Introducing the next era of Duende IdentityServer.
Validate your existing Duende IdentityServer configuration against FAPI 2.0 and OAuth 2.1 requirements and produce a conformance report to support auditing. It also provides actionable recommendations to close any gaps.

FAPI is binary. You pass or you don't. The Financial-Grade Security & Conformance add-on treats FAPI conformance as a compliance outcome, not a runtime feature. Your security team gets auditable proof and your dev team gets actionable guidance without re-architecting or leaving your .NET environment.
Inspect every server setting and registered client against OAuth 2.1 and FAPI 2.0 Security Profile requirements. Hand the resulting report to an auditor — no translation between dev assurances and audit language required.
The report doesn't just flag what failed. It tells you how to fix it, down to the configuration property. FAPI-compliant implementation becomes the guided default path, not a research project.
Install via NuGet into your existing Duende IdentityServer v8.x+ deployment. Works in self-hosted and air-gapped environments. No SaaS dependency.
One workflow and an artifact that closes the loop between your security team's requirements and your dev team's implementation. Install the add-on into your existing IdentityServer deployment, run the report, and hand the auditor an artifact that speaks for itself.



Financial-Grade Security & Conformance is available as a capability of Duende IdentityServer across eligible tiers:
Tier | Availability |
|---|---|
| Community Edition | Not available |
| Lite | Not available |
| Standard | Add-on, ~$1,500 flat fee |
| Advanced | Add-on, ~$1,500 flat fee |
| Custom | Add-on, ~$1,500 flat fee |
See the IdentityServer pricing page for full tier details.