
Kanidm
Simple, secure identity management and SSO provider
5.3k stars 354 forks last commit first released MPL-2.0
Actively maintained
Last commit 26 Aug 2026.

Kanidm is an identity management platform that centralizes users, groups, and authentication for your applications and infrastructure. It focuses on secure defaults, simple operations, and built-in capabilities so services can offload identity and access management to a single provider.
Key Features
- OAuth2/OIDC provider for single sign-on (SSO)
- WebAuthn passkeys support, including attested passkeys for higher assurance
- Application portal for launching and accessing linked applications
- Linux/Unix integration, including offline authentication support
- SSH public key distribution for Unix systems
- RADIUS support for network and VPN authentication
- Read-only LDAPS gateway for legacy LDAP-dependent systems
- Administration via CLI tooling plus Web UI for user self-service
- Two-node high availability using database replication
Use Cases
- Replace fragmented credentials with centralized SSO for internal web apps
- Provide strong phishing-resistant authentication using passkeys
- Manage Unix fleet access with centralized identities and SSH key delivery
Limitations and Considerations
- Administrative workflows are primarily CLI-driven, while the Web UI is focused on end-user self-service
Kanidm is a strong fit when you want a unified identity provider with modern authentication (passkeys) plus practical infrastructure integrations (Unix, SSH, RADIUS). It aims to deliver enterprise-grade capabilities with a streamlined operational model and secure-by-default design.
Categories:
Tags:
Tech Stack:
Similar to Kanidm
Keycloak
Open-source identity and access management with SSO
Keycloak is an open-source IAM server providing single sign-on, user federation, and centralized authentication and authorization using OIDC, OAuth 2.0, and SAML.

Casdoor
UI-first IAM and SSO platform for modern authentication
Casdoor is an open-source, UI-first IAM/SSO platform supporting OAuth 2.0, OIDC, SAML, LDAP, SCIM, WebAuthn and MFA, with an admin web UI and SDKs.
VoidAuth
Self-hosted SSO and user management with OpenID Connect and ForwardAuth
VoidAuth is a self-hosted SSO provider with OpenID Connect, ForwardAuth proxy auth, and built-in user and group management plus MFA and passkeys.

Authelia
Self-hosted IAM with SSO and multi-factor authentication
Authelia is an open-source IAM and authentication server providing SSO, MFA, and access control for web apps, with OpenID Connect/OAuth 2.0 and reverse-proxy integration.

Logto
Authentication and authorization platform for apps and APIs
Open-source authentication and authorization infrastructure with OIDC/OAuth 2.1, SAML SSO, multi-tenancy, MFA, and RBAC for SaaS and AI apps.

Authgear
Identity and authentication platform for apps and APIs
Open-source Auth0/Clerk/Firebase Auth alternative with passkeys, MFA, SSO (OIDC/SAML), user management portal, and extensible auth flows for web and mobile apps.

