7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

5 alternatives ranked by real activity

Open-source Authress alternatives

A curated, ranked list of the 5 best open-source alternatives to Authress.

The best open-source alternative to Authress is Keycloak. If that doesn't suit you, other good options are ZITADEL, Logto, SpiceDB and Hexclave.

Authress alternatives are mainly auth & identity tools. 5 of them shipped code in the last 30 days, 5 can be self-hosted, and 3 use a permissive licence.

Last updated October 2, 2026 · ranked by GitHub stars, growth and recent commits

Keycloak

Keycloak is an open-source identity and access management server that adds single sign-on, user management and authorization to applications.

GitHub stars
37k
Last commit
today
Latest release
26.8.0
Licence
Apache-2.0
Self-hosted
Yes
keycloak.orgKeycloak homepage screenshot

Keycloak is an open-source identity and access management server. It lets application teams add authentication and secure services without building their own login system, since Keycloak handles storing users and authenticating them. The project is written in Java, released under the Apache-2.0 license and governed under the Cloud Native Computing Foundation code of conduct.

Keycloak supports standard protocols such as OpenID Connect and SAML, and offers user federation, strong authentication, user management and fine-grained authorization. You can run it from the downloadable distribution using a start-dev command, or use the official Docker image published on Quay for containers and Kubernetes setups. The project provides documentation, a user mailing list and community channels for help, along with guidance for building and testing from source.

Key features

  • Single sign-on with OpenID Connect and SAML
  • User federation with external directories
  • Strong and multi-step authentication options
  • Central user and account management
  • Fine-grained authorization policies
  • Docker image and standalone distribution

Pricing: Free and open source under the Apache-2.0 license; you host and operate it yourself.

ZITADEL

An open-source identity and access management platform with SSO, MFA, passkeys, OIDC, SAML, SCIM and native multi-tenancy, available self-hosted or as a cloud service.

GitHub stars
15k
Last commit
today
Latest release
v4.19.4
Licence
AGPL-3.0
Self-hosted
Yes
Hosted version
Available
zitadel.comZITADEL homepage screenshot

ZITADEL is an identity and access management platform, open source, for teams that need more than basic login. It targets SaaS products, B2B platforms and self-hosted IAM stacks, and bundles single sign-on, multi-factor authentication, passkeys, OIDC, SAML and SCIM in an API-first design, with an emphasis on a mature multi-tenancy model.

A comparison table in the README sets it against FusionAuth, Keycloak and Auth0 or Okta on points such as open-source status, self-hosting, infrastructure-level tenants, native B2B organizations and a comprehensive event-stream audit trail. Topics list standards and features including OAuth 2, OpenID Connect, FIDO2, 2FA and passkeys. The positioning is that you can own the identity layer without vendor lock-in while still getting a polished product.

ZITADEL is written in Go and licensed under AGPL-3.0, with a website, chat, docs and blog. You can run it yourself or use the vendor's managed cloud. It suits developers and security teams building multi-tenant applications who want a self-hostable alternative to commercial identity providers.

Key features

  • Single sign-on with OIDC and SAML
  • Multi-factor authentication and passkeys
  • SCIM user provisioning support
  • Native multi-tenancy with B2B organizations
  • Event-stream audit trail
  • API-first, self-hostable design

Pricing: Free cloud plan for 100 daily active users. Pro costs $100 per month and includes 25,000 daily active users; Enterprise is custom and can run on your own infrastructure.

Logto

Open-source identity infrastructure that adds sign-in, enterprise SSO and role-based access control to SaaS and AI products, using OIDC and OAuth 2.1 standards.

GitHub stars
15k
Last commit
yesterday
Latest release
v1.44.0
Licence
MPL-2.0
Self-hosted
Yes
Hosted version
Available
logto.ioLogto homepage screenshot

Logto is an open-source identity platform that handles sign-in, sign-up and access control so product teams do not have to build them from scratch. It is built on OpenID Connect and OAuth 2.1, with SAML also supported, and is aimed at SaaS products and AI or agent-based platforms that need production-ready authentication.

Out of the box it provides multi-tenancy and organizations with member invites and role-based access, enterprise SSO, and prebuilt sign-in flows with a customizable interface. Sign-in options include social login, passwordless methods, MFA and Google One Tap, and it can connect to external identity providers such as Google, Azure AD and Okta. SDKs cover more than 30 frameworks, among them React, Next.js, Angular, Vue, Flutter, Go and Python.

