7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

20 alternatives ranked by real activity

Open-source Auth0 alternatives

A curated, ranked list of the 20 best open-source alternatives to Auth0.

The best open-source alternative to Auth0 is Keycloak. If that doesn't suit you, other good options are Authentik, SuperTokens, ZITADEL and Logto.

Auth0 alternatives are mainly auth & identity tools. 16 of them shipped code in the last 30 days, 20 can be self-hosted, and 14 use a permissive licence.

Last updated October 2, 2026 · ranked by GitHub stars, growth and recent commits

Keycloak

Keycloak is an open-source identity and access management server that adds single sign-on, user management and authorization to applications.

GitHub stars
37k
Last commit
today
Latest release
26.8.0
Licence
Apache-2.0
Self-hosted
Yes
keycloak.orgKeycloak homepage screenshot

Keycloak is an open-source identity and access management server. It lets application teams add authentication and secure services without building their own login system, since Keycloak handles storing users and authenticating them. The project is written in Java, released under the Apache-2.0 license and governed under the Cloud Native Computing Foundation code of conduct.

Keycloak supports standard protocols such as OpenID Connect and SAML, and offers user federation, strong authentication, user management and fine-grained authorization. You can run it from the downloadable distribution using a start-dev command, or use the official Docker image published on Quay for containers and Kubernetes setups. The project provides documentation, a user mailing list and community channels for help, along with guidance for building and testing from source.

Key features

  • Single sign-on with OpenID Connect and SAML
  • User federation with external directories
  • Strong and multi-step authentication options
  • Central user and account management
  • Fine-grained authorization policies
  • Docker image and standalone distribution

Pricing: Free and open source under the Apache-2.0 license; you host and operate it yourself.

Authentik

An open-source identity provider for single sign-on that supports SAML, OAuth2 and OIDC, LDAP and RADIUS, built for self-hosting from home labs to large clusters.

GitHub stars
26k
Last commit
today
Latest release
version/2026.8.3
Self-hosted
Yes
goauthentik.ioAuthentik homepage screenshot

authentik is an open-source Identity Provider for modern single sign-on. It supports SAML, OAuth2 and OpenID Connect, LDAP, RADIUS and more, and is designed for self-hosting at any scale, from a small lab to production clusters. A reverse-proxy mode also lets it protect applications that lack native SSO support.

The project positions its enterprise offering as a way for organizations to replace incumbent identity providers (Okta, Auth0, Entra ID or Ping Identity) in large-scale identity management. For installation, Docker Compose is recommended for small and test setups, a Helm chart for Kubernetes suits larger setups, and official templates exist for AWS CloudFormation and a one-click DigitalOcean Marketplace app.

The codebase is mostly Python with Kubernetes tooling, and the license is listed as 'Other' on GitHub because it mixes open-source and enterprise components, so check which features fall under which terms. authentik is a common choice for self-hosters and companies who want to centralize logins across internal tools without paying per-user fees to a hosted identity vendor.

Key features

  • SAML and OAuth2/OIDC provider
  • LDAP and RADIUS support
  • Reverse-proxy authentication for apps
  • Docker Compose and Helm chart installs
  • AWS CloudFormation and DigitalOcean templates
  • Enterprise edition for large deployments

Pricing: The open-source edition is free. Enterprise costs $5 per user per month billed annually, plus $0.02 per external user; Enterprise Plus starts at $20k per year. No hosted version is offered.

SuperTokens

An open-source authentication provider offering login, session management, MFA and multi-tenancy through frontend and backend SDKs and a Java core service.

GitHub stars
15k
Last commit
today
Latest release
v12.2.0
Self-hosted
Yes
Hosted version
Available
supertokens.comSuperTokens homepage screenshot

SuperTokens is an open-source authentication provider positioned as an alternative to Auth0, Firebase Auth and AWS Cognito. It adds secure login and session management to your apps, with SDKs for popular languages and frameworks such as Node.js, Go, Python, React and React Native.

Its architecture has three building blocks: a frontend SDK that manages session tokens and renders login UI widgets, a backend SDK that provides the APIs for sign-up, sign-in, sign-out and session refreshing, and the SuperTokens Core, an HTTP service in Java that implements the authentication logic and database operations used by the backend SDK. The feature list spans passwordless and social sign-in, email and phone with password, session handling, MFA, multi-tenant organizations with enterprise SSO, user roles, authentication between microservices, and a dashboard for managing users.

