awesome-repositories.com
Blog
MCP
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektMCP-ServerÜber unsRanking-MethodikPresse
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

Self-Hosted OAuth- und OIDC-Provider

Ranking aktualisiert am 30. Juni 2026

For Self-hosted Identity Provider, the strongest matches are authelia/authelia (Authelia is a self-hosted identity and access management server), apereo/cas (Apereo CAS is a mature, self-hostable identity provider and) and ory/kratos (Kratos is a self-hosted identity and access management server). steveiliop56/tinyauth and coreos/dex round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.

Open-Source-Identitätsmanagement-Server, die Authentifizierungs- und Autorisierungsdienste für Ihre eigene Infrastruktur bereitstellen.

Self-Hosted OAuth- und OIDC-Provider

Finde die besten Repos mit KI.Wir suchen mit KI nach den am besten passenden Repositories.
  • authelia/autheliaAvatar von authelia

    authelia/authelia

    26,785Auf GitHub ansehen↗

    Authelia is a centralized identity and access management server designed to secure web applications through unified authentication and authorization. It functions as an identity authority that enables single sign-on across diverse platforms, allowing users to access multiple services with a single set of credentials. By acting as a standards-compliant provider, it facilitates secure identity propagation and token issuance for client applications. The platform distinguishes itself through its ability to integrate directly with web gateways as a reverse proxy authentication middleware, intercep

    Authelia is a self-hosted identity and access management server that provides OAuth 2.0 and OpenID Connect support, integrates with LDAP, offers multi-factor authentication, and enables single sign-on — exactly the kind of self-hosted identity provider this search is after.

    GoMulti-Factor AuthenticationOpenID Connect ProvidersSingle Sign-On Providers
    Auf GitHub ansehen↗26,785
  • apereo/casAvatar von apereo

    apereo/cas

    11,347Auf GitHub ansehen↗

    This project is an open-source identity provider and single sign-on platform that centralizes user authentication for multiple web applications and services. It functions as a multi-protocol authentication gateway, verifying user identities and issuing tokens through the CAS protocol as well as industry standards including SAML, OAuth2, and OpenID Connect. The system acts as a federated identity server, allowing authentication to be delegated to external third-party or corporate identity providers. It distinguishes itself through identity attribute governance, which manages which specific use

    Apereo CAS is a mature, self-hostable identity provider and single sign-on platform that natively supports OAuth 2.0, OpenID Connect, LDAP, multi-factor authentication, and provides an administrative interface, exactly matching your authentication and SSO requirements.

    JavaMultifactor AuthenticationSingle Sign-OnSingle Sign-On Solutions
    Auf GitHub ansehen↗11,347
  • ory/kratosAvatar von ory

    ory/kratos

    13,455Auf GitHub ansehen↗

    Kratos is a centralized identity and access management server designed to handle user registration, authentication, and profile management. It functions as an identity flow orchestrator, managing the state and security of authentication processes across web, mobile, and command-line interfaces. The system provides a standards-compliant authorization server that issues tokens and manages delegated access for third-party applications and internal services, supporting multi-factor authentication and custom identity schemas to secure user accounts. The project distinguishes itself through a headl

    Kratos is a self-hosted identity and access management server that provides a standards-compliant authorization server for token issuance and delegated access, supporting MFA and custom schemas — fitting the core OAuth2/OIDC SSO requirements, though it may lack a built-in admin UI and LDAP support out of the box.

    GoMulti-Factor AuthenticationMulti-Factor AuthenticationOAuth2 Implementations
    Auf GitHub ansehen↗13,455
  • steveiliop56/tinyauthAvatar von steveiliop56

    steveiliop56/tinyauth

    6,979Auf GitHub ansehen↗

    Tinyauth is an authentication middleware service and identity provider that verifies user identities to grant system access. It operates as a standalone server or as an authentication gateway, utilizing a reverse proxy model to intercept requests and validate credentials before traffic reaches protected backend services. The project functions as an OpenID Connect provider for single sign-on experiences and an OAuth 2.0 gateway that delegates verification to external providers such as Google and GitHub. It also acts as an LDAP authentication server, allowing for centralized user management and

    Tinyauth is a self-hostable authentication middleware and identity provider that supports OAuth 2.0, OpenID Connect, LDAP, and TOTP-based MFA, making it a solid fit for single sign-on and user authentication needs.

