7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

7 alternatives ranked by real activity

Open-source JumpCloud alternatives

A curated, ranked list of the 7 best open-source alternatives to JumpCloud.

The best open-source alternative to JumpCloud is Authelia. If that doesn't suit you, other good options are Authentik, LLDAP, Kanidm and Defguard.

JumpCloud alternatives are mainly auth & identity tools, but some are also networking & VPN tools. 7 of them shipped code in the last 30 days, 7 can be self-hosted, and 2 use a permissive licence.

Last updated October 2, 2026 · ranked by GitHub stars, growth and recent commits

Authelia

A self-hosted single sign-on and multi-factor authentication portal that protects web applications, certified for OpenID Connect and ready for post-quantum cryptography.

GitHub stars
29k
Last commit
yesterday
Latest release
v4.39.28
Licence
Apache-2.0
Self-hosted
Yes
authelia.comAuthelia homepage screenshot

Authelia is an open-source authentication and authorization server that provides single sign-on and multi-factor authentication for web applications. It sits in front of your services, usually alongside a reverse proxy, so users sign in once at a portal and are checked against policies before reaching an app.

Supported factors and backends include TOTP, push notifications, two-factor methods and LDAP, according to its topics, and it is described as OpenID Certified and ready for post-quantum cryptography. It is written in Go and runs well as a small container, with documentation for Docker and Kubernetes deployments. Self-hosters often use it to add a consistent login and second factor to tools that have weak or no authentication of their own.

Authelia is licensed under Apache-2.0. As an authentication component, it is meant to be run on your own infrastructure, and it suits home labs, small organizations and teams wanting a lightweight identity layer without a heavier enterprise identity platform.

Key features

  • Single sign-on portal for web apps
  • Multi-factor authentication including TOTP
  • Push notification verification
  • LDAP user backend support
  • OpenID Connect support
  • Docker and Kubernetes deployment

Pricing: Free and open source under the Apache-2.0 license.

Authentik

An open-source identity provider for single sign-on that supports SAML, OAuth2 and OIDC, LDAP and RADIUS, built for self-hosting from home labs to large clusters.

GitHub stars
26k
Last commit
today
Latest release
version/2026.8.3
Self-hosted
Yes
goauthentik.ioAuthentik homepage screenshot

authentik is an open-source Identity Provider for modern single sign-on. It supports SAML, OAuth2 and OpenID Connect, LDAP, RADIUS and more, and is designed for self-hosting at any scale, from a small lab to production clusters. A reverse-proxy mode also lets it protect applications that lack native SSO support.

The project positions its enterprise offering as a way for organizations to replace incumbent identity providers (Okta, Auth0, Entra ID or Ping Identity) in large-scale identity management. For installation, Docker Compose is recommended for small and test setups, a Helm chart for Kubernetes suits larger setups, and official templates exist for AWS CloudFormation and a one-click DigitalOcean Marketplace app.

The codebase is mostly Python with Kubernetes tooling, and the license is listed as 'Other' on GitHub because it mixes open-source and enterprise components, so check which features fall under which terms. authentik is a common choice for self-hosters and companies who want to centralize logins across internal tools without paying per-user fees to a hosted identity vendor.

Key features

  • SAML and OAuth2/OIDC provider
  • LDAP and RADIUS support
  • Reverse-proxy authentication for apps
  • Docker Compose and Helm chart installs
  • AWS CloudFormation and DigitalOcean templates
  • Enterprise edition for large deployments

Pricing: The open-source edition is free. Enterprise costs $5 per user per month billed annually, plus $0.02 per external user; Enterprise Plus starts at $20k per year. No hosted version is offered.

LLDAP

lldap is a lightweight authentication server with a simplified LDAP interface and web UI, aimed at self-hosters who need LDAP for apps like Nextcloud.

GitHub stars
6.5k
Last commit
6 days ago
Latest release
v0.6.3
Licence
GPL-3.0
Self-hosted
Yes

lldap is a lightweight authentication server that exposes an opinionated, simplified LDAP interface. It is aimed mostly at self-hosting setups where open-source components such as Nextcloud only support LDAP as an external authentication source, and where running a full directory server would be more work than needed.

It comes with a web frontend for managing users, and also lets users update their own details and reset a forgotten password via email. By default data is stored in SQLite, with MySQL, MariaDB or PostgreSQL as alternative backends. It integrates with services such as Keycloak, Authelia and Nextcloud, and for features like OAuth or OpenID support you can add components such as Keycloak or Authelia that use lldap as the source of truth for users.

The project is written in Rust, licensed under GPL-3.0 and uses the OPAQUE protocol. The README states plainly that it is not meant to be a full LDAP server and points to OpenLDAP for that. It installs from OCI images, Kubernetes, TrueNAS or distribution packages.

Key features

  • Simplified LDAP interface for authentication
  • Web UI for user management
  • Self-service password reset by email
  • SQLite, MySQL, MariaDB and PostgreSQL backends
  • Works with Keycloak, Authelia and Nextcloud
  • Install from OCI images or distro packages

Pricing: Free and open source under the GPL-3.0 licence.

Read more about LLDAPGitHub

Kanidm

Kanidm is a Rust identity management server offering OIDC, LDAP, RADIUS, WebAuthn and SSH key authentication for home labs through organizations.

GitHub stars
5.4k
Last commit
yesterday
Latest release
v1.11.2
Licence
MPL-2.0
Self-hosted
Yes
kanidm.comKanidm homepage screenshot

Kanidm is an identity management platform written in Rust. Other applications and services can offload authentication and identity storage to it, and the project aims to be a complete identity provider so that you should not need to add components such as Keycloak next to it.

