For alternative à Auth0, the strongest matches are zitadel/zitadel (Zitadel is an open-source, self-hostable identity and access management), casdoor/casdoor (Casdoor is a self-hostable open-source identity and access management) and ory/kratos (Kratos is a self-hostable identity server with built-in multi-factor). steveiliop56/tinyauth and stack-auth/stack-auth round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.
Plateformes d'identité et d'authentification auto-hébergées offrant une connexion utilisateur sécurisée et un contrôle d'accès pour vos applications.
This project is a cloud-native identity and access management platform designed to centralize authentication, authorization, and identity lifecycle management. It functions as a standards-compliant OpenID Connect authorization server, providing secure session management and token issuance for web, mobile, and device-based applications. The platform is built to handle complex identity requirements through stateless token authentication and support for modern passwordless methods, including biometrics and hardware keys. What distinguishes this platform is its native support for multi-tenant env
Zitadel is an open-source, self-hostable identity and access management platform that provides OIDC/OAuth2 authentication, MFA, RBAC, and a user management dashboard, making it a direct self-managed alternative to Auth0.
Casdoor is a centralized identity and access management platform that functions as an OAuth 2.0 authorization server. It provides a comprehensive suite of services for managing user identities, authentication sessions, and access policies across both web and machine-to-machine applications. Built with a decoupled frontend-backend architecture in Go, the platform supports high-concurrency environments and offers a web-based management interface for administrative tasks. The platform distinguishes itself through its extensive support for federated identity management, allowing integration with
Casdoor is a self-hostable open-source identity and access management platform with native support for OAuth 2.0, OIDC, MFA, SSO, and a web-based admin dashboard, directly matching your need for an Auth0 alternative that handles authentication, authorization, and federated identity.
Kratos is a centralized identity and access management server designed to handle user registration, authentication, and profile management. It functions as an identity flow orchestrator, managing the state and security of authentication processes across web, mobile, and command-line interfaces. The system provides a standards-compliant authorization server that issues tokens and manages delegated access for third-party applications and internal services, supporting multi-factor authentication and custom identity schemas to secure user accounts. The project distinguishes itself through a headl
Kratos is a self-hostable identity server with built-in multi-factor authentication, customizable authentication flows, and token issuance, making it a solid fit for an Auth0 alternative, though it may require additional Ory components for role-based access control and full OAuth2/OIDC delegation.
Tinyauth is an authentication middleware service and identity provider that verifies user identities to grant system access. It operates as a standalone server or as an authentication gateway, utilizing a reverse proxy model to intercept requests and validate credentials before traffic reaches protected backend services. The project functions as an OpenID Connect provider for single sign-on experiences and an OAuth 2.0 gateway that delegates verification to external providers such as Google and GitHub. It also acts as an LDAP authentication server, allowing for centralized user management and
Tinyauth is a self-hosted authentication middleware and identity provider that supports OIDC, OAuth2, two-factor authentication, and group-based access control — directly covering your core needs for user authentication and SSO, though it is a lightweight gateway rather than a full platform with a dedicated user management dashboard or customizable UI.
Stack Auth is an open-source authentication and authorization platform that provides pre-built UI components, OAuth integration, team management, and session handling for web applications. It offers a complete authentication lifecycle covering sign-in, sign-up, session management, password recovery, and multi-factor security, with support for passkey authentication and OAuth providers including Google, GitHub, and Apple. The platform includes a team-based permission system with role-based access control, allowing users to be organized into teams with granular permissions for membership manage
Stack Auth is a self-hostable open-source authentication and authorization platform that directly handles user login, OAuth, MFA, RBAC, and API key management, providing a complete alternative to Auth0 with a dashboard and pre-built UI components.
Logto is an open-source identity provider that serves as a centralized authentication and authorization server for web, mobile, and command-line applications. It implements the OpenID Connect and OAuth 2.1 standards to handle secure user sign-in and the issuance of identity tokens. The platform is specifically designed as a multi-tenant authentication framework for software-as-a-service environments, featuring built-in organization management and tenant isolation. It includes an enterprise single sign-on gateway to integrate external identity providers and supports role-based access control t
Logto is an open-source identity provider that delivers centralized authentication and authorization with support for OAuth 2.1, OIDC, social login, MFA, RBAC, and enterprise SSO, making it a strong self-hostable alternative to Auth0 that directly matches the full scope of your requirements.
