7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

6 alternatives ranked by real activity

Open-source Amazon Cognito alternatives

A curated, ranked list of the 6 best open-source alternatives to Amazon Cognito.

The best open-source alternative to Amazon Cognito is SuperTokens. If that doesn't suit you, other good options are ZITADEL, Ory Hydra, Supabase Auth and Authgear.

Amazon Cognito alternatives are mainly auth & identity tools. 5 of them shipped code in the last 30 days, 6 can be self-hosted, and 4 use a permissive licence.

Last updated October 2, 2026 · ranked by GitHub stars, growth and recent commits

SuperTokens

An open-source authentication provider offering login, session management, MFA and multi-tenancy through frontend and backend SDKs and a Java core service.

GitHub stars
15k
Last commit
yesterday
Latest release
v12.2.0
Self-hosted
Yes
Hosted version
Available
supertokens.comSuperTokens homepage screenshot

SuperTokens is an open-source authentication provider positioned as an alternative to Auth0, Firebase Auth and AWS Cognito. It adds secure login and session management to your apps, with SDKs for popular languages and frameworks such as Node.js, Go, Python, React and React Native.

Its architecture has three building blocks: a frontend SDK that manages session tokens and renders login UI widgets, a backend SDK that provides the APIs for sign-up, sign-in, sign-out and session refreshing, and the SuperTokens Core, an HTTP service in Java that implements the authentication logic and database operations used by the backend SDK. The feature list spans passwordless and social sign-in, email and phone with password, session handling, MFA, multi-tenant organizations with enterprise SSO, user roles, authentication between microservices, and a dashboard for managing users.

You can self-host the core to keep user data in your own database, or use the vendor's managed offering. The repository's license is listed as 'Other' on GitHub, because enterprise features sit under a separate license, so check which features you need. It suits teams that want to own authentication without building it from scratch.

Key features

  • Email-password, passwordless and social login
  • Session management with token refresh
  • Multi-factor authentication support
  • Multi-tenancy and enterprise SSO
  • User roles and microservice authentication
  • User management dashboard

Pricing: Self-hosting is free at any scale. The managed cloud is free below 5K monthly active users, then $0.02 per active user per month, plus optional paid add-ons.

Read more about SuperTokensWebsite GitHub

ZITADEL

An open-source identity and access management platform with SSO, MFA, passkeys, OIDC, SAML, SCIM and native multi-tenancy, available self-hosted or as a cloud service.

GitHub stars
15k
Last commit
today
Latest release
v4.19.4
Licence
AGPL-3.0
Self-hosted
Yes
Hosted version
Available
zitadel.comZITADEL homepage screenshot

ZITADEL is an identity and access management platform, open source, for teams that need more than basic login. It targets SaaS products, B2B platforms and self-hosted IAM stacks, and bundles single sign-on, multi-factor authentication, passkeys, OIDC, SAML and SCIM in an API-first design, with an emphasis on a mature multi-tenancy model.

A comparison table in the README sets it against FusionAuth, Keycloak and Auth0 or Okta on points such as open-source status, self-hosting, infrastructure-level tenants, native B2B organizations and a comprehensive event-stream audit trail. Topics list standards and features including OAuth 2, OpenID Connect, FIDO2, 2FA and passkeys. The positioning is that you can own the identity layer without vendor lock-in while still getting a polished product.

ZITADEL is written in Go and licensed under AGPL-3.0, with a website, chat, docs and blog. You can run it yourself or use the vendor's managed cloud. It suits developers and security teams building multi-tenant applications who want a self-hostable alternative to commercial identity providers.

Key features

  • Single sign-on with OIDC and SAML
  • Multi-factor authentication and passkeys
  • SCIM user provisioning support
  • Native multi-tenancy with B2B organizations
  • Event-stream audit trail
  • API-first, self-hostable design

Pricing: Free cloud plan for 100 daily active users. Pro costs $100 per month and includes 25,000 daily active users; Enterprise is custom and can run on your own infrastructure.

Read more about ZITADELWebsite GitHub

Ory Hydra

Ory Hydra is a certified OAuth 2.0 and OpenID Connect server that plugs into your existing user management through headless APIs, self-hosted or hosted.

GitHub stars
18k
Last commit
2 mo ago
Latest release
v26.2.0
Licence
Apache-2.0
Self-hosted
Yes
Hosted version
Available
ory.comOry Hydra homepage screenshot

Ory Hydra is an OAuth 2.0 authorization server and an implementation of OpenID Connect Core 1.0. It is designed as a standalone server without user management, so it connects to whatever identity provider you already use through a login and consent app, leaving you in control of the user interface.

It handles OAuth 2.0 and OpenID Connect flows, issues and validates tokens, manages clients, orchestrates login and consent flows and manages JWKS. The project says it is tuned for low latency and high throughput with modest resource use, and it is OpenID Certified. It works with any authentication endpoint, including Ory Kratos, and belongs to an ecosystem that also includes Oathkeeper for access proxying and Keto for access control policies.

Hydra is written in Go and licensed under Apache-2.0. You can consume it as a managed service on Ory Network or self-host it, and a quickstart, documentation and telemetry notes are provided in the repository.

Key features

  • OAuth 2.0 and OpenID Connect server
  • Token issuance and validation
  • Client management
  • Login and consent flow orchestration
  • JWKS management
  • Headless APIs for any identity provider

Pricing: Ory Network has a free Developer plan. Production is $770 and Growth $9350 per year plus usage fees; Enterprise and the self-hosted license are quoted.

