About Kanidm
Kanidm is an identity management platform written in Rust. Other applications and services can offload authentication and identity storage to it, and the project aims to be a complete identity provider so that you should not need to add components such as Keycloak next to it.
It covers a broad set of protocols and features: OpenID Connect, LDAP, RADIUS, SCIM, WebAuthn passkeys and SSH key authentication, according to the repository topics. To keep it manageable, the design favors secure defaults, minimal configuration and components that repair themselves, so the same system can serve small home labs, families and small businesses as well as larger deployments.
Kanidm is licensed under MPL-2.0 and runs on your own servers, with documentation and a community around the project. It suits administrators who want a single, secure place to manage users, groups and logins for their services without operating a heavyweight identity stack.
Key features
- OpenID Connect identity provider
- LDAP and RADIUS interfaces
- WebAuthn and passkey authentication
- SSH key authentication support
- SCIM user provisioning support
- Strict secure defaults, simple configuration
Good fit for
- →Single sign-on for a home lab
- →Central login for small business services
- →Replacing Keycloak with a simpler server
- Built with
- Rust
- Tags
- identity-management
- oidc
- ldap
- radius
- webauthn
- sso
- rust
- self-hosted
Kanidm: questions and answers
- What is Kanidm used for?
- Kanidm is a Rust identity management server offering OIDC, LDAP, RADIUS, WebAuthn and SSH key authentication for home labs through organizations. It is a good fit for single sign-on for a home lab, central login for small business services and replacing Keycloak with a simpler server.
- Is Kanidm open source?
- Yes. Kanidm is open source under the MPL-2.0 licence. Its source code is on GitHub at kanidm/kanidm and is written mainly in Rust.
- Is Kanidm free?
- Yes. Kanidm is open source, so the software itself is free to use.
- Can I self-host Kanidm?
- Yes. Kanidm can be self-hosted on your own server or infrastructure; there is no official hosted version.
- What is Kanidm an alternative to?
- Kanidm is an open-source alternative to JumpCloud, Microsoft Entra ID, Okta and IBM Verify. Other open-source alternatives to JumpCloud include Authentik, Authelia and FreeIPA.
- Is Kanidm actively maintained?
- Yes. The most recent commit to Kanidm was on 2 October 2026, and the latest release is v1.11.2, published on 11 September 2026. The project has 5.4k stars on GitHub.
Open-source alternatives to Kanidm
See all
Authentik
Auth & Identity
The authentication glue you need.
OSSvs Auth0★ 26k
Authelia
Auth & Identity
The Single Sign-On Multi-Factor portal for web apps. OpenID Certified™ and Post-Quantum Cr
Apache-2.0vs OneLogin★ 29k
FreeIPA
Auth & Identity
Mirror of FreeIPA, an integrated security information management solution
GPL-3.0vs Microsoft Entra ID★ 1.3k
Casdoor
Auth & Identity
An open-source Agent-first Identity and Access Management (IAM) /LLM MCP & agent gateway a
Apache-2.0vs Auth0★ 15k
Keycloak
Auth & Identity
Open Source Identity and Access Management For Modern Applications and Services
Apache-2.0vs Auth0★ 37k
ZITADEL
Auth & Identity
ZITADEL - Identity infrastructure, simplified for you.
AGPL-3.0vs Auth0★ 15k
SaaS alternatives to Kanidm
See all
JumpCloud
Auth & Identity
Cloud directory for identity, device management and SSO
SaaS
Microsoft Entra ID
Auth & Identity
Microsoft cloud identity service for SSO, MFA and conditional access, formerly Azure AD
SaaS
Okta
Auth & Identity
Cloud identity platform for workforce single sign-on, multifactor authentication and lifecycle management
SaaS
IBM Verify
Auth & Identity
IBM SSO, MFA and identity governance for workforce and customer identities
SaaS
Duo Security
Auth & Identity
Cisco's multi-factor authentication and device trust service for workforces
SaaS
OneLogin
Auth & Identity
Cloud single sign-on and MFA for workforce identity, from One Identity
SaaS