    GoMulti-Factor AuthenticationOpenID Connect ProvidersSingle Sign-On
    Auf GitHub ansehen↗6,979
  • coreos/dexAvatar von coreos

    coreos/dex

    10,885Auf GitHub ansehen↗

    Dex is an OpenID Connect identity provider that functions as an identity federation gateway. It authenticates users and issues signed tokens for applications by using a variety of pluggable connectors to interface with external identity sources. The project focuses on federating multiple external identity providers into a single authentication portal. It maps diverse external authentication sources to a uniform internal user representation and manages the orchestration of authorization handshakes between clients and identity sources. Capability areas include centralized user authentication,

    Dex is a self-hostable OpenID Connect identity provider that supports OAuth2 and can integrate with LDAP via connectors, but it lacks a built-in admin UI and multi-factor authentication, relying on external identity sources for those capabilities.

    GoOAuth ProvidersOpenID Connect ProvidersOIDC Identity Token Issuance
    Auf GitHub ansehen↗10,885
  • casdoor/casdoorAvatar von casdoor

    casdoor/casdoor

    13,814Auf GitHub ansehen↗

    Casdoor is a centralized identity and access management platform that functions as an OAuth 2.0 authorization server. It provides a comprehensive suite of services for managing user identities, authentication sessions, and access policies across both web and machine-to-machine applications. Built with a decoupled frontend-backend architecture in Go, the platform supports high-concurrency environments and offers a web-based management interface for administrative tasks. The platform distinguishes itself through its extensive support for federated identity management, allowing integration with

    Casdoor is a self-hostable identity and access management platform that directly delivers OAuth 2.0, OpenID Connect, LDAP integration, SSO, an admin UI, and multi‑factor authentication (TOTP, WebAuthn), making it a comprehensive fit for your self‑hosted identity provider needs.

    GoOAuth ProvidersOAuth2 ProvidersSingle Sign-On Solutions
    Auf GitHub ansehen↗13,814
  • zitadel/zitadelAvatar von zitadel

    zitadel/zitadel

    13,029Auf GitHub ansehen↗

    This project is a cloud-native identity and access management platform designed to centralize authentication, authorization, and identity lifecycle management. It functions as a standards-compliant OpenID Connect authorization server, providing secure session management and token issuance for web, mobile, and device-based applications. The platform is built to handle complex identity requirements through stateless token authentication and support for modern passwordless methods, including biometrics and hardware keys. What distinguishes this platform is its native support for multi-tenant env

    Zitadel is a standards-compliant OpenID Connect authorization server with native OAuth 2.0, SSO, MFA, and passwordless support, making it an excellent self-hostable identity provider for your authentication and single sign-on needs.

    GoOpenID Connect ProvidersSingle Sign-On
    Auf GitHub ansehen↗13,029
  • dexidp/dexAvatar von dexidp

    dexidp/dex

    10,902Auf GitHub ansehen↗

    Dex is an OpenID Connect provider and identity federation proxy that translates authentication signals from various upstream sources into a unified OpenID Connect interface. It functions as a multi-protocol identity broker, enabling client applications to implement a single standard while delegating user verification to external identity providers. The project distinguishes itself through a pluggable connector architecture that bridges disparate protocols including LDAP, SAML, and OAuth2. It provides specific integrations for services such as GitHub, Google, GitLab, and Microsoft, while offer

    Dex is an OpenID Connect provider and identity federation proxy that you can self-host, with native OAuth2/OIDC support, LDAP integration, and SSO capabilities through pluggable connectors, directly matching your search for a self-hostable identity provider.

    GoOAuth2 ImplementationsOpenID Connect ProvidersSingle Sign-On
    Auf GitHub ansehen↗10,902
  • ory/hydraAvatar von ory

    ory/hydra

    17,236Auf GitHub ansehen↗

    Hydra is a headless identity server that functions as a certified OAuth2 and OpenID Connect provider. It is designed as an authentication engine that manages authorization handshakes and token lifecycles while remaining decoupled from the user interface. The project distinguishes itself through a headless architecture, allowing external management of login and consent flows. It provides specialized capabilities for dynamic client registration, JSON Web Token issuance, and a system for rotating encryption secrets without service downtime. The system covers a broad range of identity operations

    Hydra is a self-hosted, certified OAuth 2.0 and OpenID Connect provider that handles authentication and SSO, but its headless design means it lacks a built-in admin UI, built-in LDAP support, and built-in MFA, so you would need to integrate those externally.