Read more about Ory HydraWebsite GitHub

Supabase Auth

Go-based user management and authentication server from Supabase that issues JWTs and supports email, passwordless, phone, and social sign-in.

GitHub stars
2.6k
Last commit
yesterday
Latest release
v2.197.0
Licence
MIT
Self-hosted
Yes
Hosted version
Available
supabase.comSupabase Auth homepage screenshot

Supabase Auth is an authentication and user management server written in Go. It powers Supabase's sign-in features by issuing JSON Web Tokens that downstream services, such as PostgREST with Row Level Security, can trust. It started from Netlify's GoTrue codebase, but both projects have diverged significantly. It is released under the MIT license.

Supported sign-in methods include email and password, magic links, phone numbers, and external providers such as Google, Apple, Facebook, and Discord. The server exposes an HTTP API for managing users and sessions, and its configuration is handled through environment variables in a .env file, with an example file provided.

The README walks through a quick start using a local Postgres database and has sections on running in production, configuration, and endpoints. The service can be used as part of the Supabase hosted platform or run on its own, which suits teams that want an open-source JWT-based identity service they can host themselves.

Key features

  • JWT issuing for application sessions
  • Email and password sign-in
  • Magic link and phone number login
  • OAuth providers such as Google and Apple
  • User management API
  • Row Level Security integration with PostgREST

Pricing: Free and open source under the MIT license; it is also available through the hosted Supabase platform.

Authgear

Open-source customer authentication platform offering passkeys, SSO, MFA, passwordless login, and biometric sign-in, available self-hosted or as Authgear Cloud.

GitHub stars
2.1k
Last commit
today
Latest release
2026-09-23.0
Licence
Apache-2.0
Self-hosted
Yes
Hosted version
Available
authgear.comAuthgear homepage screenshot

Authgear is an open-source authentication solution for consumer-facing applications, presented as an alternative to Auth0, Keycloak, Clerk, and Firebase Auth. It is written in Go and released under the Apache-2.0 license, and can be self-hosted or used on Authgear Cloud. SDKs and a management portal help developers get started in a few minutes.

Out-of-the-box features include passwordless login through magic link or one-time codes over email, SMS, and WhatsApp, passkeys, pre-built sign-up, login, and account settings pages, biometric login on iOS and Android, and two-factor authentication with TOTP, SMS, or email. It supports OIDC, OAuth 2.0, and SAML for SSO, enterprise connections such as ADFS and LDAP, and security features like audit logs, brute-force protection, and rate limits.

The Authgear Portal provides a web interface for user management and configuration, and an Admin API in GraphQL manages resources programmatically. It suits SaaS products and multi-app ecosystems that need flexible authentication without building it themselves.

Key features

  • Passkeys and passwordless login
  • Pre-built login, signup, and account pages
  • Biometric login on iOS and Android
  • TOTP, SMS, and email two-factor authentication
  • OIDC, OAuth 2.0, and SAML single sign-on
  • Admin portal and GraphQL Admin API
  • Audit logs and brute-force protection

Pricing: A free plan includes unlimited MAUs. Developers costs $50 and Business $500 per month, with a 30-day money-back guarantee; Enterprise is custom and the software can also be self-hosted.

Read more about AuthgearWebsite GitHub

Authorizer

Self-hosted authentication and authorization server with OAuth2/OIDC, social login, MFA, magic links, and RBAC that works with more than a dozen database backends.

GitHub stars
2.1k
Last commit
4 days ago
Latest release
2.4.1
Licence
Apache-2.0
Self-hosted
Yes
authorizer.devAuthorizer homepage screenshot

Authorizer is an open-source authentication and authorization server written in Go that you can host yourself. Its pitch is that you bring your own database and stay in control of user data. It supports more than 13 backends, including Postgres, MySQL, SQLite, SQL Server, MariaDB, Cassandra, ScyllaDB, MongoDB, ArangoDB, DynamoDB, and Couchbase. It is released under the Apache-2.0 license.

From one place it offers OAuth 2.0 and OpenID Connect, social login, multi-factor authentication, magic links, role-based access control, webhooks, and email templates, and it ships with a built-in login page and an admin panel. Version 2 is configured entirely through command-line arguments and does not read .env files or operating system environment variables.

You can run it as a Docker image or micro-service in your own infrastructure, or deploy it quickly on Railway. It suits developers who want a hosted-auth style experience without lock-in and with a choice of database.

Key features

  • OAuth 2.0 and OpenID Connect provider
  • Social login and magic links
  • Multi-factor authentication
  • Role-based access control
  • Built-in login page and admin panel
  • 13+ database backends
  • Webhooks and email templates

Pricing: Free and open source under the Apache-2.0 license.

Read more about AuthorizerWebsite GitHub

Amazon Cognito alternatives: questions

What is the best open-source alternative to Amazon Cognito?
SuperTokens is the top-ranked open-source alternative to Amazon Cognito on Enlisted: An open-source authentication provider offering login, session management, MFA and multi-tenancy through frontend and backend SDKs and a Java core service. Other strong options are ZITADEL, Ory Hydra, Supabase Auth and Authgear.
Are these Amazon Cognito alternatives free?
All 6 are open source, so the code is free to use under its licence, and all of them can be self-hosted on your own server or computer. 5 also offer a paid or managed cloud version if you'd rather not host it yourself.
How is this list of Amazon Cognito alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 5 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all