privacyIDEA
An open-source authentication server for managing two-factor and multi-factor logins with OTP tokens, push, FIDO2 keys and passkeys across an organization.
- GitHub stars
- 1.8k
- Last commit
- yesterday
- Latest release
- v3.14
- Licence
- AGPL-3.0
- Self-hosted
- Yes

privacyIDEA is an open-source authentication server that manages multi-factor authentication for an organization. It issues and verifies second factors such as one-time passwords, hardware tokens, push notifications and FIDO2 or WebAuthn security keys, so applications and servers can add two-factor login without each building its own token handling.
The server is written in Python and exposes an API that other systems can call to check a login attempt. Its topics point to support for OTP, passkeys, push authentication and certificates, and administrators enroll and manage tokens centrally rather than configuring every service by hand. The project documentation includes how-tos for running it behind Apache2 with MySQL and for protecting a whole server farm.
privacyIDEA is released under the AGPL-3.0 licence and can be self-hosted, which keeps token data and user policies on infrastructure you control. The project website also lists an Enterprise Edition next to the community version, along with a demo site, screenshots and community resources for anyone evaluating it.
Key features
- OTP, push, and hardware token support
- FIDO2, WebAuthn, and passkey authentication
- REST API for application integration
- Central web interface for token enrollment
- Policy-based control of authentication rules
- Certificate and CA related features
Pricing: The community edition is free and open source under AGPL-3.0; an Enterprise Edition is also listed on the project website.