LLDAP

LLDAP

Lightweight LDAP authentication server with a web UI

5.9kstars
310forks
Last commit: 3d ago
Repo age: 5y old

LLDAP is a lightweight authentication server that provides an opinionated, simplified LDAP interface for managing users and groups. It is designed to be easy to set up and operate compared to full LDAP suites, while still integrating with many services that support LDAP authentication.

Key Features

  • Simplified LDAP directory structure focused on users and groups
  • Web UI for user and group management, including self-service profile edits
  • Password reset via email when SMTP is configured
  • Group membership support via memberOf for common LDAP filters
  • Custom attributes management (for compatibility with specific integrations)
  • Multiple storage backends: SQLite by default, with MySQL/MariaDB and PostgreSQL options
  • Scriptable management via a GraphQL API
  • Optional LDAPS support for encrypted LDAP connections

Use Cases

  • Central user directory for self-hosted apps that support LDAP (for example file sync and media apps)
  • LDAP backend (“source of truth”) for an SSO layer such as Authelia, Authentik, or Keycloak
  • Lightweight user/group management for homelabs and small organizations

Limitations and Considerations

  • Not a full-featured LDAP server by design; some advanced LDAP features and browsing tools may not work as expected
  • Does not support providing password hashes for services that validate passwords locally (known incompatibility category)

LLDAP is a pragmatic choice when you need LDAP compatibility for authentication without the complexity of running a full LDAP stack. It works best as a simple user and group directory paired with other components for SSO and access control when needed.

Categories:

Tags:

Tech Stack:

Share:

Similar Services

PocketBase

PocketBase

Lightweight open-source realtime backend with embedded SQLite

55.3k
3k
Last commit: 1d ago

Open-source Go backend providing embedded SQLite, realtime (SSE) subscriptions, auth (JWT/OAuth2), file storage, admin UI and REST-style APIs for web and mobile apps.

Alternative to:
PocketBase Cloud
PocketBase Cloud
+17
Keycloak

Keycloak

Open-source identity and access management with SSO

32.3k
8k
Last commit: 21h ago

Keycloak is an open-source IAM server providing single sign-on, user federation, and centralized authentication and authorization using OIDC, OAuth 2.0, and SAML.

Alternative to:
Okta
Okta
+19
Authelia

Authelia

Self-hosted IAM with SSO and multi-factor authentication

26.4k
1.3k
Last commit: 1d ago

Authelia is an open-source IAM and authentication server providing SSO, MFA, and access control for web apps, with OpenID Connect/OAuth 2.0 and reverse-proxy integration.

Alternative to:
Auth0
Auth0
+16
Infisical

Infisical

Open-source platform for secrets, PKI certificates, and privileged access

24.5k
1.7k
Last commit: 20h ago

Infisical is an open-source platform to manage and deliver app secrets, certificates (PKI), SSH credentials, and encryption keys across teams and infrastructure.

Alternative to:
HashiCorp Vault
HashiCorp Vault
+9
authentik

authentik

Open-source Identity Provider (IdP) for SSO, OIDC, and SAML

19.7k
1.4k
Last commit: 17h ago

Open-source IdP delivering SSO, OAuth2/OIDC, SAML2, LDAP, RADIUS, MFA, WebAuthn, conditional access and application-proxy capabilities for self-hosted deployments.

Alternative to:
Okta
Okta
+19
Teleport

Teleport

Identity-aware access proxy for infrastructure and internal apps

19.7k
2k
Last commit: 17h ago

Secure access platform for servers, Kubernetes, databases, desktops, and web apps with SSO/MFA, short-lived certificates, and full session auditing.

Alternative to:
Twingate
Twingate
+16