7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

Caddy Security

Open source

Authentication, authorization, and accounting plugin for the Caddy v2 web server, supporting forms, LDAP, OIDC, OAuth 2.0, SAML, MFA, and JWT or PASETO tokens.

authcrunch.com
Caddy Security homepage screenshot
GitHub stars
2.2k
Last commit
4 days ago
Repository age
4 years
Version
v1.3.0
Licence
Apache-2.0
Self-hosted
Yes

About Caddy Security

Caddy Security is a security app for Caddy v2 that bundles three plugins: an authentication plugin, an authorization plugin, and a credentials plugin. It is written in Go, released under the Apache-2.0 license, and sold under the AuthCrunch name on its website. It adds single sign-on style protection in front of anything that Caddy serves.

Authentication supports form-based, basic, local, LDAP, OpenID Connect, OAuth 2.0 with providers such as GitHub, Google, Facebook, and Okta, and SAML. Multi-factor authentication works with authenticator apps and Yubico devices, and topics mention WebAuthn. The authorization plugin checks HTTP requests using JWT or PASETO tokens and access control lists, and the credentials plugin manages secrets for various integrations.

It supports portals as well as direct OAuth policies without a portal, and persistent runtime state can be enabled so sessions and signing keys survive restarts. Caddy Security suits homelab users and teams who already run Caddy as a reverse proxy and want built-in login and access control without a separate identity gateway.

Key features

  • Form, basic, LDAP, OIDC, OAuth 2.0, and SAML login
  • Multi-factor authentication with Yubico
  • JWT and PASETO token authorization
  • Access control lists for routes
  • Credentials management plugin
  • Persistent sessions across restarts

Good fit for

  • →Protecting self-hosted apps behind Caddy
  • →Adding SSO login to a reverse proxy
Built with
Go
Tags
caddy
authentication
authorization
sso
oidc
saml
mfa
reverse-proxy

Caddy Security: questions and answers

What is Caddy Security used for?
Caddy Security is an authentication, authorization, and accounting plugin for the Caddy v2 web server, supporting forms, LDAP, OIDC, OAuth 2.0, SAML, MFA, and JWT or PASETO tokens. It is a good fit for protecting self-hosted apps behind Caddy and adding SSO login to a reverse proxy.
Is Caddy Security open source?
Yes. Caddy Security is open source under the Apache-2.0 licence. Its source code is on GitHub at greenpau/caddy-security and is written mainly in Go.
Is Caddy Security free?
Yes. Caddy Security is open source, so the software itself is free to use.
Can I self-host Caddy Security?
Yes. Caddy Security can be self-hosted on your own server or infrastructure; there is no official hosted version.
What are some alternatives to Caddy Security?
Similar open-source tools in the Auth & Identity category include Casdoor, Keycloak and Authentik. SaaS products in the same category include Stytch, Auth0 and Authress.
Is Caddy Security actively maintained?
Yes. The most recent commit to Caddy Security was on 29 September 2026, and the latest release is v1.3.0, published on 28 September 2026. The project has 2.2k stars on GitHub.

Open-source alternatives to Caddy Security

See all

SaaS alternatives to Caddy Security

See all