7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

mod_auth_openidc

Open source

mod_auth_openidc is an OpenID Certified Apache HTTP Server module that adds OpenID Connect and FAPI 2 Relying Party login to web applications.

openidc.com
mod_auth_openidc homepage screenshot
GitHub stars
1.1k
Last commit
yesterday
Repository age
12 years
Version
v2.4.20.3
Licence
Apache-2.0
Self-hosted
Yes

About mod_auth_openidc

mod_auth_openidc is an authentication and authorization module for the Apache 2.x HTTP server. It lets Apache act as an OpenID Connect Relying Party that delegates user login to an OpenID Connect Provider, then passes the resulting identity information to the applications it protects. The README says it is OpenID Certified and also covers FAPI 2.

Because the module sits in the web server, it can protect content hosted by Apache itself or applications behind Apache acting as a reverse proxy, which makes it possible to add single sign-on to existing applications without modifying them. By default it sets REMOTE_USER from the ID token's subject and issuer, and other claims are passed on in HTTP headers or environment variables. Authorization rules can be written with Apache's Require primitives, and clustering can be configured for resilience and performance.

The module is written in C and licensed under Apache-2.0, and it is installed on your own Apache servers. It suits system administrators who want to migrate legacy applications from older authentication methods to standards-based OpenID Connect at the web server layer.

Key features

  • OpenID Connect Relying Party for Apache
  • FAPI 2 support
  • Claims passed in headers and environment variables
  • Authorization rules with Apache Require directives
  • Works in reverse proxy setups
  • Clustering support for resilience

Good fit for

  • →Adding SSO to an application without code changes
  • →Replacing legacy authentication with OpenID Connect
  • →Protecting reverse-proxied services with an identity provider
Built with
C
Tags
openid-connect
apache
sso
authentication
oidc
fapi
reverse-proxy
apache-module
access-control

mod_auth_openidc: questions and answers

What is mod_auth_openidc used for?
mod_auth_openidc is an OpenID Certified Apache HTTP Server module that adds OpenID Connect and FAPI 2 Relying Party login to web applications. It is a good fit for adding SSO to an application without code changes, replacing legacy authentication with OpenID Connect and protecting reverse-proxied services with an identity provider.
Is mod_auth_openidc open source?
Yes. mod_auth_openidc is open source under the Apache-2.0 licence. Its source code is on GitHub at OpenIDC/mod_auth_openidc and is written mainly in C.
Is mod_auth_openidc free?
Yes. mod_auth_openidc is open source, so the software itself is free to use.
Can I self-host mod_auth_openidc?
Yes. mod_auth_openidc can be self-hosted on your own server or infrastructure; there is no official hosted version.
What are some alternatives to mod_auth_openidc?
Similar open-source tools in the Auth & Identity category include OAuth2 Proxy, Tinyauth and Caddy Security. SaaS products in the same category include Authress, Auth0 and Clerk.
Is mod_auth_openidc actively maintained?
Yes. The most recent commit to mod_auth_openidc was on 1 October 2026, and the latest release is v2.4.20.3, published on 1 September 2026. The project has 1.1k stars on GitHub.

Open-source alternatives to mod_auth_openidc

See all

SaaS alternatives to mod_auth_openidc

See all