    GoOAuth2 ImplementationsOpenID Connect ProvidersSingle Sign-On Solutions
    Auf GitHub ansehen↗17,236
  • anomalyco/openauthAvatar von anomalyco

    anomalyco/openauth

    6,971Auf GitHub ansehen↗

    OpenAuth is a standards-based authentication server and identity provider that implements OAuth 2.0 and OpenID Connect protocols. It serves as a centralized system for managing user identities, issuing access tokens, and orchestrating authentication flows across various services. The project functions as a federated identity gateway, aggregating external providers such as Google, GitHub, Microsoft, Apple, and Discord into a unified login flow. It distinguishes itself with a multi-tenant architecture that supports pluggable identity providers and customizable user interface frameworks for bran

    OpenAuth is a self-hostable authentication server and identity provider that implements OAuth 2.0 and OpenID Connect, supporting federated SSO; while it covers the core protocols and centralized identity management, its explicit support for LDAP and multi-factor authentication is not confirmed in the provided evidence, so it fits the category but lacks some of the listed features.

    TypeScriptOAuth 2.0 Authorization FlowsOpenID Connect ProvidersOpenID Connect Support
    Auf GitHub ansehen↗6,971
  • keycloak/keycloakAvatar von keycloak

    keycloak/keycloak

    34,934Auf GitHub ansehen↗

    Keycloak is an open-source identity and access management server that provides a centralized platform for user authentication, authorization, and identity federation. It functions as a standards-compliant identity provider, utilizing a centralized engine to validate credentials and issue cryptographically signed tokens based on industry-standard protocols like OpenID Connect and SAML. This enables organizations to secure diverse applications and services through a unified authentication layer. The platform distinguishes itself through its cloud-native orchestration and high-availability capab

    Keycloak is a standards-compliant identity and access management server that provides OAuth 2.0, OpenID Connect, SAML, single sign-on, user federation with LDAP, an admin UI, and multi-factor authentication—exactly the self-hostable identity provider you're looking for.

    JavaIdentity ServersIdentity Management SystemsIdentity Providers
    Auf GitHub ansehen↗34,934
  • wso2/product-isAvatar von wso2

    wso2/product-is

    843Auf GitHub ansehen↗

    This platform is an identity and access management suite designed to secure and coordinate digital identities for employees, customers, and automated agents. It functions as an enterprise authentication server, providing centralized single sign-on and multi-factor authentication capabilities to protect access across diverse internal and external applications. The engine operates through event-driven orchestration, triggering modular handlers to process authentication and authorization requests. The system is built on a Java-based middleware architecture that utilizes a dynamic component model

    WSO2 Identity Server is an enterprise-grade self-hostable identity and access management suite that provides OAuth 2.0, OpenID Connect, SSO, and MFA out of the box, making it a comprehensive fit for your authentication and single sign-on needs.

    JavaEnterprise AuthenticationEvent-Driven OrchestrationIdentity and Access Management Servers
    Auf GitHub ansehen↗843
  • supertokens/supertokens-coreAvatar von supertokens

    supertokens/supertokens-core

    14,922Auf GitHub ansehen↗

    SuperTokens Core is an open-source, self-hosted authentication and identity management platform designed for deployment within private infrastructure. It provides a comprehensive suite for managing user accounts, roles, and secure authentication flows, utilizing a modular, recipe-based architecture that allows developers to enable specific security features without modifying the core codebase. The platform distinguishes itself through its robust multi-tenancy capabilities, which allow for the logical or physical isolation of user records and configuration settings across different organizatio

    SuperTokens Core is a self-hosted authentication and identity management platform that fits the identity provider category, with support for OAuth 2.0 and social login; while it may lack explicit mention of OpenID Connect and LDAP in the description, its architecture and comparisons to Keycloak and Auth0 suggest it covers single sign-on and likely includes an admin UI and MFA.

    JavaOAuth ProvidersOAuth2 Providers
    Auf GitHub ansehen↗14,922
  • teamhanko/hankoAvatar von teamhanko

    teamhanko/hanko

    8,801Auf GitHub ansehen↗

    Hanko is an open-source identity provider and customer identity and access management system. It serves as a passkey authentication service and an OAuth and SAML SSO gateway, allowing applications to authenticate users and issue tokens via standard identity protocols. The project distinguishes itself through a strong focus on passwordless access using WebAuthn-based passkeys and email-based passcodes. It provides framework-agnostic authentication interfaces as customizable web components that can be embedded directly into web applications to handle login, registration, and profile management.

