7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

4 alternatives ranked by real activity

Open-source Beyond Identity alternatives

A curated, ranked list of the 4 best open-source alternatives to Beyond Identity.

The best open-source alternative to Beyond Identity is Authentik. If that doesn't suit you, other good options are Pocket ID, Hanko and privacyIDEA.

Beyond Identity alternatives are mainly auth & identity tools. 4 of them shipped code in the last 30 days, 4 can be self-hosted, and 1 uses a permissive licence.

Last updated October 2, 2026 · ranked by GitHub stars, growth and recent commits

Authentik

An open-source identity provider for single sign-on that supports SAML, OAuth2 and OIDC, LDAP and RADIUS, built for self-hosting from home labs to large clusters.

GitHub stars
26k
Last commit
today
Latest release
version/2026.8.3
Self-hosted
Yes
goauthentik.ioAuthentik homepage screenshot

authentik is an open-source Identity Provider for modern single sign-on. It supports SAML, OAuth2 and OpenID Connect, LDAP, RADIUS and more, and is designed for self-hosting at any scale, from a small lab to production clusters. A reverse-proxy mode also lets it protect applications that lack native SSO support.

The project positions its enterprise offering as a way for organizations to replace incumbent identity providers (Okta, Auth0, Entra ID or Ping Identity) in large-scale identity management. For installation, Docker Compose is recommended for small and test setups, a Helm chart for Kubernetes suits larger setups, and official templates exist for AWS CloudFormation and a one-click DigitalOcean Marketplace app.

The codebase is mostly Python with Kubernetes tooling, and the license is listed as 'Other' on GitHub because it mixes open-source and enterprise components, so check which features fall under which terms. authentik is a common choice for self-hosters and companies who want to centralize logins across internal tools without paying per-user fees to a hosted identity vendor.

Key features

  • SAML and OAuth2/OIDC provider
  • LDAP and RADIUS support
  • Reverse-proxy authentication for apps
  • Docker Compose and Helm chart installs
  • AWS CloudFormation and DigitalOcean templates
  • Enterprise edition for large deployments

Pricing: The open-source edition is free. Enterprise costs $5 per user per month billed annually, plus $0.02 per external user; Enterprise Plus starts at $20k per year. No hosted version is offered.

Read more about AuthentikWebsite GitHub

Pocket ID

A simple self-hosted identity provider for OpenID Connect and OAuth 2.0 that signs users in to your apps with passkeys only, without passwords.

GitHub stars
9.4k
Last commit
yesterday
Latest release
v2.17.0
Licence
BSD-2-Clause
Self-hosted
Yes
pocket-id.orgPocket ID homepage screenshot

Pocket ID is a self-hosted identity provider that speaks OpenID Connect and OAuth 2.0 and is described as OpenID Connect certified. Users sign in to your applications with passkeys, so there are no passwords to store, reset or leak, and a hardware key such as a YubiKey can unlock all of your self-hosted services.

Its goal is simplicity. The author notes that existing self-hosted providers like Keycloak or ORY Hydra are often too complex for simple use cases, and Pocket ID aims to be easy to set up and use. The distinctive design choice is that it supports only passkey authentication, which the project argues is the future, and a demo is available to try it.

The recommended installation is Docker, with a setup guide in the documentation. Pocket ID is written in Go and released under the BSD 2-Clause licence. It suits homelab users and small teams who want single sign-on across self-hosted applications without administering a heavyweight identity system.

Key features

  • OpenID Connect and OAuth 2.0 provider
  • Passkey-only sign-in for users
  • No passwords to manage
  • Hardware key sign-in such as YubiKey
  • Recommended setup with Docker
  • Lightweight Go server

Pricing: Free and open source under the BSD 2-Clause licence.

Read more about Pocket IDWebsite GitHub

Hanko

An open-source authentication and user management service built around passkeys, with MFA, social login, SAML SSO and web components, self-hosted or on Hanko Cloud.

