5,756 open-source and SaaS tools, with GitHub stats refreshed every day.

Tinyauth

Open source

A small, OpenID-certified authentication and authorization server that works as middleware for reverse proxies such as Traefik, Nginx and Caddy or as a standalone server.

tinyauth.app
Tinyauth homepage screenshot
GitHub stars
8.3k
Last commit
today
Repository age
20 months
Version
v5.2.0
Licence
AGPL-3.0
Self-hosted
Yes

About Tinyauth

Tinyauth is a minimal authentication and authorization server aimed at self-hosters and homelabs. It can sit in front of your apps as authentication middleware, with support for OAuth, LDAP and access controls, or run on its own as a standalone server, and it works with common proxies including Traefik, Nginx and Caddy.

The project reports that version 5.1.0 achieved OpenID Certification for the Basic OP profile, and its topics mention OIDC, SSO and two-factor authentication with TOTP. A docker-compose file demonstrates it alongside Traefik and a whoami test service, and a public demo and documentation site explain the configuration options.

Tinyauth is written in Go and licensed under AGPL-3.0. The README warns that it is in active development and that configuration may change often, so release notes should be read before updating. It suits people who want single sign-on for self-hosted services without running a heavier identity platform.

Key features

  • Authentication middleware for reverse proxies
  • OIDC provider with OpenID Certification
  • OAuth and LDAP support
  • Access controls per application
  • TOTP two-factor authentication
  • Traefik, Nginx and Caddy integration
  • Docker Compose example

Good fit for

  • →Protecting self-hosted apps behind Traefik
  • →Single sign-on for a homelab
  • →Lightweight alternative to larger identity servers
Built with
Go
Tags
authentication
sso
oidc
oauth
self-hosted
traefik
reverse-proxy
homelab
golang

Open-source alternatives to Tinyauth

See all

SaaS alternatives to Tinyauth

See all