Skip to content
CAI
Produce a survey ↗Verify a survey

dromara/Sa-Token

Sa-Token is a comprehensive Java security framework designed to simplify the implementation of authentication, authorization, and session management in web and distributed applications. It provides a unified API for handling login states, role and permission checks, and various authentication schemes including HTTP Basic/Digest, OAuth2, JWT, and API keys. The system supports flexible session storage via Redis, Caffeine, or in-memory caches, and integrates seamlessly with major frameworks like Spring Boot, Dubbo, and gRPC to manage security contexts across different environments.

26.0

Weak · 6 August 2026

73k

lines of production code

Java

with JavaScript

1

bus factor · 159 authors in all

3

measurements over time

CAI band scale
CAI trend line

How it got here

2020–2021 · core architecture and framework integrations

This period focused on restructuring the Sa-Token framework into a multi-module Maven architecture and introducing a comprehensive set of core features, including annotation-based security, session management, and a centralized strategy pattern. It also expanded ecosystem support by adding starters and plugins for Spring Boot, WebFlux, Solon, Jboot, and JFinal, alongside new capabilities like temporary tokens and standalone Redis caching.

53 changes

2022–2023 · Spring Boot 3 and Jakarta migration

This period focused on modernizing the framework for Spring Boot 3 and Jakarta EE, introducing new starters, auto-configuration, and compatibility checks. It also expanded the library's capabilities with gRPC, Dubbo, and WebFlux integrations, while significantly broadening the range of demo applications to cover OAuth2, SSO, and various frontend frameworks.

65 changes

2024–2025 · Plugin ecosystem and HTTP abstraction

This period focused on expanding the framework's capabilities through a modular plugin architecture, introducing new authentication methods like HTTP Basic, Digest, and API Keys. The team also standardized the HTTP client abstraction and added diverse serialization and cache implementations to support various storage and template engines.

61 changes

2026 · Spring Boot 4 and Reactor support

This period focused on extending Sa-Token compatibility to Spring Boot 4 and reactive WebFlux environments, introducing dedicated starters, filters, and demo applications for these stacks. The team also added a new Jackson 3 JSON parser plugin and implemented access control features for documentation, alongside general test coverage improvements.

12 changes

CAI lens gauges

Survey your own repository

dromara/Sa-Token was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point the surveyor at a repository you know and see whether you agree with it.

Survey a repository

About this page

  • The description of this project is derived from its own commit history, not from its README.
  • The score is its highest published measurement, taken on 6 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit c4181820a4 — the exact code this score is about.
  • Scored under rubric rubric-2026.08.19. Score the same commit under that rubric and you get the same number.
CAI link cards