The core is licensed under MPL-2.0 and can be self-hosted by following the OSS installation guide or run locally for development. Logto Cloud offers the same product as a fully managed service. The project also advertises support for the Model Context Protocol and agent-style AI architectures.

Key features

  • OIDC, OAuth 2.1 and SAML support
  • Multi-tenancy with organization RBAC
  • Enterprise single sign-on
  • Prebuilt, customizable sign-in flows
  • Social login, passwordless and MFA
  • SDKs for over 30 frameworks
  • Machine-to-machine access for APIs and CLIs

Pricing: Free cloud plan for up to 50,000 MAU. Pro starts at $24 per month plus token usage and add-ons; Enterprise is quoted, and self-hosting is available.

SpiceDB

SpiceDB from Authzed is an open-source, Google Zanzibar-inspired database for storing and querying fine-grained authorization data, answering whether a subject can perform an action on a resource.

GitHub stars
7.1k
Last commit
yesterday
Latest release
v1.56.2
Licence
Apache-2.0
Self-hosted
Yes
authzed.comSpiceDB homepage screenshot

This entry covers SpiceDB, the open-source authorization database from Authzed. It is inspired by Google's Zanzibar paper and lets platform and product teams answer questions such as whether a given subject can perform an action on a given resource, which addresses broken access control, a major web security risk.

Like a relational database, you define a schema, write data as relationships and then use client libraries to issue permission checks from your application. Other queries are possible too, such as what a subject can do or who can access a resource. SpiceDB typically runs as one central service used by several products and microservices, and it focuses purely on authorization, staying agnostic to authentication and identity providers. Topics mention RBAC, ABAC, ReBAC and fine-grained access control.

SpiceDB is written in Go, runs on Kubernetes and elsewhere, and is licensed under Apache-2.0. Authzed also offers commercial products around it. It suits engineering teams that need consistent, scalable permissions for multi-tenant or collaborative applications.

Key features

  • Zanzibar-style relationship-based permissions
  • Schema language for authorization models
  • Permission check and lookup queries
  • Centralized authorization service
  • Independent of identity providers
  • Distributed, cloud-native design

Pricing: Free and open source under the Apache-2.0 licence.

Hexclave

A user infrastructure platform that handles authentication, teams, RBAC, API keys, payments, emails and analytics for apps, with a dashboard and optional deployment hosting.

GitHub stars
6.9k
Last commit
today
Latest release
dashboard-v1.0.123
Self-hosted
Yes
Hosted version
Available
hexclave.comHexclave homepage screenshot

Hexclave positions itself as infrastructure for the user side of an app: you pick the frontend, backend and database, and it manages everything around your users. That covers authentication, teams, permissions, API keys, payments, emails and analytics, packaged as a catalog of modules that you enable when your product needs them, all sharing one user model.

Authentication supports passkeys, OAuth and CLI auth, with methods toggled from the dashboard without code changes. Teams add workspaces, email invites and roles, while RBAC provides nested roles and a single permission check usable on server or client. API keys are auto-revoked if leaked and show their secret only once. Payments cover subscriptions, single charges and credit-based usage metering for individuals or teams, and emails cover transactional and marketing sends with an AI template editor.

Setup is designed around pasting one prompt into a coding agent, and a Hexclave Deploy offering can deploy the frontend, backend and database together. The code is TypeScript with Next.js, topics mention self-hosting and alternatives such as Auth0, Clerk, Supabase and PostHog, and the repository lists the licence as Other, so review the licence terms.

Key features

  • Passkey, OAuth and CLI authentication
  • Teams, workspaces and email invites
  • Nested roles with RBAC checks
  • API keys with auto-revocation of leaks
  • Subscriptions, one-time payments and usage credits
  • Transactional and marketing emails
  • Product analytics for user activity

Pricing: Free forever plan for up to 10,000 auth users, and free self-hosting. Team is $49 per month and Growth $299 per month, with extra dashboard admins at $29 each.

Authress alternatives: questions

What is the best open-source alternative to Authress?
Keycloak is the top-ranked open-source alternative to Authress on Enlisted: Keycloak is an open-source identity and access management server that adds single sign-on, user management and authorization to applications. Other strong options are ZITADEL, Logto, SpiceDB and Hexclave.
Are these Authress alternatives free?
All 5 are open source, so the code is free to use under its licence, and all of them can be self-hosted on your own server or computer. 3 also offer a paid or managed cloud version if you'd rather not host it yourself.
How is this list of Authress alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 5 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all