You can self-host the core to keep user data in your own database, or use the vendor's managed offering. The repository's license is listed as 'Other' on GitHub, because enterprise features sit under a separate license, so check which features you need. It suits teams that want to own authentication without building it from scratch.

Key features

  • Email-password, passwordless and social login
  • Session management with token refresh
  • Multi-factor authentication support
  • Multi-tenancy and enterprise SSO
  • User roles and microservice authentication
  • User management dashboard

Pricing: Self-hosting is free at any scale. The managed cloud is free below 5K monthly active users, then $0.02 per active user per month, plus optional paid add-ons.

ZITADEL

An open-source identity and access management platform with SSO, MFA, passkeys, OIDC, SAML, SCIM and native multi-tenancy, available self-hosted or as a cloud service.

GitHub stars
15k
Last commit
today
Latest release
v4.19.4
Licence
AGPL-3.0
Self-hosted
Yes
Hosted version
Available
zitadel.comZITADEL homepage screenshot

ZITADEL is an identity and access management platform, open source, for teams that need more than basic login. It targets SaaS products, B2B platforms and self-hosted IAM stacks, and bundles single sign-on, multi-factor authentication, passkeys, OIDC, SAML and SCIM in an API-first design, with an emphasis on a mature multi-tenancy model.

A comparison table in the README sets it against FusionAuth, Keycloak and Auth0 or Okta on points such as open-source status, self-hosting, infrastructure-level tenants, native B2B organizations and a comprehensive event-stream audit trail. Topics list standards and features including OAuth 2, OpenID Connect, FIDO2, 2FA and passkeys. The positioning is that you can own the identity layer without vendor lock-in while still getting a polished product.

ZITADEL is written in Go and licensed under AGPL-3.0, with a website, chat, docs and blog. You can run it yourself or use the vendor's managed cloud. It suits developers and security teams building multi-tenant applications who want a self-hostable alternative to commercial identity providers.

Key features

  • Single sign-on with OIDC and SAML
  • Multi-factor authentication and passkeys
  • SCIM user provisioning support
  • Native multi-tenancy with B2B organizations
  • Event-stream audit trail
  • API-first, self-hostable design

Pricing: Free cloud plan for 100 daily active users. Pro costs $100 per month and includes 25,000 daily active users; Enterprise is custom and can run on your own infrastructure.

Logto

Open-source identity infrastructure that adds sign-in, enterprise SSO and role-based access control to SaaS and AI products, using OIDC and OAuth 2.1 standards.

GitHub stars
15k
Last commit
yesterday
Latest release
v1.44.0
Licence
MPL-2.0
Self-hosted
Yes
Hosted version
Available
logto.ioLogto homepage screenshot

Logto is an open-source identity platform that handles sign-in, sign-up and access control so product teams do not have to build them from scratch. It is built on OpenID Connect and OAuth 2.1, with SAML also supported, and is aimed at SaaS products and AI or agent-based platforms that need production-ready authentication.

Out of the box it provides multi-tenancy and organizations with member invites and role-based access, enterprise SSO, and prebuilt sign-in flows with a customizable interface. Sign-in options include social login, passwordless methods, MFA and Google One Tap, and it can connect to external identity providers such as Google, Azure AD and Okta. SDKs cover more than 30 frameworks, among them React, Next.js, Angular, Vue, Flutter, Go and Python.

The core is licensed under MPL-2.0 and can be self-hosted by following the OSS installation guide or run locally for development. Logto Cloud offers the same product as a fully managed service. The project also advertises support for the Model Context Protocol and agent-style AI architectures.

Key features

  • OIDC, OAuth 2.1 and SAML support
  • Multi-tenancy with organization RBAC
  • Enterprise single sign-on
  • Prebuilt, customizable sign-in flows
  • Social login, passwordless and MFA
  • SDKs for over 30 frameworks
  • Machine-to-machine access for APIs and CLIs

Pricing: Free cloud plan for up to 50,000 MAU. Pro starts at $24 per month plus token usage and add-ons; Enterprise is quoted, and self-hosting is available.

