Pocket ID
A simple self-hosted identity provider for OpenID Connect and OAuth 2.0 that signs users in to your apps with passkeys only, without passwords.
- GitHub stars
- 9.4k
- Last commit
- yesterday
- Latest release
- v2.17.0
- Licence
- BSD-2-Clause
- Self-hosted
- Yes

Pocket ID is a self-hosted identity provider that speaks OpenID Connect and OAuth 2.0 and is described as OpenID Connect certified. Users sign in to your applications with passkeys, so there are no passwords to store, reset or leak, and a hardware key such as a YubiKey can unlock all of your self-hosted services.
Its goal is simplicity. The author notes that existing self-hosted providers like Keycloak or ORY Hydra are often too complex for simple use cases, and Pocket ID aims to be easy to set up and use. The distinctive design choice is that it supports only passkey authentication, which the project argues is the future, and a demo is available to try it.
The recommended installation is Docker, with a setup guide in the documentation. Pocket ID is written in Go and released under the BSD 2-Clause licence. It suits homelab users and small teams who want single sign-on across self-hosted applications without administering a heavyweight identity system.
Key features
- OpenID Connect and OAuth 2.0 provider
- Passkey-only sign-in for users
- No passwords to manage
- Hardware key sign-in such as YubiKey
- Recommended setup with Docker
- Lightweight Go server
Pricing: Free and open source under the BSD 2-Clause licence.


