
REST API (generated from the registry), the MCP server (one tool per action at /mcp) and
the cbox CLI (one command per action, built from the OpenAPI documents) all run it
through the same runner: same authorization, validation, approvals, idempotency and audit
entry. A key's creator can require a person's approval on their device before its
dangerous actions run, and a token a person delegated always waits for them on critical
ones. More.
Four planes. The management API is split by who acts over what: environment
(/api/v1), workspace (/api/v1/workspace), account (/api/v1/me) and platform
(/api/v1/platform). Each publishes a public OpenAPI 3.1 document, and the
actions reference is generated from the same registry.
- Laravel 13, PHP 8.5, argon2id password hashing.
- Inertia + React 19 + Tailwind v4. Every page and every write is a Laravel route with
its own middleware, and React renders the props the controller hands it. Chosen for an
identity console: session-cookie auth with no tokens in the browser, one same-origin
bundle, and a
script-srcwithoutunsafe-inlineorunsafe-eval. The console is in English; the hosted pages (sign-in, consent, the Admin Portal and their emails) are translated into six languages. laravel/mcpfor the MCP server;cboxdk/laravel-idfor the identity engine; the first-party observability stack (laravel-telemetry,laravel-health,laravel-queue-metrics,laravel-queue-autoscale).
git clone https://github.com/cboxdk/cbox-id.git && cd cbox-id
composer setup # installs deps, copies .env, creates the sqlite db, then runs
# `cbox-id:install`: mints the crypto master key, migrates, and
# creates the first operator and environment (and, in the
# SaaS shape, the first workspace)
composer run dev # serve + queue + vite + logsSign in at /login. Back up CBOX_ID_CRYPTO_KEY somewhere separate from the database:
losing it makes sealed secrets unrecoverable. The required variables are CBOX_ID_CRYPTO_KEY,
CBOX_ID_ISSUER, CBOX_ID_WEBAUTHN_RP_ID and CBOX_ID_WEBAUTHN_ORIGIN, all in
.env.example. No shell on the box? An empty deployment serves one page, /first-run,
guarded by a setup token. See the self-hosting quickstart
and, for production, Deployment.
composer run dev # the app, the queue, vite and logs
vendor/bin/pest --parallel --testsuite=Unit,Feature
vendor/bin/pest --testsuite=Browser # real-browser tests (Playwright)
vendor/bin/pint --test
vendor/bin/phpstan analyse --memory-limit=2G
php artisan openapi:build --check # the OpenAPI documents are current
php artisan docs:actions --check # so is docs/referenceAdding an action: write the class in app/Actions/<Area>/, then run
php artisan openapi:build and php artisan docs:actions and commit what they write.
cbox.yaml runs it locally in production's shape (two web replicas sharing Valkey, the
queue manager and the scheduler, PostgreSQL 18) with
cbox-engine: cbox deploy.
Merging to
mainreleases to production. cboxid.com runs every commit onmainwhose checks have all passed — automatically, within minutes of the last check going green and its arm64 image existing, with its migrations run first. There is no separate deploy and no second approval. How the release works.
So:
- Work on a branch and open a pull request. Never push to
maindirectly. - The gate is green before you merge: the commands under Develop, and CI on
the pull request. A red check on
mainholds every release until a newer commit passes. - Migrations must work with the release before them. They run while the old code is still serving, and a failed rollout returns to the old code on the new schema.
- New configuration goes into production before the merge that needs it. Ask the operator; a release does not wait for an environment variable.
- Changes only to Markdown or
docs/build no image and ship with the next release.
Actively developed and dogfooded on cboxid.com. It composes
cboxdk/laravel-id 1.x (see composer.json for the constraint). Review the
security notes and SECURITY.md before running it in
production, and UPGRADING.md before crossing a version.
Cbox ID (this application) is source-available under the Elastic License 2.0 — see LICENSE. It is not open source. You may use, copy, modify and redistribute it, with three limitations:
- you may not provide it to third parties as a hosted or managed service that gives them substantial access to its features;
- you may not circumvent the licence-key functionality or remove or obscure protected features;
- you may not remove or alter any licensing, copyright or other notices.
The framework it is built on, cboxdk/laravel-id, is
MIT, so building your own identity product on the framework is unrestricted. The
Elastic-2.0 terms apply to this deployable app. To run Cbox ID as a managed service for your
own customers, get in touch about a commercial licence.