dromara/Sa-Token
Sa-Token is a comprehensive Java security framework designed to simplify the implementation of authentication, authorization, and session management in web and distributed applications. It provides a unified API for handling login states, role and permission checks, and various authentication schemes including HTTP Basic/Digest, OAuth2, JWT, and API keys. The system supports flexible session storage via Redis, Caffeine, or in-memory caches, and integrates seamlessly with major frameworks like Spring Boot, Dubbo, and gRPC to manage security contexts across different environments.
26.0
Weak · 6 August 2026
73k
lines of production code
Java
with JavaScript
1
bus factor · 159 authors in all
3
measurements over time
How it got here
2020–2021 · core architecture and framework integrations
This period focused on restructuring the Sa-Token framework into a multi-module Maven architecture and introducing a comprehensive set of core features, including annotation-based security, session management, and a centralized strategy pattern. It also expanded ecosystem support by adding starters and plugins for Spring Boot, WebFlux, Solon, Jboot, and JFinal, alongside new capabilities like temporary tokens and standalone Redis caching.
53 changes
2022–2023 · Spring Boot 3 and Jakarta migration
This period focused on modernizing the framework for Spring Boot 3 and Jakarta EE, introducing new starters, auto-configuration, and compatibility checks. It also expanded the library's capabilities with gRPC, Dubbo, and WebFlux integrations, while significantly broadening the range of demo applications to cover OAuth2, SSO, and various frontend frameworks.
65 changes
2024–2025 · Plugin ecosystem and HTTP abstraction
This period focused on expanding the framework's capabilities through a modular plugin architecture, introducing new authentication methods like HTTP Basic, Digest, and API Keys. The team also standardized the HTTP client abstraction and added diverse serialization and cache implementations to support various storage and template engines.
61 changes
2026 · Spring Boot 4 and Reactor support
This period focused on extending Sa-Token compatibility to Spring Boot 4 and reactive WebFlux environments, introducing dedicated starters, filters, and demo applications for these stacks. The team also added a new Jackson 3 JSON parser plugin and implemented access control features for documentation, alongside general test coverage improvements.
12 changes
Survey your own repository
dromara/Sa-Token was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point the surveyor at a repository you know and see whether you agree with it.
About this page
- The description of this project is derived from its own commit history, not from its README.
- The score is its highest published measurement, taken on 6 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit c4181820a4 — the exact code this score is about.
- Scored under rubric rubric-2026.08.19. Score the same commit under that rubric and you get the same number.