7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

7 alternatives ranked by real activity

Open-source Ping Identity alternatives

A curated, ranked list of the 7 best open-source alternatives to Ping Identity.

The best open-source alternative to Ping Identity is Keycloak. If that doesn't suit you, other good options are Authentik, Apereo CAS, MaxKey and SimpleSAMLphp.

Ping Identity alternatives are mainly auth & identity tools. 7 of them shipped code in the last 30 days, 7 can be self-hosted, and 4 use a permissive licence.

Last updated October 2, 2026 · ranked by GitHub stars, growth and recent commits

Keycloak

Keycloak is an open-source identity and access management server that adds single sign-on, user management and authorization to applications.

GitHub stars
37k
Last commit
today
Latest release
26.8.0
Licence
Apache-2.0
Self-hosted
Yes
keycloak.orgKeycloak homepage screenshot

Keycloak is an open-source identity and access management server. It lets application teams add authentication and secure services without building their own login system, since Keycloak handles storing users and authenticating them. The project is written in Java, released under the Apache-2.0 license and governed under the Cloud Native Computing Foundation code of conduct.

Keycloak supports standard protocols such as OpenID Connect and SAML, and offers user federation, strong authentication, user management and fine-grained authorization. You can run it from the downloadable distribution using a start-dev command, or use the official Docker image published on Quay for containers and Kubernetes setups. The project provides documentation, a user mailing list and community channels for help, along with guidance for building and testing from source.

Key features

  • Single sign-on with OpenID Connect and SAML
  • User federation with external directories
  • Strong and multi-step authentication options
  • Central user and account management
  • Fine-grained authorization policies
  • Docker image and standalone distribution

Pricing: Free and open source under the Apache-2.0 license; you host and operate it yourself.

Read more about KeycloakWebsite GitHub

Authentik

An open-source identity provider for single sign-on that supports SAML, OAuth2 and OIDC, LDAP and RADIUS, built for self-hosting from home labs to large clusters.

GitHub stars
26k
Last commit
today
Latest release
version/2026.8.3
Self-hosted
Yes
goauthentik.ioAuthentik homepage screenshot

authentik is an open-source Identity Provider for modern single sign-on. It supports SAML, OAuth2 and OpenID Connect, LDAP, RADIUS and more, and is designed for self-hosting at any scale, from a small lab to production clusters. A reverse-proxy mode also lets it protect applications that lack native SSO support.

The project positions its enterprise offering as a way for organizations to replace incumbent identity providers (Okta, Auth0, Entra ID or Ping Identity) in large-scale identity management. For installation, Docker Compose is recommended for small and test setups, a Helm chart for Kubernetes suits larger setups, and official templates exist for AWS CloudFormation and a one-click DigitalOcean Marketplace app.

The codebase is mostly Python with Kubernetes tooling, and the license is listed as 'Other' on GitHub because it mixes open-source and enterprise components, so check which features fall under which terms. authentik is a common choice for self-hosters and companies who want to centralize logins across internal tools without paying per-user fees to a hosted identity vendor.

Key features

  • SAML and OAuth2/OIDC provider
  • LDAP and RADIUS support
  • Reverse-proxy authentication for apps
  • Docker Compose and Helm chart installs
  • AWS CloudFormation and DigitalOcean templates
  • Enterprise edition for large deployments

Pricing: The open-source edition is free. Enterprise costs $5 per user per month billed annually, plus $0.02 per external user; Enterprise Plus starts at $20k per year. No hosted version is offered.

Read more about AuthentikWebsite GitHub

Apereo CAS

Apereo CAS is an enterprise identity provider and single sign-on server written in Java, supporting CAS, SAML2, OpenID Connect, OAuth2 and multifactor authentication.

GitHub stars
11k
Last commit
yesterday
Latest release
v8.0.2
Licence
Apache-2.0
Self-hosted
Yes
apereo.github.ioApereo CAS homepage screenshot

This entry covers Apereo CAS, the Central Authentication Service. CAS is both an open and well-documented authentication protocol and the primary open-source Java server implementing it, which works as a multilingual, enterprise-grade identity provider and web single sign-on solution.