Casdoor

An open-source identity and access management platform written in Go, providing single sign-on, OAuth, OIDC, SAML, MFA and a web console for users and applications.

GitHub stars
15k
Last commit
today
Latest release
v4.13.0
Licence
Apache-2.0
Self-hosted
Yes
casdoor.aiCasdoor homepage screenshot

Casdoor is a self-hosted identity and access management platform with a web console. It acts as a single sign-on and authentication server, so applications can delegate login to it instead of implementing their own user management, sessions and password handling.

Supported protocols include OIDC, OAuth 2.0, SAML 2.0, LDAP, CAS and SCIM 2.0, alongside WebAuthn, TOTP and MCP, and it can connect to identity providers such as Google Workspace, Microsoft Entra ID and GitHub. Sign-in options include passwords, email or SMS codes, WebAuthn and Face ID, plus any social providers you enable. The admin console covers users, tokens, organizations, providers and applications, and settings change without a redeploy or config file.

Casdoor is written in Go and licensed under Apache-2.0. A quick trial runs on SQLite with sample data and needs no separate database or config file. Its newer positioning emphasizes AI agents, with an MCP and agent gateway for LLM tooling, and hosted demo instances are available for trying it before installing.

Key features

  • Single sign-on and authentication server
  • OIDC, OAuth 2.0 and SAML support
  • LDAP, CAS and SCIM integration
  • WebAuthn, TOTP and MFA
  • Social and enterprise identity providers
  • Web console for users and organizations
  • MCP and agent gateway features

Pricing: Free and open source under the Apache-2.0 licence.

Dex

Federated OpenID Connect and OAuth 2.0 identity provider that fronts LDAP, SAML and social logins through pluggable connectors.

GitHub stars
11k
Last commit
yesterday
Latest release
v2.45.1
Licence
Apache-2.0
Self-hosted
Yes
dexidp.ioDex homepage screenshot

Dex is an identity service that uses OpenID Connect to handle authentication for other applications. Rather than storing users itself, it acts as a portal to other identity providers through connectors, so apps only need to implement one authentication flow and let Dex deal with each backend's protocol.

Connectors let it defer login to LDAP servers, SAML providers, and established providers such as GitHub, Google and Active Directory. Its primary output is the ID Token, a JSON Web Token signed by Dex that states which client logged the user in, when the token expires and who the user is. Because these tokens follow standard claims, other services such as Kubernetes and AWS STS can consume them.

Dex runs natively on Kubernetes using Custom Resource Definitions and can drive API server authentication through the OpenID Connect plugin, with clients like kubelogin and kubectl logging users in through any supported provider. The project is written in Go, licensed under Apache-2.0, and you deploy and operate it yourself.

Key features

  • OpenID Connect and OAuth 2.0 provider
  • Pluggable connectors for LDAP, SAML and GitHub
  • Signed ID Tokens as JSON Web Tokens
  • Runs on Kubernetes with custom resources
  • Kubernetes API server authentication
  • Works with kubelogin and kubectl

Pricing: Free and open source under the Apache-2.0 license.

Pocket ID

A simple self-hosted identity provider for OpenID Connect and OAuth 2.0 that signs users in to your apps with passkeys only, without passwords.

GitHub stars
9.4k
Last commit
yesterday
Latest release
v2.17.0
Licence
BSD-2-Clause
Self-hosted
Yes
pocket-id.orgPocket ID homepage screenshot

Pocket ID is a self-hosted identity provider that speaks OpenID Connect and OAuth 2.0 and is described as OpenID Connect certified. Users sign in to your applications with passkeys, so there are no passwords to store, reset or leak, and a hardware key such as a YubiKey can unlock all of your self-hosted services.

Its goal is simplicity. The author notes that existing self-hosted providers like Keycloak or ORY Hydra are often too complex for simple use cases, and Pocket ID aims to be easy to set up and use. The distinctive design choice is that it supports only passkey authentication, which the project argues is the future, and a demo is available to try it.

The recommended installation is Docker, with a setup guide in the documentation. Pocket ID is written in Go and released under the BSD 2-Clause licence. It suits homelab users and small teams who want single sign-on across self-hosted applications without administering a heavyweight identity system.