GitHub stars
9k
Last commit
today
Latest release
backend/v3.1.0
Self-hosted
Yes
Hosted version
Available
hanko.ioHanko homepage screenshot

Hanko is an authentication and user management solution released as open source, framework-agnostic and designed around privacy-first principles such as data minimalism and phishing resistance. It is presented as an alternative to Auth0, Clerk, WorkOS and Stytch, written in Go, with an API-first and lightweight design.

It supports modern sign-in methods including passwords, email passcodes, passkeys, MFA with TOTP and security keys, social logins such as Apple, Google and GitHub, custom OIDC and OAuth connections and SAML enterprise SSO. Configuration is flexible, for example passkey-only or OAuth-only setups, and passwords can be deletable by users. Hanko Elements web components make integration quick, a JS SDK is available, webhooks and server-side sessions with remote revocation are included, and a full API supports custom front ends. Organizations, roles and permissions plus mobile SDKs are on the roadmap.

You can self-host Hanko or use it as a fully managed service on Hanko Cloud. The repository lists the licence as Other, so review the licence file for the terms. It suits developers who want to own their authentication stack without building it from scratch.

Key features

  • Passkeys, passwords and email passcodes
  • MFA with TOTP and security keys
  • Social login and custom OIDC connections
  • SAML enterprise SSO
  • Hanko Elements web components
  • Webhooks and server-side sessions
  • JS SDK and API-first design

Pricing: Free Starter plan covers 10,000 monthly active users. Pro is $29 per month plus $0.01 per user above 10,000; Enterprise is custom. The code is open source for self-hosting.

Read more about HankoWebsite GitHub

privacyIDEA

An open-source authentication server for managing two-factor and multi-factor logins with OTP tokens, push, FIDO2 keys and passkeys across an organization.

GitHub stars
1.8k
Last commit
today
Latest release
v3.14
Licence
AGPL-3.0
Self-hosted
Yes
privacyidea.orgprivacyIDEA homepage screenshot

privacyIDEA is an open-source authentication server that manages multi-factor authentication for an organization. It issues and verifies second factors such as one-time passwords, hardware tokens, push notifications and FIDO2 or WebAuthn security keys, so applications and servers can add two-factor login without each building its own token handling.

The server is written in Python and exposes an API that other systems can call to check a login attempt. Its topics point to support for OTP, passkeys, push authentication and certificates, and administrators enroll and manage tokens centrally rather than configuring every service by hand. The project documentation includes how-tos for running it behind Apache2 with MySQL and for protecting a whole server farm.

privacyIDEA is released under the AGPL-3.0 licence and can be self-hosted, which keeps token data and user policies on infrastructure you control. The project website also lists an Enterprise Edition next to the community version, along with a demo site, screenshots and community resources for anyone evaluating it.

Key features

  • OTP, push, and hardware token support
  • FIDO2, WebAuthn, and passkey authentication
  • REST API for application integration
  • Central web interface for token enrollment
  • Policy-based control of authentication rules
  • Certificate and CA related features

Pricing: The community edition is free and open source under AGPL-3.0; an Enterprise Edition is also listed on the project website.

Read more about privacyIDEAWebsite GitHub

Beyond Identity alternatives: questions

What is the best open-source alternative to Beyond Identity?
Authentik is the top-ranked open-source alternative to Beyond Identity on Enlisted: An open-source identity provider for single sign-on that supports SAML, OAuth2 and OIDC, LDAP and RADIUS, built for self-hosting from home labs to large clusters. Other strong options are Pocket ID, Hanko and privacyIDEA.
Are these Beyond Identity alternatives free?
All 4 are open source, so the code is free to use under its licence, and all of them can be self-hosted on your own server or computer. 1 also offers a paid or managed cloud version if you'd rather not host it yourself.
How is this list of Beyond Identity alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 4 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all