
Teleport
Identity-aware access proxy for infrastructure and internal apps
20.9k stars 2.1k forks last commit first released AGPL-3.0
Actively maintained
Last commit 25 Aug 2026.

Teleport is an identity and access platform that provides secure connectivity, authentication, authorization, and auditing for infrastructure. It replaces long-lived SSH keys, static tokens, and traditional bastions/VPN approaches with an identity-aware access proxy and short-lived certificates.
Key Features
- Single sign-on for infrastructure via OIDC and SAML integrations
- Multi-factor authentication and support for modern authenticators (including FIDO2/WebAuthn)
- Short-lived, certificate-based access for SSH, Kubernetes, databases, and other resource types
- Role-based access control with support for fine-grained policies and just-in-time elevation workflows
- Session recording and audit trails across SSH, Kubernetes, database, RDP, and web application access
- Secure tunneling to reach resources behind NATs and firewalls without exposing inbound ports
- Web UI and CLI for resource discovery, access, and operational visibility
Use Cases
- Centralize secure admin access to servers, clusters, and databases without distributing keys
- Provide audited access to sensitive environments (production, regulated systems) with MFA and approvals
- Enable secure remote access to internal web apps and desktops for support and operations teams
Limitations and Considerations
- Full functionality spans multiple protocols and resource types, which can increase deployment and policy complexity in larger environments
Teleport is well-suited for teams that need a unified access layer across diverse infrastructure and want consistent identity-based controls. Its combination of SSO/MFA, short-lived credentials, and detailed auditing helps reduce risk while improving operational access workflows.
Categories:
Tags:
Tech Stack:
Similar to Teleport
ZITADEL
API-first identity and access management platform for applications
ZITADEL is an open source IAM/CIAM platform providing SSO, MFA, OIDC/OAuth2, SAML, user management, and multi-tenant organizations with audit logging.

Authgear
Identity and authentication platform for apps and APIs
Open-source Auth0/Clerk/Firebase Auth alternative with passkeys, MFA, SSO (OIDC/SAML), user management portal, and extensible auth flows for web and mobile apps.

Casdoor
UI-first IAM and SSO platform for modern authentication
Casdoor is an open-source, UI-first IAM/SSO platform supporting OAuth 2.0, OIDC, SAML, LDAP, SCIM, WebAuthn and MFA, with an admin web UI and SDKs.

Warpgate
Transparent bastion and PAM for SSH, HTTPS, MySQL and PostgreSQL
Self-hosted transparent bastion host and PAM for SSH, HTTPS, MySQL and Postgres with RBAC, session recording, and SSO/2FA—no client-side software required.


Logto
Authentication and authorization platform for apps and APIs
Open-source authentication and authorization infrastructure with OIDC/OAuth 2.1, SAML SSO, multi-tenancy, MFA, and RBAC for SaaS and AI apps.

Authelia
Self-hosted IAM with SSO and multi-factor authentication
Authelia is an open-source IAM and authentication server providing SSO, MFA, and access control for web apps, with OpenID Connect/OAuth 2.0 and reverse-proxy integration.




