
Logto
Authentication and authorization platform for apps and APIs
Logto is an open-source identity and access management platform for adding authentication and authorization to web, mobile, and API-based products. It provides standards-based login, enterprise SSO, and scalable multi-tenant identity management for SaaS and AI applications.
Key Features
- OAuth 2.1 and OpenID Connect provider for apps, SPAs, and APIs
- SAML-based enterprise SSO with common external IdPs
- Multi-tenancy via organizations, including invitations and provisioning flows
- Role-based access control for global and organization-scoped permissions
- Multiple sign-in methods: password, passwordless (email/SMS codes), and social login
- Multi-factor authentication options including passkeys, authenticator apps, and backup codes
- Customizable, pre-built sign-in experience and broad SDK/framework support
- Admin console for managing apps, users, roles, and authentication settings
Use Cases
- Add secure login and token-based API access to a SaaS product
- Implement enterprise-ready SSO and org-level access controls for B2B apps
- Centralize identity for multi-app ecosystems, including AI agents and tools
Limitations and Considerations
- Running at scale typically requires operating and tuning PostgreSQL and the service stack
- Advanced enterprise/security expectations may require careful configuration of SSO, MFA, and authorization models
Logto is a strong fit when you want a modern, standards-based auth system with multi-tenancy, SSO, and RBAC built in. It helps teams ship production-ready identity features without building and maintaining custom auth infrastructure from scratch.
Categories:
Tags:
Tech Stack:
Similar Services

PocketBase
Lightweight open-source realtime backend with embedded SQLite
Open-source Go backend providing embedded SQLite, realtime (SSE) subscriptions, auth (JWT/OAuth2), file storage, admin UI and REST-style APIs for web and mobile apps.
Keycloak
Open-source identity and access management with SSO
Keycloak is an open-source IAM server providing single sign-on, user federation, and centralized authentication and authorization using OIDC, OAuth 2.0, and SAML.

Authelia
Self-hosted IAM with SSO and multi-factor authentication
Authelia is an open-source IAM and authentication server providing SSO, MFA, and access control for web apps, with OpenID Connect/OAuth 2.0 and reverse-proxy integration.
Infisical
Open-source platform for secrets, PKI certificates, and privileged access
Infisical is an open-source platform to manage and deliver app secrets, certificates (PKI), SSH credentials, and encryption keys across teams and infrastructure.

authentik
Open-source Identity Provider (IdP) for SSO, OIDC, and SAML
Open-source IdP delivering SSO, OAuth2/OIDC, SAML2, LDAP, RADIUS, MFA, WebAuthn, conditional access and application-proxy capabilities for self-hosted deployments.

Teleport
Identity-aware access proxy for infrastructure and internal apps
Secure access platform for servers, Kubernetes, databases, desktops, and web apps with SSO/MFA, short-lived certificates, and full session auditing.

Docker
TypeScript
SCSS
Node.js