Reference articles on history, science, culture and more
Encyclopedia

Apache Shiro

Open-source Java security framework

Image credit is listed at the end of this article.

Apache Shiro (pronounced "sheeroh", a Japanese word for castle (Japanese: )) is an open source software security framework that performs authentication, authorization, cryptography and session management. Shiro has been designed to be an intuitive and easy-to-use framework while still providing robust security features.

01History

Shiro's predecessor, JSecurity, was founded in 2004 by Les Hazlewood and Jeremy Haile because they could not find a suitable Java security framework that operated well at the application level and they were frustrated with JAAS. Between 2004 and 2008, JSecurity was hosted on SourceForge and its committer list grew to include Peter Ledbrook, Alan Ditzel, Tim Veil.

In 2008, JSecurity project was submitted to the Apache Software Foundation (ASF) and accepted into their Incubator Program to be stewarded by mentors in order to become a top level Apache Project. Under the ASF's Incubator, Jsecurity was renamed Ki (pronounced Key) and shortly later renamed Shiro by the community because of trademark concerns.

The project continued to grow while in the Apache Incubator, adding Kalle Korhonen as a project committer. And in July 2010, the Shiro community released its official version 1.0, marking a period of stability in the code base. Following the release of version 1.0, the Shiro community created a Project Management Committee and elected Les Hazlewood as its chair. On September 22, 2010, Shiro became a top level project (TLP) in the Apache Software Foundation.

Between 2010 and 2023, Brian Demers, François Papon and Benjamin Marwell maintained the project, and added the foundation for new cryptographic APIs and support for stronger password encryption, such as Argon2 and BCrypt.

In 2023, Brian Demers left Okta, which stopped financially supporting Apache Shiro, leaving project maintenance to volunteers only.

In July 2025, Lenny Primak was elected Apache Shiro PMC chair. As a CTO of Flow Logix, Inc. he donated his time to the project since 2012. Lenny was instrumental in getting Shiro 2.0.0 and Shiro 3.0.0 completed.

FlowLogix and Lenny contributed Jakata EE support, Spring 7, Spring Boot 4 support, and unique features such as form save / resubmit support

02Releases

  • 3.0.0 on 2026-06-29 (current stable release)
  • 2.0.5 on 2025-07-07
  • 2.0.4 on 2025-04-20
  • 2.0.3 on 2025-04-06
  • 2.0.2 on 2024-11-13
  • 2.0.1 on 2024-05-30
  • 2.0.0 on 2024-02-28
  • 1.13.0 on 2024-11-13
  • 1.12.0 on 2023-07-18
  • 1.11.0 on 2023-01-13
  • 1.10.1 on 2022-11-19
  • 1.10.0 on 2022-10-10
  • 1.9.1 on 2022-06-28
  • 1.9.0 on 2022-03-22
  • 1.8.0 on 2021-08-26
  • 1.7.1 on 2021-01-31
  • 1.7.0 on 2020-10-29
  • 1.6.0 on 2020-08-17
  • 1.5.3 on 2020-05-03
  • 1.5.2 on 2020-03-23
  • 1.5.1 on 2020-02-23
  • 1.5.0 on 2020-01-24
  • 1.4.2 on 2019-11-18
  • 1.4.1 on 2019-04-18
  • 1.4.0 on 2017-05-05
  • 1.3.2 on 2016-09-11
  • 1.3.1 on 2016-08-29
  • 1.3.0 on 2016-07-25
  • 1.2.6 on 2016-06-28
  • 1.2.5 on 2016-05-24
  • 1.2.4 on 2015-07-07
  • 1.2.3 on 2014-02-25
  • 1.2.2 on 2013-05-15
  • 1.2.1 on 2012-07-28
  • 1.2.0 on 2012-01-24
  • 1.1.0 on 2010-11-01
Watch videos about Apache ShiroExplainers and documentaries on YouTube (opens in a new tab)

Sources and credits

This article is adapted from the Wikipedia article Apache Shiro, written by its contributors and licensed under CC BY-SA 4.0. Fathomly has changed the layout, removed citation markers, navigation and maintenance notices, and adjusted punctuation. This adapted version is shared under the same license. For references, see the original article.

Images, from Wikimedia Commons:

Fathomly is not affiliated with or endorsed by the Wikimedia Foundation. Spotted a problem? Tell us.