Beyond its own protocol, the server supports additional authentication protocols and features, including SAML2, OpenID Connect, OAuth2, LDAP authentication and multifactor authentication, with topics also referencing FIDO and Duo Security. It is built on Spring Boot, Spring Webflow and Spring Cloud, and aims to be a comprehensive platform for authentication and authorization needs.

Apereo CAS is licensed under Apache-2.0. The recommended way to deploy it is the WAR Overlay method, and cloning the full codebase is only needed if you want to contribute. Documentation, release notes, a maintenance policy and a release schedule are published by the project. It is typically adopted by universities and other organizations that need centralized login across many applications.

Key features

  • Single sign-on for web applications
  • CAS protocol server
  • SAML2 and OpenID Connect support
  • OAuth2 and LDAP authentication
  • Multifactor authentication including FIDO
  • Spring Boot based Java server
  • WAR overlay deployment method

Pricing: Free and open source under the Apache-2.0 licence.

Read more about Apereo CASWebsite GitHub

MaxKey

Java identity and access management product offering single sign-on with OAuth 2, OpenID Connect, SAML, CAS, JWT, and SCIM, plus RBAC and user lifecycle management.

GitHub stars
2k
Last commit
9 days ago
Latest release
4.1.12
Licence
Apache-2.0
Self-hosted
Yes
maxkey.topMaxKey homepage screenshot

MaxKey, from the Dromara community, is an IAM and IDaaS product written in Java and released under the Apache-2.0 license. It provides single sign-on, identity management, access management, RBAC-based permission control, and resource management. The name is a homophone of a phrase about a master key that unlocks enterprise security needs, according to the README.

It supports standard protocols including OAuth 2.x and OpenID Connect, SAML 2.0, CAS, JWT, and SCIM, and its topics also list LDAP, Active Directory, Kerberos, multi-factor authentication, TOTP, and multi-tenancy. Features focus on user lifecycle management and compliance, and the project presents itself as open, secure, and self-controlled. Documentation is in English and Chinese.

MaxKey is aimed at enterprises, particularly in Chinese-speaking markets, that need a self-hosted alternative to commercial identity platforms. Teams should confirm industry claims in the README against their own requirements.

Key features

  • Single sign-on across applications
  • OAuth 2.x, OpenID Connect, SAML 2.0, and CAS
  • SCIM provisioning and user lifecycle management
  • RBAC permission management
  • LDAP, Active Directory, and MFA integration
  • Multi-tenancy support

Pricing: Free and open source under the Apache-2.0 license.

Read more about MaxKeyWebsite GitHub

SimpleSAMLphp

SimpleSAMLphp is a PHP authentication application that acts as a SAML 2.0 service provider or identity provider and supports CAS, OpenID Connect and OAuth.

GitHub stars
1.1k
Last commit
yesterday
Latest release
v2.5.3.1
Licence
LGPL-2.1
Self-hosted
Yes
simplesamlphp.orgSimpleSAMLphp homepage screenshot

SimpleSAMLphp is an application written in native PHP that deals with authentication. Its main focus is SAML 2.0, where it can act either as a service provider that protects a web application or as an identity provider that authenticates users, which makes it common in universities and organizations using federated login.

It also supports other identity protocols and frameworks including CAS, OpenID Connect, WS-Federation and OAuth, and it is easy to extend with custom modules. The project site offers downloads, documentation, security announcements, modules and support, and the community-led project publishes regular releases, with security releases announced on its mailing list in advance.

SimpleSAMLphp is licensed under LGPL-2.1 and installed on your own PHP web server, so it is self-hosted. The project is run by a board and community of contributors. It suits developers and identity administrators who need to connect PHP applications to a SAML federation or run a lightweight identity provider.

