Skip to content
cboxdkPublic

About

Cbox ID — the hosted, self-hostable identity platform app (admin console + hosted cloud) built on cboxdk/laravel-id.

Topics

Resources

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Latest commit

 

History

358 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Cbox ID

The identity platform behind cboxid.com, and the app you can run yourself. Sign-in for your apps, your customers' organizations, Enterprise SSO (SAML and OIDC), Directory Sync (SCIM), roles and permissions, API keys, App audit logs, an Admin Portal for your customers' IT admins, and a tamper-evident Audit log — every change reachable from the console, a REST API, an MCP server and the cbox CLI.

It is the deployable app built on the cboxdk/laravel-id framework, which provides the identity engine (crypto, tenancy, OAuth 2.1 and OpenID Connect, SAML, SCIM, CIBA, audit). This repository adds the consoles, the hosted pages, onboarding, the action layer and the hosted-cloud concerns.

Source-available under the Elastic License 2.0 (see License).

Quick links

Sign in to your first app Quickstarts: Next.js, React, Laravel, Nuxt, Go, Python
Understand the model Concepts, starting with Workspaces & organizations
Wire up an AI agent Agents and MCP, Actions reference
Administer an environment Admin guides
Hand a customer's IT admin a setup link Admin Portal, For IT admins
Run it yourself Self-hosting, Upgrading
Report a vulnerability SECURITY.md

All documentation starts at docs/index.md.

How it is put together

Workspace → project → environment → organizations → users. Your workspace is your own Cbox account; it owns projects (one identity product each), each project has environments (production, sandbox), and each environment is a fully isolated identity provider on its own host, holding your customers' organizations and their people. More.

Two kinds of host. The platform root (cboxid.com) serves the workspace console, the workspace and platform APIs, and one MCP server for your whole workspace. Each environment's own host (<environment>.cboxid.com, or a custom domain) is the OpenID Connect issuer your apps use, with its hosted sign-in pages, its console at /admin, its management API and its own MCP server. More.

One action, four doors. Every change the console can make is an action: one class in app/Actions declaring its name, REST route, scope, danger and input. The console, the REST API (generated from the registry), the MCP server (one tool per action at /mcp) and the cbox CLI (one command per action, built from the OpenAPI documents) all run it through the same runner: same authorization, validation, approvals, idempotency and audit entry. A key's creator can require a person's approval on their device before its dangerous actions run, and a token a person delegated always waits for them on critical ones. More.

Four planes. The management API is split by who acts over what: environment (/api/v1), workspace (/api/v1/workspace), account (/api/v1/me) and platform (/api/v1/platform). Each publishes a public OpenAPI 3.1 document, and the actions reference is generated from the same registry.

Stack

  • Laravel 13, PHP 8.5, argon2id password hashing.
  • Inertia + React 19 + Tailwind v4. Every page and every write is a Laravel route with its own middleware, and React renders the props the controller hands it. Chosen for an identity console: session-cookie auth with no tokens in the browser, one same-origin bundle, and a script-src without unsafe-inline or unsafe-eval. The console is in English; the hosted pages (sign-in, consent, the Admin Portal and their emails) are translated into six languages.
  • laravel/mcp for the MCP server; cboxdk/laravel-id for the identity engine; the first-party observability stack (laravel-telemetry, laravel-health, laravel-queue-metrics, laravel-queue-autoscale).

Run it locally

git clone https://github.com/cboxdk/cbox-id.git && cd cbox-id
composer setup          # installs deps, copies .env, creates the sqlite db, then runs
                        # `cbox-id:install`: mints the crypto master key, migrates, and
                        # creates the first operator and environment (and, in the
                        # SaaS shape, the first workspace)
composer run dev        # serve + queue + vite + logs

Sign in at /login. Back up CBOX_ID_CRYPTO_KEY somewhere separate from the database: losing it makes sealed secrets unrecoverable. The required variables are CBOX_ID_CRYPTO_KEY, CBOX_ID_ISSUER, CBOX_ID_WEBAUTHN_RP_ID and CBOX_ID_WEBAUTHN_ORIGIN, all in .env.example. No shell on the box? An empty deployment serves one page, /first-run, guarded by a setup token. See the self-hosting quickstart and, for production, Deployment.

Develop

composer run dev                                  # the app, the queue, vite and logs
vendor/bin/pest --parallel --testsuite=Unit,Feature
vendor/bin/pest --testsuite=Browser               # real-browser tests (Playwright)
vendor/bin/pint --test
vendor/bin/phpstan analyse --memory-limit=2G
php artisan openapi:build --check                 # the OpenAPI documents are current
php artisan docs:actions --check                  # so is docs/reference

Adding an action: write the class in app/Actions/<Area>/, then run php artisan openapi:build and php artisan docs:actions and commit what they write.

cbox.yaml runs it locally in production's shape (two web replicas sharing Valkey, the queue manager and the scheduler, PostgreSQL 18) with cbox-engine: cbox deploy.

Contributing and releasing

Merging to main releases to production. cboxid.com runs every commit on main whose checks have all passed — automatically, within minutes of the last check going green and its arm64 image existing, with its migrations run first. There is no separate deploy and no second approval. How the release works.

So:

  • Work on a branch and open a pull request. Never push to main directly.
  • The gate is green before you merge: the commands under Develop, and CI on the pull request. A red check on main holds every release until a newer commit passes.
  • Migrations must work with the release before them. They run while the old code is still serving, and a failed rollout returns to the old code on the new schema.
  • New configuration goes into production before the merge that needs it. Ask the operator; a release does not wait for an environment variable.
  • Changes only to Markdown or docs/ build no image and ship with the next release.

Status

Actively developed and dogfooded on cboxid.com. It composes cboxdk/laravel-id 1.x (see composer.json for the constraint). Review the security notes and SECURITY.md before running it in production, and UPGRADING.md before crossing a version.

License

Cbox ID (this application) is source-available under the Elastic License 2.0 — see LICENSE. It is not open source. You may use, copy, modify and redistribute it, with three limitations:

  • you may not provide it to third parties as a hosted or managed service that gives them substantial access to its features;
  • you may not circumvent the licence-key functionality or remove or obscure protected features;
  • you may not remove or alter any licensing, copyright or other notices.

The framework it is built on, cboxdk/laravel-id, is MIT, so building your own identity product on the framework is unrestricted. The Elastic-2.0 terms apply to this deployable app. To run Cbox ID as a managed service for your own customers, get in touch about a commercial licence.

About

Cbox ID — the hosted, self-hostable identity platform app (admin console + hosted cloud) built on cboxdk/laravel-id.

Topics

Resources

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages