Ping Identity logo

20 self-hosted Ping Identity alternatives

Enterprise identity and access management (IAM) platform providing single sign-on (SSO), multi‑factor authentication (MFA), directory and API access management, federation (SAML/OIDC/OAuth), and identity governance to secure workforce and customer access across cloud and on‑premises apps.

Alternatives to Ping Identity

Keycloak is an open-source IAM server providing single sign-on, user federation, and centralized authentication and authorization using OIDC, OAuth 2.0, and SAML.

Keycloak screenshot

36.4k stars8.9k forksApache-2.0last commit Actively maintained

Authelia is an open-source IAM and authentication server providing SSO, MFA, and access control for web apps, with OpenID Connect/OAuth 2.0 and reverse-proxy integration.

Authelia screenshot

28.7k stars1.5k forksApache-2.0last commit Actively maintained

Open-source IdP delivering SSO, OAuth2/OIDC, SAML2, LDAP, RADIUS, MFA, WebAuthn, conditional access and application-proxy capabilities for self-hosted deployments.

authentik screenshot

25.2k stars2k forkslast commit Actively maintained

OAuth2 Proxy is a reverse proxy and middleware that protects web apps with OAuth2/OIDC login and forwards authenticated user identity to upstream services.

OAuth2 Proxy screenshot

14.9k stars2.2k forksMITlast commit Actively maintained

ZITADEL is an open source IAM/CIAM platform providing SSO, MFA, OIDC/OAuth2, SAML, user management, and multi-tenant organizations with audit logging.

14.9k stars1.3k forksAGPL-3.0last commit Actively maintained

Open-source authentication and authorization infrastructure with OIDC/OAuth 2.1, SAML SSO, multi-tenancy, MFA, and RBAC for SaaS and AI apps.

14.5k stars1.2k forksMPL-2.0last commit Actively maintained

Casdoor is an open-source, UI-first IAM/SSO platform supporting OAuth 2.0, OIDC, SAML, LDAP, SCIM, WebAuthn and MFA, with an admin web UI and SDKs.

14.3k stars1.8k forksApache-2.0last commit Actively maintained

Pocket ID is a simple self-hosted OpenID Connect (OIDC) provider that lets users sign in to apps using passkeys instead of passwords.

Pocket ID screenshot

9k stars304 forksBSD-2-Clauselast commit Actively maintained

Tinyauth is a lightweight auth middleware that adds a login screen, OAuth, or LDAP authentication in front of your apps via common reverse proxies.

Tinyauth screenshot

8.2k stars264 forksAGPL-3.0last commit Actively maintained

Kanidm is a secure identity management platform providing SSO, passkeys (WebAuthn), and integrations like OAuth2/OIDC, RADIUS, and LDAP gateway for legacy apps.

Kanidm screenshot

5.3k stars354 forksMPL-2.0last commit Actively maintained

Pomerium is an identity-aware access proxy that provides zero trust, per-request authorization to internal web apps and services without a traditional VPN.

Pomerium screenshot

5k stars350 forksApache-2.0last commit Actively maintained

Cerbos is a scalable, language-agnostic authorization layer for defining and evaluating context-aware access control policies via a dedicated Policy Decision Point (PDP) API.

4.6k stars208 forksApache-2.0last commit Actively maintained

#13

GLAuth is a lightweight LDAP/LDAPS authentication server for development, CI, and homelabs, supporting file, S3, SQL, or LDAP proxy backends and optional 2FA.

2.8k stars240 forksMITlast commit Actively maintained

Enterprise-grade zero-trust access management platform providing WireGuard VPN with true protocol-level 2FA/MFA, plus integrated OpenID Connect SSO and user/device controls.

Defguard screenshot

2.8k stars110 forkslast commit Actively maintained

VoidAuth is a self-hosted SSO provider with OpenID Connect, ForwardAuth proxy auth, and built-in user and group management plus MFA and passkeys.

VoidAuth screenshot

2.5k stars100 forksAGPL-3.0last commit Actively maintained

Open-source Auth0/Clerk/Firebase Auth alternative with passkeys, MFA, SSO (OIDC/SAML), user management portal, and extensible auth flows for web and mobile apps.

Authgear screenshot

2k stars125 forksApache-2.0last commit Actively maintained

Turnkey OAuth 2.0/OIDC authentication system with admin panel, REST APIs, RBAC, MFA, social login, and flexible deployment on Cloudflare Workers or Node.js.

Melody Auth screenshot

635 stars68 forksMITlast commit Actively maintained

A minimal, Rust-based forward authentication middleware for reverse proxies (Traefik, Caddy, nginx) using a passwd file and signed auth tokens.

157 stars8 forksMITlast commit Actively maintained

Lightweight Go-based authentication gateway that provides unified SSO for Plex, Jellyfin, and Emby users with OIDC, MFA and an admin console. Runs in Docker and stores profiles in Postgres.

98 stars1 forksGPL-3.0last commit Actively maintained

What replacing Ping Identity actually involves

Every option on this page is open source and free to run on your own hardware, so you own the data and there is no subscription to cancel. 20 of 20 shipped a commit in the last six months. Licences in this list: Apache-2.0, MIT, AGPL-3.0, MPL-2.0, BSD-2-Clause. In exchange you take on hosting, backups and updates yourself.

Browse everything in Identity & Access Management (IAM).

Other tools people replace alongside Ping Identity