7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

Rauthy

Open source

Rauthy is a lightweight single sign-on identity provider written in Rust, supporting OpenID Connect, OAuth 2, PAM and passkey-first logins.

Open-source alternative to

sebadob.github.io
Rauthy homepage screenshot
GitHub stars
1.4k
Last commit
yesterday
Repository age
3 years
Version
v0.36.2
Licence
Apache-2.0
Self-hosted
Yes

About Rauthy

Rauthy is an identity and access management server written in Rust. It acts as a single sign-on identity provider supporting OpenID Connect, OAuth 2 and PAM, and it aims to be simple to set up and run while keeping secure defaults. The project received an independent security audit as part of its funding, and the findings were addressed in a later release.

It puts heavy emphasis on passkeys and strong security, with FIDO2 and WebAuthn login options, MFA and passwordless flows. Defaults include ed25519 token signing and S256 PKCE for new OIDC clients, though these can be relaxed for older systems. Other features include high availability, client branding, UI translation, an admin UI, events and auditing, SCIM, and support for IoT and headless CLI tools.

By default Rauthy runs on top of Hiqlite, so it needs no external database, with Postgres available as an alternative. It is licensed under Apache-2.0, can run on modest hardware, and is self-hosted. Its topics reference Keycloak as the kind of software it can replace, so it suits small teams and homelabs that want a compact SSO server.

Key features

  • OpenID Connect and OAuth 2 provider
  • PAM integration for Linux logins
  • Passkeys, FIDO2, and WebAuthn
  • Admin UI with events and auditing
  • Built-in database with optional Postgres
  • SCIM and client branding support

Good fit for

  • →Single sign-on for self-hosted apps
  • →Replacing Keycloak with a lighter server
  • →Passkey-based login for internal tools
Built with
Rust
Tags
sso
oidc
oauth2
identity-provider
passkeys
webauthn
rust
pam
self-hosted
iam

Rauthy: questions and answers

What is Rauthy used for?
Rauthy is a lightweight single sign-on identity provider written in Rust, supporting OpenID Connect, OAuth 2, PAM and passkey-first logins. It is a good fit for single sign-on for self-hosted apps, replacing Keycloak with a lighter server and passkey-based login for internal tools.
Is Rauthy open source?
Yes. Rauthy is open source under the Apache-2.0 licence. Its source code is on GitHub at sebadob/rauthy and is written mainly in Rust.
Is Rauthy free?
Yes. Rauthy is open source, so the software itself is free to use.
Can I self-host Rauthy?
Yes. Rauthy can be self-hosted on your own server or infrastructure.
What is Rauthy an alternative to?
Rauthy is an open-source alternative to Auth0, Microsoft Entra ID and OneLogin. Other open-source alternatives to Auth0 include Authentik, Keycloak and Casdoor.
Is Rauthy actively maintained?
Yes. The most recent commit to Rauthy was on 2 October 2026, and the latest release is v0.36.2, published on 8 August 2026. The project has 1.4k stars on GitHub.

Open-source alternatives to Rauthy

See all

SaaS alternatives to Rauthy

See all