Best Self-hosted Identity & Access Management (IAM) tools in 2026

37 self-hosted open source alternatives in this category

37 services found

PocketBase

PocketBase

Lightweight open-source realtime backend with embedded SQLite

56.4k
3.1k
Last commit: 4d ago

Open-source Go backend providing embedded SQLite, realtime (SSE) subscriptions, auth (JWT/OAuth2), file storage, admin UI and REST-style APIs for web and mobile apps.

Alternative to:
PocketBase Cloud
PocketBase Cloud
+17
Keycloak

Keycloak

Open-source identity and access management with SSO

33k
8.1k
Last commit: 14h ago

Keycloak is an open-source IAM server providing single sign-on, user federation, and centralized authentication and authorization using OIDC, OAuth 2.0, and SAML.

Alternative to:
Okta
Okta
+19
Authelia

Authelia

Self-hosted IAM with SSO and multi-factor authentication

26.9k
1.3k
Last commit: 14h ago

Authelia is an open-source IAM and authentication server providing SSO, MFA, and access control for web apps, with OpenID Connect/OAuth 2.0 and reverse-proxy integration.

Alternative to:
Auth0
Auth0
+16
Infisical

Infisical

Open-source platform for secrets, PKI certificates, and privileged access

25.1k
1.7k
Last commit: 9h ago

Infisical is an open-source platform to manage and deliver app secrets, certificates (PKI), SSH credentials, and encryption keys across teams and infrastructure.

Alternative to:
HashiCorp Vault
HashiCorp Vault
+9
authentik

authentik

Open-source Identity Provider (IdP) for SSO, OIDC, and SAML

20.3k
1.5k
Last commit: 9h ago

Open-source IdP delivering SSO, OAuth2/OIDC, SAML2, LDAP, RADIUS, MFA, WebAuthn, conditional access and application-proxy capabilities for self-hosted deployments.

Alternative to:
Okta
Okta
+19
Teleport

Teleport

Identity-aware access proxy for infrastructure and internal apps

19.9k
2k
Last commit: 9h ago

Secure access platform for servers, Kubernetes, databases, desktops, and web apps with SSO/MFA, short-lived certificates, and full session auditing.

Alternative to:
Twingate
Twingate
+16
OAuth2 Proxy

OAuth2 Proxy

Reverse proxy and middleware for OAuth2/OIDC authentication

13.9k
2k
Last commit: 6d ago

OAuth2 Proxy is a reverse proxy and middleware that protects web apps with OAuth2/OIDC login and forwards authenticated user identity to upstream services.

Alternative to:
Cloudflare Access
Cloudflare Access
+14
ZITADEL

ZITADEL

API-first identity and access management platform for applications

13.1k
947
Last commit: 10h ago

ZITADEL is an open source IAM/CIAM platform providing SSO, MFA, OIDC/OAuth2, SAML, user management, and multi-tenant organizations with audit logging.

Alternative to:
Auth0
Auth0
+19
Casdoor

Casdoor

UI-first IAM and SSO platform for modern authentication

13.1k
1.6k
Last commit: 1d ago

Casdoor is an open-source, UI-first IAM/SSO platform supporting OAuth 2.0, OIDC, SAML, LDAP, SCIM, WebAuthn and MFA, with an admin web UI and SDKs.

Alternative to:
Okta
Okta
+19
Logto

Logto

Authentication and authorization platform for apps and APIs

11.6k
713
Last commit: 19h ago

Open-source authentication and authorization infrastructure with OIDC/OAuth 2.1, SAML SSO, multi-tenancy, MFA, and RBAC for SaaS and AI apps.

Alternative to:
Auth0
Auth0
+19
Tinyauth

Tinyauth

Lightweight authentication middleware for protecting web apps

7k
222
Last commit: 1d ago

Tinyauth is a lightweight auth middleware that adds a login screen, OAuth, or LDAP authentication in front of your apps via common reverse proxies.

Alternative to:
Cloudflare Access
Cloudflare Access
+17
Pocket ID

Pocket ID

A passkey-only OpenID Connect identity provider

6.7k
199
Last commit: 2d ago

Pocket ID is a simple self-hosted OpenID Connect (OIDC) provider that lets users sign in to apps using passkeys instead of passwords.

Alternative to:
Auth0
Auth0
+19
Warpgate

Warpgate

Transparent bastion and PAM for SSH, HTTPS, MySQL and PostgreSQL

6.6k
239
Last commit: 7d ago

Self-hosted transparent bastion host and PAM for SSH, HTTPS, MySQL and Postgres with RBAC, session recording, and SSO/2FA—no client-side software required.

Alternative to:
Teleport
Teleport
+7
LLDAP

LLDAP

Lightweight LDAP authentication server with a web UI

6k
315
Last commit: 1d ago

LLDAP is a lightweight LDAP server for authentication and user management, providing a simplified LDAP interface, a web admin UI, and SQLite/MySQL/PostgreSQL backends.

Alternative to:
Microsoft Active Directory
Microsoft Active Directory
+2
Cosmos Cloud

Cosmos Cloud

Security-first self-hosting platform with reverse proxy, SSO, and apps

5.7k
206
Last commit: 1mo ago

Cosmos Cloud is a security-focused self-hosting platform that provides an app store, reverse proxy with automatic HTTPS, SSO/MFA, container management, backups, and monit...