It covers a broad set of protocols and features: OpenID Connect, LDAP, RADIUS, SCIM, WebAuthn passkeys and SSH key authentication, according to the repository topics. To keep it manageable, the design favors secure defaults, minimal configuration and components that repair themselves, so the same system can serve small home labs, families and small businesses as well as larger deployments.

Kanidm is licensed under MPL-2.0 and runs on your own servers, with documentation and a community around the project. It suits administrators who want a single, secure place to manage users, groups and logins for their services without operating a heavyweight identity stack.

Key features

  • OpenID Connect identity provider
  • LDAP and RADIUS interfaces
  • WebAuthn and passkey authentication
  • SSH key authentication support
  • SCIM user provisioning support
  • Strict secure defaults, simple configuration

Pricing: Free and open source under the MPL-2.0 license.

Defguard

Self-hosted secure remote access platform combining WireGuard VPN, identity management, multi-factor authentication, and network access control.

GitHub stars
2.9k
Last commit
today
Latest release
v2.1.0
Self-hosted
Yes
defguard.netDefguard homepage screenshot

Defguard is a self-hosted platform that brings WireGuard VPN, identity and access management, multi-factor authentication, and network access control into one product. It is built in Rust with a security-first design and targets organizations that otherwise juggle separate tools for identity, VPN access, and permissions. The core is open source under the AGPL, while some Enterprise components are open-code.

The VPN side supports multiple locations with per-location access control, MFA per connection, self-service device setup, and kernel and userspace WireGuard. The identity side includes an internal OIDC provider for single sign-on, external OIDC with Google, Microsoft, or custom providers, LDAP and Active Directory sync, remote enrollment, and user self-service. MFA options include TOTP, WebAuthn and FIDO2, and email tokens.

Everything runs in your own environment with no external dependencies or data leaving your infrastructure, and the project publishes SBOMs, penetration test reports, and architecture decision records. It suits IT and security teams that want zero-trust remote access and identity management they control, as an alternative to products such as Keycloak and Pritunl.

Key features

  • WireGuard VPN with per-connection MFA
  • Internal OIDC provider for single sign-on
  • LDAP and Active Directory sync
  • TOTP, WebAuthn, and email-token MFA
  • Per-location access control
  • Self-service device setup
  • Published SBOMs and security reports

Pricing: The Open Source edition is free to self-host. Business is free up to 10 users and 1 location, with larger setups priced through a calculator; Enterprise is custom.

VoidAuth

Self-hostable single sign-on and user management provider with OIDC, proxy ForwardAuth, LDAP, passkeys, invitations, and an admin panel.

GitHub stars
2.9k
Last commit
yesterday
Latest release
v1.16.0
Licence
AGPL-3.0
Self-hosted
Yes
voidauth.appVoidAuth homepage screenshot

VoidAuth is an open-source SSO authentication and user management provider that sits in front of self-hosted applications. It is meant to be easy for administrators and end users, adding features such as passkeys, user invitations, self-registration, and email support. It runs in Docker and is released under the AGPL-3.0 license.

It acts as an OpenID Connect provider, supports proxy ForwardAuth for protecting apps behind a reverse proxy, and offers an LDAP directory server. Administrators manage users and groups from an admin panel, invite users or allow self-registration, and customize the logo, title, theme color, and email templates. Security options include multi-factor authentication, passkey-only accounts, and password resets verified by email.

Data is stored in Postgres or SQLite with encryption at rest. VoidAuth suits homelab users and small teams who run several services and want one login across them, as a lighter alternative to larger identity platforms.

Key features

  • OpenID Connect provider
  • Proxy ForwardAuth for reverse proxies
  • LDAP directory server
  • User and group management with invitations
  • Multi-factor authentication and passkeys
  • Customizable branding and email templates
  • Encryption at rest with Postgres or SQLite

Pricing: Free and open source under the AGPL-3.0 license.

FreeIPA

FreeIPA is an integrated identity, authentication and access control system for Linux and UNIX networks, built on LDAP, Kerberos and PKI.

GitHub stars
1.3k
Last commit
today
Licence
GPL-3.0
Self-hosted
Yes
freeipa.orgFreeIPA homepage screenshot

FreeIPA lets Linux administrators centrally manage identity, authentication and access control for Linux and UNIX systems. It provides command-line and web-based management tools that are simple to install and use, and it focuses on ease of management and automation of installation and configuration. The repository is a mirror of the upstream project and is written mostly in Python.

The README lists benefits such as letting users access every machine with the same credentials and security settings, transparent access to personal files from any machine, grouping to restrict services and files to specific users, central management of passwords, SSH public keys, sudo rules, keytabs and access control rules, and delegation of selected administrative tasks to other power users.

FreeIPA bundles well-known open-source components with unified tools: an LDAP server based on the 389 project, a Kerberos KDC based on MIT Kerberos, a public key infrastructure based on Dogtag, Samba libraries for Active Directory integration and a DNS server based on BIND. It can integrate into Active Directory environments through cross-realm Kerberos trust or user synchronization. The code is licensed under GPL-3.0.

Key features

  • Central identity and authentication management
  • LDAP and Kerberos services
  • Certificate authority based on Dogtag
  • Integrated DNS server
  • Sudo rules and SSH key management
  • Active Directory trust and synchronization

Pricing: Free and open source under the GPL-3.0 license.

JumpCloud alternatives: questions

What is the best open-source alternative to JumpCloud?
Authelia is the top-ranked open-source alternative to JumpCloud on Enlisted: A self-hosted single sign-on and multi-factor authentication portal that protects web applications, certified for OpenID Connect and ready for post-quantum cryptography. Other strong options are Authentik, LLDAP, Kanidm and Defguard.
Are these JumpCloud alternatives free?
All 7 are open source, so the code is free to use under its licence, and all of them can be self-hosted on your own server or computer.
How is this list of JumpCloud alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 7 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all