
Logto
Authentication and authorization platform for apps and APIs
14.5k stars 1.2k forks last commit first released MPL-2.0
Actively maintained
Last commit 27 Aug 2026.
Logto is an open-source identity and access management platform for adding authentication and authorization to web, mobile, and API-based products. It provides standards-based login, enterprise SSO, and scalable multi-tenant identity management for SaaS and AI applications.
Key Features
- OAuth 2.1 and OpenID Connect provider for apps, SPAs, and APIs
- SAML-based enterprise SSO with common external IdPs
- Multi-tenancy via organizations, including invitations and provisioning flows
- Role-based access control for global and organization-scoped permissions
- Multiple sign-in methods: password, passwordless (email/SMS codes), and social login
- Multi-factor authentication options including passkeys, authenticator apps, and backup codes
- Customizable, pre-built sign-in experience and broad SDK/framework support
- Admin console for managing apps, users, roles, and authentication settings
Use Cases
- Add secure login and token-based API access to a SaaS product
- Implement enterprise-ready SSO and org-level access controls for B2B apps
- Centralize identity for multi-app ecosystems, including AI agents and tools
Limitations and Considerations
- Running at scale typically requires operating and tuning PostgreSQL and the service stack
- Advanced enterprise/security expectations may require careful configuration of SSO, MFA, and authorization models
Logto is a strong fit when you want a modern, standards-based auth system with multi-tenancy, SSO, and RBAC built in. It helps teams ship production-ready identity features without building and maintaining custom auth infrastructure from scratch.
Categories:
Tags:
Tech Stack:
Similar to Logto
ZITADEL
API-first identity and access management platform for applications
ZITADEL is an open source IAM/CIAM platform providing SSO, MFA, OIDC/OAuth2, SAML, user management, and multi-tenant organizations with audit logging.

FusionAuth
Self-hosted identity and access management for applications
FusionAuth is a self-hosted authentication and IAM platform supporting OAuth2, OIDC and SAML, with SSO, MFA, user management and developer-focused integrations.

Authgear
Identity and authentication platform for apps and APIs
Open-source Auth0/Clerk/Firebase Auth alternative with passkeys, MFA, SSO (OIDC/SAML), user management portal, and extensible auth flows for web and mobile apps.
Keycloak
Open-source identity and access management with SSO
Keycloak is an open-source IAM server providing single sign-on, user federation, and centralized authentication and authorization using OIDC, OAuth 2.0, and SAML.

Casdoor
UI-first IAM and SSO platform for modern authentication
Casdoor is an open-source, UI-first IAM/SSO platform supporting OAuth 2.0, OIDC, SAML, LDAP, SCIM, WebAuthn and MFA, with an admin web UI and SDKs.

authentik
Open-source Identity Provider (IdP) for SSO, OIDC, and SAML
Open-source IdP delivering SSO, OAuth2/OIDC, SAML2, LDAP, RADIUS, MFA, WebAuthn, conditional access and application-proxy capabilities for self-hosted deployments.



