Best Self-hosted SSO & Federated Identity (OIDC/SAML) tools in 2026

18 self-hosted open source alternatives in this category

18 services found

Keycloak

Keycloak

Open-source identity and access management with SSO

33k
8.1k
Last commit: 14h ago

Keycloak is an open-source IAM server providing single sign-on, user federation, and centralized authentication and authorization using OIDC, OAuth 2.0, and SAML.

Alternative to:
Okta
Okta
+19
Authelia

Authelia

Self-hosted IAM with SSO and multi-factor authentication

26.9k
1.3k
Last commit: 14h ago

Authelia is an open-source IAM and authentication server providing SSO, MFA, and access control for web apps, with OpenID Connect/OAuth 2.0 and reverse-proxy integration.

Alternative to:
Auth0
Auth0
+16
authentik

authentik

Open-source Identity Provider (IdP) for SSO, OIDC, and SAML

20.3k
1.5k
Last commit: 9h ago

Open-source IdP delivering SSO, OAuth2/OIDC, SAML2, LDAP, RADIUS, MFA, WebAuthn, conditional access and application-proxy capabilities for self-hosted deployments.

Alternative to:
Okta
Okta
+19
OAuth2 Proxy

OAuth2 Proxy

Reverse proxy and middleware for OAuth2/OIDC authentication

13.9k
2k
Last commit: 6d ago

OAuth2 Proxy is a reverse proxy and middleware that protects web apps with OAuth2/OIDC login and forwards authenticated user identity to upstream services.

Alternative to:
Cloudflare Access
Cloudflare Access
+14
ZITADEL

ZITADEL

API-first identity and access management platform for applications

13.1k
947
Last commit: 10h ago

ZITADEL is an open source IAM/CIAM platform providing SSO, MFA, OIDC/OAuth2, SAML, user management, and multi-tenant organizations with audit logging.

Alternative to:
Auth0
Auth0
+19
Casdoor

Casdoor

UI-first IAM and SSO platform for modern authentication

13.1k
1.6k
Last commit: 1d ago

Casdoor is an open-source, UI-first IAM/SSO platform supporting OAuth 2.0, OIDC, SAML, LDAP, SCIM, WebAuthn and MFA, with an admin web UI and SDKs.

Alternative to:
Okta
Okta
+19
Logto

Logto

Authentication and authorization platform for apps and APIs

11.6k
713
Last commit: 19h ago

Open-source authentication and authorization infrastructure with OIDC/OAuth 2.1, SAML SSO, multi-tenancy, MFA, and RBAC for SaaS and AI apps.

Alternative to:
Auth0
Auth0
+19
Pocket ID

Pocket ID

A passkey-only OpenID Connect identity provider

6.7k
199
Last commit: 2d ago

Pocket ID is a simple self-hosted OpenID Connect (OIDC) provider that lets users sign in to apps using passkeys instead of passwords.

Alternative to:
Auth0
Auth0
+19
MeshCentral

MeshCentral

Open-source web-based remote device management and remote desktop server

6.2k
813
Last commit: 20h ago

Self-hosted Node.js server for remote monitoring, web-based remote desktop, terminal, file access and multi-DB device management.

Alternative to:
TeamViewer
TeamViewer
+14
Kanidm

Kanidm

Simple, secure identity management and SSO provider

4.6k
296
Last commit: 20h ago

Kanidm is a secure identity management platform providing SSO, passkeys (WebAuthn), and integrations like OAuth2/OIDC, RADIUS, and LDAP gateway for legacy apps.

Alternative to:
Okta
Okta
+19
Wizarr

Wizarr

User invitation and management system for media servers

2.7k
166
Last commit: 18h ago

Wizarr automates user invitations and onboarding for Plex, Jellyfin, Emby and similar media servers, with SSO, time-limited access, Discord and request-system integration...

VoidAuth

VoidAuth

Self-hosted SSO and user management with OpenID Connect and ForwardAuth

1.8k
56
Last commit: 2d ago

VoidAuth is a self-hosted SSO provider with OpenID Connect, ForwardAuth proxy auth, and built-in user and group management plus MFA and passkeys.

Alternative to:
Auth0
Auth0
+19
Authgear

Authgear

Identity and authentication platform for apps and APIs

1.4k
98
Last commit: 12d ago

Open-source Auth0/Clerk/Firebase Auth alternative with passkeys, MFA, SSO (OIDC/SAML), user management portal, and extensible auth flows for web and mobile apps.

Alternative to:
Auth0
Auth0
+19
Melody Auth

Melody Auth

OAuth 2.0 and authentication server for Cloudflare Workers or Node.js

586
54
Last commit: 21d ago

Turnkey OAuth 2.0/OIDC authentication system with admin panel, REST APIs, RBAC, MFA, social login, and flexible deployment on Cloudflare Workers or Node.js.

Alternative to:
Auth0
Auth0
+19
VaulTLS

VaulTLS

Web application to generate and manage mTLS certificates.

322
8
Last commit: 25d ago

Self-hosted web app to generate, manage and distribute mTLS client and server certificates with OIDC auth, email alerts and a REST API.

Alternative to:
Venafi TLS Protect
Venafi TLS Protect
+5
AuthPortal

AuthPortal

Self-hosted SSO gateway for Plex, Jellyfin and Emby

84
1
Last commit: 19d ago

Lightweight Go-based authentication gateway that provides unified SSO for Plex, Jellyfin, and Emby users with OIDC, MFA and an admin console. Runs in Docker and stores pr...

Alternative to:
Auth0
Auth0
+19
Stackspin

Stackspin

Open source collaboration suite with SSO and admin dashboard

Stackspin is an open source platform that bundles common team collaboration apps with single sign-on, centralized user management, backups, and monitoring for admins.

Alternative to:
Google Workspace
Google Workspace
+19
FusionAuth

FusionAuth

Self-hosted identity and access management for applications

FusionAuth is a self-hosted authentication and IAM platform supporting OAuth2, OIDC and SAML, with SSO, MFA, user management and developer-focused integrations.

Alternative to:
Auth0
Auth0
+19