    Hanko is a self-hosted identity provider focused on passwordless authentication with OAuth2 and SAML SSO, but it does not explicitly mention OpenID Connect support, and its user directory features (like LDAP) are not clearly outlined, making it a narrower fit for this search.

    GoMulti-Factor AuthenticationSAML SSO Integrations
    Auf GitHub ansehen↗8,801
  • logto-io/logtoAvatar von logto-io

    logto-io/logto

    12,161Auf GitHub ansehen↗

    Logto is an open-source identity provider that serves as a centralized authentication and authorization server for web, mobile, and command-line applications. It implements the OpenID Connect and OAuth 2.1 standards to handle secure user sign-in and the issuance of identity tokens. The platform is specifically designed as a multi-tenant authentication framework for software-as-a-service environments, featuring built-in organization management and tenant isolation. It includes an enterprise single sign-on gateway to integrate external identity providers and supports role-based access control t

    Logto is an open-source, self-hostable identity provider that implements OAuth 2.1 and OpenID Connect for authentication and single sign-on, with support for MFA, RBAC, and enterprise SSO — it fits your search well but does not explicitly include LDAP directory integration.

    TypeScriptIdentity and Access Management ServersIdentity ProvidersEnterprise Identity Providers
    Auf GitHub ansehen↗12,161
  • panva/node-oidc-providerAvatar von panva

    panva/node-oidc-provider

    3,756Auf GitHub ansehen↗

    node-oidc-provider is a framework for building OpenID Certified authorization servers and identity providers within Node.js environments. It provides a comprehensive suite of tools for managing the full lifecycle of OAuth 2.0 and OpenID Connect services, including user authentication, client registration, and the issuance and validation of identity and access tokens. The project distinguishes itself through a highly modular architecture that allows developers to integrate authentication services directly into existing web application stacks. It supports advanced customization through a middle

    panva/node-oidc-provider is an OpenID Certified OAuth 2.0 Authorization Server that you can self-host, supporting OAuth2 and OpenID Connect directly, though as a library it may need additional work for an admin UI, LDAP, and MFA.

    JavaScriptOpenID Connect Providers
    Auf GitHub ansehen↗3,756
  • mitreid-connect/openid-connect-java-spring-serverAvatar von mitreid-connect

    mitreid-connect/OpenID-Connect-Java-Spring-Server

    1,506Auf GitHub ansehen↗

    This project is an authentication and authorization platform built on the Spring framework that functions as a centralized identity provider and authorization server. It manages user identities and protects resources by implementing standardized protocols to verify credentials and issue secure tokens for web applications. The platform distinguishes itself by providing a comprehensive framework for managing complex authorization flows and identity verification. It supports dynamic client registration to automate the onboarding of third-party applications and utilizes relational database persis

    This repository is a self-hostable OpenID Connect server that implements OAuth 2.0 and OIDC for authentication and single sign-on, but as a reference implementation, it may lack built-in user directory, LDAP, admin UI, and MFA features.

    JavaOAuth2 ProvidersOpenID Connect Providers
    Auf GitHub ansehen↗1,506
Die Top 10 auf einen Blick vergleichen
RepositoryStarsSpracheLizenzLetzter Push
authelia/authelia26.8KGoapache-2.019. Feb. 2026
apereo/cas11.3KJavaApache-2.023. Juni 2026
ory/kratos13.5KGoapache-2.021. Feb. 2026
steveiliop56/tinyauth7KGogpl-3.020. Feb. 2026
coreos/dex10.9KGoApache-2.017. Juni 2026
casdoor/casdoor13.8KGoApache-2.022. Juni 2026
zitadel/zitadel13KGoagpl-3.020. Feb. 2026
dexidp/dex10.9KGoApache-2.019. Juni 2026
ory/hydra17.2KGoApache-2.022. Juni 2026
anomalyco/openauth7KTypeScriptMIT18. Juli 2025

Related searches

  • an open source identity management platform
  • Alternative zu Auth0
  • Self-hosted SSO-Gateway
  • ein selbstgehosteter Passwort-Tresor
  • ein selbstgehosteter Passwort-Manager für Zugangsdaten
  • eine Authentifizierungs-Bibliothek für Webanwendungen
  • selbstgehosteter Passwort-Manager für Zugangsdaten
  • a self hosted server for calendar synchronization