Alternative to:
Cloudron
Cloudron
+18
Pomerium

Pomerium

Identity- and context-aware access proxy for zero trust access

4.7k
321
Last commit: 11h ago

Pomerium is an identity-aware access proxy that provides zero trust, per-request authorization to internal web apps and services without a traditional VPN.

Alternative to:
Cloudflare Access
Cloudflare Access
+12
Kanidm

Kanidm

Simple, secure identity management and SSO provider

4.6k
296
Last commit: 20h ago

Kanidm is a secure identity management platform providing SSO, passkeys (WebAuthn), and integrations like OAuth2/OIDC, RADIUS, and LDAP gateway for legacy apps.

Alternative to:
Okta
Okta
+19
Cerbos

Cerbos

Context-aware authorization and access control policy engine

4.2k
170
Last commit: 2d ago

Cerbos is a scalable, language-agnostic authorization layer for defining and evaluating context-aware access control policies via a dedicated Policy Decision Point (PDP)...

Alternative to:
OSO Cloud
OSO Cloud
+17
2FAuth

2FAuth

Web-based TOTP/HOTP authenticator and 2FA account manager

3.8k
273
Last commit: 1mo ago

Open-source web app to manage TOTP/HOTP 2FA accounts: scan QR codes, generate one-time codes, import/export tokens, and protect access with WebAuthn and optional encrypti...

Alternative to:
Google Authenticator
Google Authenticator
+3
GLAuth

GLAuth

Lightweight LDAP authentication server with pluggable backends

2.8k
238
Last commit: 6mo ago

GLAuth is a lightweight LDAP/LDAPS authentication server for development, CI, and homelabs, supporting file, S3, SQL, or LDAP proxy backends and optional 2FA.

Alternative to:
Microsoft Active Directory
Microsoft Active Directory
+5
Defguard

Defguard

Zero-trust WireGuard VPN with protocol-level MFA and integrated SSO

2.6k
88
Last commit: 8d ago

Enterprise-grade zero-trust access management platform providing WireGuard VPN with true protocol-level 2FA/MFA, plus integrated OpenID Connect SSO and user/device contro...

Alternative to:
Defguard Cloud
Defguard Cloud
+19
VoidAuth

VoidAuth

Self-hosted SSO and user management with OpenID Connect and ForwardAuth

1.8k
56
Last commit: 2d ago

VoidAuth is a self-hosted SSO provider with OpenID Connect, ForwardAuth proxy auth, and built-in user and group management plus MFA and passkeys.

Alternative to:
Auth0
Auth0
+19
TeamPass

TeamPass

Collaborative on-prem password management with RBAC and encryption.

1.8k
566
Last commit: 3d ago

On-prem password manager enabling secure sharing and fine-grained access control over credentials.

Alternative to:
Bitwarden
Bitwarden
+9
Authgear

Authgear

Identity and authentication platform for apps and APIs

1.4k
98
Last commit: 12d ago

Open-source Auth0/Clerk/Firebase Auth alternative with passkeys, MFA, SSO (OIDC/SAML), user management portal, and extensible auth flows for web and mobile apps.

Alternative to:
Auth0
Auth0
+19
Databunker

Databunker

Self-hosted vault for tokenizing and encrypting sensitive records

1.4k
90
Last commit: 3mo ago

Databunker is a self-hosted vault that tokenizes and encrypts PII/PHI/KYC/PCI data, providing a secure API, consent management, and audit trails for compliance.

Alternative to:
Skyflow
Skyflow
Mozilla Accounts (FxA)

Mozilla Accounts (FxA)

Account and authentication service for Mozilla products

663
222
Last commit: 7h ago

Mozilla Accounts (FxA) is an account and authentication service used by Mozilla clients, providing login, session management, and account-related APIs for Mozilla product...

Alternative to:
Auth0
Auth0
+15
Melody Auth

Melody Auth

OAuth 2.0 and authentication server for Cloudflare Workers or Node.js

586
54
Last commit: 21d ago

Turnkey OAuth 2.0/OIDC authentication system with admin panel, REST APIs, RBAC, MFA, social login, and flexible deployment on Cloudflare Workers or Node.js.

Alternative to:
Auth0
Auth0
+19
UniFi Voucher Site

UniFi Voucher Site

Generate and manage UniFi guest WiFi vouchers

264
32
Last commit: 12d ago

Web app to create, print, email, and manage UniFi guest vouchers with OIDC support, kiosk mode, PDF/thermal printing, and a REST API. Deployable via Docker.

Alternative to:
Proxyclick
Proxyclick
+1
Jauth

Jauth

Lightweight TLS reverse proxy with SSH and Telegram authorization

177
8
Last commit: 1y ago

Single-binary TLS reverse proxy for self-hosted apps that provides SSH- and Telegram-based authorization, simple SSO, Let's Encrypt support and whitelist access control.

Alternative to:
Cloudflare Access
Cloudflare Access
+4
Guardian

Guardian

Plex session monitoring and device access control platform

161
3
Last commit: 3d ago

Open-source companion app for Plex Media Server to monitor live streams, enforce per-user device access, and automate session blocking with notifications and schedules.

Alternative to:
Tautulli
Tautulli