7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

5 alternatives ranked by real activity

Open-source Duo Security alternatives

A curated, ranked list of the 5 best open-source alternatives to Duo Security.

The best open-source alternative to Duo Security is Keycloak. If that doesn't suit you, other good options are Authelia, Authentik, Aegis Authenticator and privacyIDEA.

Duo Security alternatives are mainly auth & identity tools. 5 of them shipped code in the last 30 days, 5 can be self-hosted, and 2 use a permissive licence.

Last updated October 2, 2026 · ranked by GitHub stars, growth and recent commits

Keycloak

Keycloak is an open-source identity and access management server that adds single sign-on, user management and authorization to applications.

GitHub stars
37k
Last commit
today
Latest release
26.8.0
Licence
Apache-2.0
Self-hosted
Yes
keycloak.orgKeycloak homepage screenshot

Keycloak is an open-source identity and access management server. It lets application teams add authentication and secure services without building their own login system, since Keycloak handles storing users and authenticating them. The project is written in Java, released under the Apache-2.0 license and governed under the Cloud Native Computing Foundation code of conduct.

Keycloak supports standard protocols such as OpenID Connect and SAML, and offers user federation, strong authentication, user management and fine-grained authorization. You can run it from the downloadable distribution using a start-dev command, or use the official Docker image published on Quay for containers and Kubernetes setups. The project provides documentation, a user mailing list and community channels for help, along with guidance for building and testing from source.

Key features

  • Single sign-on with OpenID Connect and SAML
  • User federation with external directories
  • Strong and multi-step authentication options
  • Central user and account management
  • Fine-grained authorization policies
  • Docker image and standalone distribution

Pricing: Free and open source under the Apache-2.0 license; you host and operate it yourself.

Read more about KeycloakWebsite GitHub

Authelia

A self-hosted single sign-on and multi-factor authentication portal that protects web applications, certified for OpenID Connect and ready for post-quantum cryptography.

GitHub stars
29k
Last commit
yesterday
Latest release
v4.39.28
Licence
Apache-2.0
Self-hosted
Yes
authelia.comAuthelia homepage screenshot

Authelia is an open-source authentication and authorization server that provides single sign-on and multi-factor authentication for web applications. It sits in front of your services, usually alongside a reverse proxy, so users sign in once at a portal and are checked against policies before reaching an app.

Supported factors and backends include TOTP, push notifications, two-factor methods and LDAP, according to its topics, and it is described as OpenID Certified and ready for post-quantum cryptography. It is written in Go and runs well as a small container, with documentation for Docker and Kubernetes deployments. Self-hosters often use it to add a consistent login and second factor to tools that have weak or no authentication of their own.

Authelia is licensed under Apache-2.0. As an authentication component, it is meant to be run on your own infrastructure, and it suits home labs, small organizations and teams wanting a lightweight identity layer without a heavier enterprise identity platform.

Key features

  • Single sign-on portal for web apps
  • Multi-factor authentication including TOTP
  • Push notification verification
  • LDAP user backend support
  • OpenID Connect support
  • Docker and Kubernetes deployment

Pricing: Free and open source under the Apache-2.0 license.

Read more about AutheliaWebsite GitHub

Authentik

An open-source identity provider for single sign-on that supports SAML, OAuth2 and OIDC, LDAP and RADIUS, built for self-hosting from home labs to large clusters.

GitHub stars
26k
Last commit
today
Latest release
version/2026.8.3
Self-hosted
Yes
goauthentik.ioAuthentik homepage screenshot

authentik is an open-source Identity Provider for modern single sign-on. It supports SAML, OAuth2 and OpenID Connect, LDAP, RADIUS and more, and is designed for self-hosting at any scale, from a small lab to production clusters. A reverse-proxy mode also lets it protect applications that lack native SSO support.

The project positions its enterprise offering as a way for organizations to replace incumbent identity providers (Okta, Auth0, Entra ID or Ping Identity) in large-scale identity management. For installation, Docker Compose is recommended for small and test setups, a Helm chart for Kubernetes suits larger setups, and official templates exist for AWS CloudFormation and a one-click DigitalOcean Marketplace app.