Key features

  • OpenID Connect and OAuth 2.0 provider
  • Passkey-only sign-in for users
  • No passwords to manage
  • Hardware key sign-in such as YubiKey
  • Recommended setup with Docker
  • Lightweight Go server

Pricing: Free and open source under the BSD 2-Clause licence.

Hanko

An open-source authentication and user management service built around passkeys, with MFA, social login, SAML SSO and web components, self-hosted or on Hanko Cloud.

GitHub stars
9k
Last commit
today
Latest release
backend/v3.1.0
Self-hosted
Yes
Hosted version
Available
hanko.ioHanko homepage screenshot

Hanko is an authentication and user management solution released as open source, framework-agnostic and designed around privacy-first principles such as data minimalism and phishing resistance. It is presented as an alternative to Auth0, Clerk, WorkOS and Stytch, written in Go, with an API-first and lightweight design.

It supports modern sign-in methods including passwords, email passcodes, passkeys, MFA with TOTP and security keys, social logins such as Apple, Google and GitHub, custom OIDC and OAuth connections and SAML enterprise SSO. Configuration is flexible, for example passkey-only or OAuth-only setups, and passwords can be deletable by users. Hanko Elements web components make integration quick, a JS SDK is available, webhooks and server-side sessions with remote revocation are included, and a full API supports custom front ends. Organizations, roles and permissions plus mobile SDKs are on the roadmap.

You can self-host Hanko or use it as a fully managed service on Hanko Cloud. The repository lists the licence as Other, so review the licence file for the terms. It suits developers who want to own their authentication stack without building it from scratch.

Key features

  • Passkeys, passwords and email passcodes
  • MFA with TOTP and security keys
  • Social login and custom OIDC connections
  • SAML enterprise SSO
  • Hanko Elements web components
  • Webhooks and server-side sessions
  • JS SDK and API-first design

Pricing: Free Starter plan covers 10,000 monthly active users. Pro is $29 per month plus $0.01 per user above 10,000; Enterprise is custom. The code is open source for self-hosting.

Ory Hydra

Ory Hydra is a certified OAuth 2.0 and OpenID Connect server that plugs into your existing user management through headless APIs, self-hosted or hosted.

GitHub stars
18k
Last commit
2 mo ago
Latest release
v26.2.0
Licence
Apache-2.0
Self-hosted
Yes
Hosted version
Available
ory.comOry Hydra homepage screenshot

Ory Hydra is an OAuth 2.0 authorization server and an implementation of OpenID Connect Core 1.0. It is designed as a standalone server without user management, so it connects to whatever identity provider you already use through a login and consent app, leaving you in control of the user interface.

It handles OAuth 2.0 and OpenID Connect flows, issues and validates tokens, manages clients, orchestrates login and consent flows and manages JWKS. The project says it is tuned for low latency and high throughput with modest resource use, and it is OpenID Certified. It works with any authentication endpoint, including Ory Kratos, and belongs to an ecosystem that also includes Oathkeeper for access proxying and Keto for access control policies.

Hydra is written in Go and licensed under Apache-2.0. You can consume it as a managed service on Ory Network or self-host it, and a quickstart, documentation and telemetry notes are provided in the repository.

Key features

  • OAuth 2.0 and OpenID Connect server
  • Token issuance and validation
  • Client management
  • Login and consent flow orchestration
  • JWKS management
  • Headless APIs for any identity provider

Pricing: Ory Network has a free Developer plan. Production is $770 and Growth $9350 per year plus usage fees; Enterprise and the self-hosted license are quoted.

10 more Auth0 alternatives

Auth0 alternatives: questions

What is the best open-source alternative to Auth0?
Keycloak is the top-ranked open-source alternative to Auth0 on Enlisted: Keycloak is an open-source identity and access management server that adds single sign-on, user management and authorization to applications. Other strong options are Authentik, SuperTokens, ZITADEL and Logto.
Are these Auth0 alternatives free?
All 20 are open source, so the code is free to use under its licence, and all of them can be self-hosted on your own server or computer. 11 also offer a paid or managed cloud version if you'd rather not host it yourself.
How is this list of Auth0 alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 16 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all