Key features

  • SAML 2.0 service provider
  • SAML 2.0 identity provider
  • CAS, OpenID Connect, and WS-Federation support
  • OAuth support
  • Extensible through modules
  • Regular releases with security announcements

Pricing: Free and open source under the LGPL-2.1 licence.

OpenAM

OpenAM is an open-source Java access management platform offering single sign-on, federation, authentication and policy-based authorization.

GitHub stars
897
Last commit
yesterday
Latest release
16.1.3
Self-hosted
Yes
openidentityplatform.orgOpenAM homepage screenshot

OpenAM, from the Open Identity Platform community, is an access management solution that covers authentication, single sign-on, authorization, federation, entitlements and web services security. It is meant for organizations that want to own and protect their users' digital identities rather than hand them to an outside provider.

Cross-domain single sign-on, SAML 2.0, OAuth 2.0 and OpenID Connect let it integrate with legacy, custom and cloud applications without changing them. Authentication can combine methods such as password, OTP, saved cookie and QR, and third-party identity providers can be used through SAML, OAuth2, NTLM and Kerberos. Policies can be role-, attribute- or authentication-level-based and can be scripted, using OpenIG or the OpenAM Policy Agent.

OpenAM's pluggable architecture allows custom authentication modules, user data sources, session data sources and post-authentication logic. It is written in Java and licensed under the Common Development and Distribution License; distribution packages are available for download. Because it is software you deploy yourself, you run and operate it on your own infrastructure.

Key features

  • Single sign-on across domains
  • SAML 2.0, OAuth 2.0 and OpenID Connect
  • Multiple authentication methods and OTP
  • Role- and attribute-based access policies
  • Federation as identity or service provider
  • Pluggable custom modules
  • Kerberos and NTLM identity provider support

Pricing: Free and open source under the Common Development and Distribution License (CDDL).

Read more about OpenAMWebsite GitHub

WSO2 Identity Server

WSO2 Identity Server is an open-source identity and access management platform for single sign-on, federation and API access control, deployable on-premises or in the cloud.

GitHub stars
881
Last commit
today
Latest release
v7.3.0
Licence
Apache-2.0
Self-hosted
Yes
Hosted version
Available
wso2.github.ioWSO2 Identity Server homepage screenshot

WSO2 Identity Server is an identity and access management solution that organizations can run on premises or in their own cloud environment. It is meant to secure applications for external consumers, an internal workforce, business customers and partners, and API access.

Standards support includes OAuth 2.0, OpenID Connect and SAML 2.0, with single sign-on, multi-factor and adaptive authentication. Recent versions add a visual designer for authentication flows, templates for configuring apps and login methods, simplified role-based access control for API policies, and a new authentication API for in-app login. AI-assisted features can generate flows from natural language descriptions and match branding. B2B capabilities include delegated administration and per-customer login options.

The code is Java and Apache-2.0 licensed. For teams that prefer not to operate it, WSO2 points to Asgardeo, a public identity cloud service built on the same technology core, which it says can be tried free of charge.

Key features

  • SSO with OAuth 2.0, OIDC and SAML 2.0
  • Multi-factor and adaptive authentication
  • Visual designer for login flows
  • Fine-grained role-based API access
  • B2B delegated administration
  • AI-assisted authentication flow generation
  • Templates for app configuration

Pricing: Open source under Apache-2.0; the hosted Asgardeo service is described by WSO2 as free to try.

Ping Identity alternatives: questions

What is the best open-source alternative to Ping Identity?
Keycloak is the top-ranked open-source alternative to Ping Identity on Enlisted: Keycloak is an open-source identity and access management server that adds single sign-on, user management and authorization to applications. Other strong options are Authentik, Apereo CAS, MaxKey and SimpleSAMLphp.
Are these Ping Identity alternatives free?
All 7 are open source, so the code is free to use under its licence, and all of them can be self-hosted on your own server or computer. 1 also offers a paid or managed cloud version if you'd rather not host it yourself.
How is this list of Ping Identity alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 7 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all