
Teleport
Identity-aware access proxy for infrastructure and internal apps

Teleport is an identity and access platform that provides secure connectivity, authentication, authorization, and auditing for infrastructure. It replaces long-lived SSH keys, static tokens, and traditional bastions/VPN approaches with an identity-aware access proxy and short-lived certificates.
Key Features
- Single sign-on for infrastructure via OIDC and SAML integrations
- Multi-factor authentication and support for modern authenticators (including FIDO2/WebAuthn)
- Short-lived, certificate-based access for SSH, Kubernetes, databases, and other resource types
- Role-based access control with support for fine-grained policies and just-in-time elevation workflows
- Session recording and audit trails across SSH, Kubernetes, database, RDP, and web application access
- Secure tunneling to reach resources behind NATs and firewalls without exposing inbound ports
- Web UI and CLI for resource discovery, access, and operational visibility
Use Cases
- Centralize secure admin access to servers, clusters, and databases without distributing keys
- Provide audited access to sensitive environments (production, regulated systems) with MFA and approvals
- Enable secure remote access to internal web apps and desktops for support and operations teams
Limitations and Considerations
- Full functionality spans multiple protocols and resource types, which can increase deployment and policy complexity in larger environments
Teleport is well-suited for teams that need a unified access layer across diverse infrastructure and want consistent identity-based controls. Its combination of SSO/MFA, short-lived credentials, and detailed auditing helps reduce risk while improving operational access workflows.
Categories:
Tags:
Tech Stack:
Similar Services

PocketBase
Lightweight open-source realtime backend with embedded SQLite
Open-source Go backend providing embedded SQLite, realtime (SSE) subscriptions, auth (JWT/OAuth2), file storage, admin UI and REST-style APIs for web and mobile apps.
Keycloak
Open-source identity and access management with SSO
Keycloak is an open-source IAM server providing single sign-on, user federation, and centralized authentication and authorization using OIDC, OAuth 2.0, and SAML.

Authelia
Self-hosted IAM with SSO and multi-factor authentication
Authelia is an open-source IAM and authentication server providing SSO, MFA, and access control for web apps, with OpenID Connect/OAuth 2.0 and reverse-proxy integration.
Infisical
Open-source platform for secrets, PKI certificates, and privileged access
Infisical is an open-source platform to manage and deliver app secrets, certificates (PKI), SSH credentials, and encryption keys across teams and infrastructure.

authentik
Open-source Identity Provider (IdP) for SSO, OIDC, and SAML
Open-source IdP delivering SSO, OAuth2/OIDC, SAML2, LDAP, RADIUS, MFA, WebAuthn, conditional access and application-proxy capabilities for self-hosted deployments.
OAuth2 Proxy
Reverse proxy and middleware for OAuth2/OIDC authentication
OAuth2 Proxy is a reverse proxy and middleware that protects web apps with OAuth2/OIDC login and forwards authenticated user identity to upstream services.