The codebase is mostly Python with Kubernetes tooling, and the license is listed as 'Other' on GitHub because it mixes open-source and enterprise components, so check which features fall under which terms. authentik is a common choice for self-hosters and companies who want to centralize logins across internal tools without paying per-user fees to a hosted identity vendor.

Key features

  • SAML and OAuth2/OIDC provider
  • LDAP and RADIUS support
  • Reverse-proxy authentication for apps
  • Docker Compose and Helm chart installs
  • AWS CloudFormation and DigitalOcean templates
  • Enterprise edition for large deployments

Pricing: The open-source edition is free. Enterprise costs $5 per user per month billed annually, plus $0.02 per external user; Enterprise Plus starts at $20k per year. No hosted version is offered.

Read more about AuthentikWebsite GitHub

Aegis Authenticator

Free Android authenticator app that stores two-factor authentication tokens in an encrypted vault with backups and import options.

GitHub stars
13k
Last commit
26 days ago
Latest release
v3.4.3
Licence
GPL-3.0
getaegis.appAegis Authenticator homepage screenshot

Aegis Authenticator is an open-source two-factor authentication app for Android. It generates one-time codes for online accounts and was created to offer features missing from other authenticator apps, notably proper encryption of the token store and reliable backups.

It supports the HOTP and TOTP algorithms, so it works with thousands of services and is compatible with Google Authenticator. The vault is encrypted with AES-256-GCM and can be unlocked with a password protected by scrypt or with biometrics through the Android Keystore. Extra protections include screen capture prevention and tap-to-reveal codes. Entries can be added by scanning a QR code, from an image or manually, and imported from apps such as Authy, andOTP, FreeOTP and Google Authenticator.

Aegis is written in Java and released under GPL-3.0. Entries can be organized with groups, custom icons and search, and the interface offers Light, Dark and AMOLED themes. Vaults can be exported in plaintext or encrypted form and backed up automatically. The app is distributed through Google Play and F-Droid, and the documentation describes its security design.

Key features

  • AES-256-GCM encrypted token vault
  • Unlock with password or biometrics
  • HOTP and TOTP code generation
  • Import from Authy, andOTP and Google Authenticator
  • Encrypted export and automatic backups
  • Groups, custom icons and search

Pricing: Free and open source under the GPL-3.0 license.

privacyIDEA

An open-source authentication server for managing two-factor and multi-factor logins with OTP tokens, push, FIDO2 keys and passkeys across an organization.

GitHub stars
1.8k
Last commit
today
Latest release
v3.14
Licence
AGPL-3.0
Self-hosted
Yes
privacyidea.orgprivacyIDEA homepage screenshot

privacyIDEA is an open-source authentication server that manages multi-factor authentication for an organization. It issues and verifies second factors such as one-time passwords, hardware tokens, push notifications and FIDO2 or WebAuthn security keys, so applications and servers can add two-factor login without each building its own token handling.

The server is written in Python and exposes an API that other systems can call to check a login attempt. Its topics point to support for OTP, passkeys, push authentication and certificates, and administrators enroll and manage tokens centrally rather than configuring every service by hand. The project documentation includes how-tos for running it behind Apache2 with MySQL and for protecting a whole server farm.

privacyIDEA is released under the AGPL-3.0 licence and can be self-hosted, which keeps token data and user policies on infrastructure you control. The project website also lists an Enterprise Edition next to the community version, along with a demo site, screenshots and community resources for anyone evaluating it.

Key features

  • OTP, push, and hardware token support
  • FIDO2, WebAuthn, and passkey authentication
  • REST API for application integration
  • Central web interface for token enrollment
  • Policy-based control of authentication rules
  • Certificate and CA related features

Pricing: The community edition is free and open source under AGPL-3.0; an Enterprise Edition is also listed on the project website.

Duo Security alternatives: questions

What is the best open-source alternative to Duo Security?
Keycloak is the top-ranked open-source alternative to Duo Security on Enlisted: Keycloak is an open-source identity and access management server that adds single sign-on, user management and authorization to applications. Other strong options are Authelia, Authentik, Aegis Authenticator and privacyIDEA.
Are these Duo Security alternatives free?
All 5 are open source, so the code is free to use under its licence, and all of them can be self-hosted on your own server or computer.
How is this list of Duo Security alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 5 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all