ZITADEL
An open-source identity and access management platform with SSO, MFA, passkeys, OIDC, SAML, SCIM and native multi-tenancy, available self-hosted or as a cloud service.
- GitHub stars
- 15k
- Last commit
- today
- Latest release
- v4.19.4
- Licence
- AGPL-3.0
- Self-hosted
- Yes
- Hosted version
- Available

ZITADEL is an identity and access management platform, open source, for teams that need more than basic login. It targets SaaS products, B2B platforms and self-hosted IAM stacks, and bundles single sign-on, multi-factor authentication, passkeys, OIDC, SAML and SCIM in an API-first design, with an emphasis on a mature multi-tenancy model.
A comparison table in the README sets it against FusionAuth, Keycloak and Auth0 or Okta on points such as open-source status, self-hosting, infrastructure-level tenants, native B2B organizations and a comprehensive event-stream audit trail. Topics list standards and features including OAuth 2, OpenID Connect, FIDO2, 2FA and passkeys. The positioning is that you can own the identity layer without vendor lock-in while still getting a polished product.
ZITADEL is written in Go and licensed under AGPL-3.0, with a website, chat, docs and blog. You can run it yourself or use the vendor's managed cloud. It suits developers and security teams building multi-tenant applications who want a self-hostable alternative to commercial identity providers.
Key features
- Single sign-on with OIDC and SAML
- Multi-factor authentication and passkeys
- SCIM user provisioning support
- Native multi-tenancy with B2B organizations
- Event-stream audit trail
- API-first, self-hostable design
Pricing: Free cloud plan for 100 daily active users. Pro costs $100 per month and includes 25,000 daily active users; Enterprise is custom and can run on your own infrastructure.



