Hanko
An open-source authentication and user management service built around passkeys, with MFA, social login, SAML SSO and web components, self-hosted or on Hanko Cloud.
- GitHub stars
- 9k
- Last commit
- yesterday
- Latest release
- backend/v3.1.0
- Self-hosted
- Yes
- Hosted version
- Available

Hanko is an authentication and user management solution released as open source, framework-agnostic and designed around privacy-first principles such as data minimalism and phishing resistance. It is presented as an alternative to Auth0, Clerk, WorkOS and Stytch, written in Go, with an API-first and lightweight design.
It supports modern sign-in methods including passwords, email passcodes, passkeys, MFA with TOTP and security keys, social logins such as Apple, Google and GitHub, custom OIDC and OAuth connections and SAML enterprise SSO. Configuration is flexible, for example passkey-only or OAuth-only setups, and passwords can be deletable by users. Hanko Elements web components make integration quick, a JS SDK is available, webhooks and server-side sessions with remote revocation are included, and a full API supports custom front ends. Organizations, roles and permissions plus mobile SDKs are on the roadmap.
You can self-host Hanko or use it as a fully managed service on Hanko Cloud. The repository lists the licence as Other, so review the licence file for the terms. It suits developers who want to own their authentication stack without building it from scratch.
Key features
- Passkeys, passwords and email passcodes
- MFA with TOTP and security keys
- Social login and custom OIDC connections
- SAML enterprise SSO
- Hanko Elements web components
- Webhooks and server-side sessions
- JS SDK and API-first design
Pricing: Free Starter plan covers 10,000 monthly active users. Pro is $29 per month plus $0.01 per user above 10,000; Enterprise is custom. The code is open source for self-hosting.