SuperTokens Core is an open-source, self-hosted authentication and identity management platform designed for deployment within private infrastructure. It provides a comprehensive suite for managing user accounts, roles, and secure authentication flows, utilizing a modular, recipe-based architecture that allows developers to enable specific security features without modifying the core codebase. The platform distinguishes itself through its robust multi-tenancy capabilities, which allow for the logical or physical isolation of user records and configuration settings across different organizatio
SuperTokens Core is a self-hosted open-source authentication and identity management platform with support for social login, OAuth2/OIDC, session management, and role-based access control, fitting this search for an Auth0 alternative.
Hanko is an open-source identity provider and customer identity and access management system. It serves as a passkey authentication service and an OAuth and SAML SSO gateway, allowing applications to authenticate users and issue tokens via standard identity protocols. The project distinguishes itself through a strong focus on passwordless access using WebAuthn-based passkeys and email-based passcodes. It provides framework-agnostic authentication interfaces as customizable web components that can be embedded directly into web applications to handle login, registration, and profile management.
Hanko is a self-hostable identity provider and CIAM that covers most of the features you need — OAuth2/OIDC and SAML SSO, MFA via passkeys, customizable web components for the authentication UI, and API token issuance — making it a strong alternative to Auth0.
Authelia is a centralized identity and access management server designed to secure web applications through unified authentication and authorization. It functions as an identity authority that enables single sign-on across diverse platforms, allowing users to access multiple services with a single set of credentials. By acting as a standards-compliant provider, it facilitates secure identity propagation and token issuance for client applications. The platform distinguishes itself through its ability to integrate directly with web gateways as a reverse proxy authentication middleware, intercep
Authelia is a self-hosted identity and access management server that provides single sign-on, multi-factor authentication, and OAuth2/OIDC support for web applications, fitting the core needs of an Auth0 alternative—though it operates as a reverse proxy middleware rather than offering a full user management dashboard.
Kanidm is a centralized identity management server designed to handle authentication, authorization, and directory services across distributed infrastructure. It provides a comprehensive framework for managing human and service accounts, utilizing a schema-driven database to store identity records, group memberships, and system attributes. The platform supports a wide range of authentication methods, including passkeys, passwords, and standard protocols like OAuth2, OIDC, LDAP, and RADIUS. The system distinguishes itself through a granular access control engine that enforces security policies
Kanidm is a self-hostable identity management server that supports OAuth2/OIDC, MFA via WebAuthn, LDAP, and RBAC, making it a genuine IAM platform; while it may lack a polished user-facing login UI out of the box, it covers the core requirements for authentication and authorization as a direct alternative to Auth0.
Hydra is a headless identity server that functions as a certified OAuth2 and OpenID Connect provider. It is designed as an authentication engine that manages authorization handshakes and token lifecycles while remaining decoupled from the user interface. The project distinguishes itself through a headless architecture, allowing external management of login and consent flows. It provides specialized capabilities for dynamic client registration, JSON Web Token issuance, and a system for rotating encryption secrets without service downtime. The system covers a broad range of identity operations
Ory Hydra is a certified OAuth2 and OpenID Connect provider that handles authentication, authorization, and token management, making it a solid self-hostable backend for identity and access management — though its headless design means you'll need to build your own user management dashboard and login UI to match Auth0's all-in-one experience.
Keycloak is an open-source identity and access management server that provides a centralized platform for user authentication, authorization, and identity federation. It functions as a standards-compliant identity provider, utilizing a centralized engine to validate credentials and issue cryptographically signed tokens based on industry-standard protocols like OpenID Connect and SAML. This enables organizations to secure diverse applications and services through a unified authentication layer. The platform distinguishes itself through its cloud-native orchestration and high-availability capab
Keycloak is a full-featured open-source Identity and Access Management server that provides all the requested features: OIDC/SAML, MFA, social login, RBAC, customizable login pages, and a user management dashboard, and it is designed for self-hosting as an alternative to Auth0.
This platform is an identity and access management suite designed to secure and coordinate digital identities for employees, customers, and automated agents. It functions as an enterprise authentication server, providing centralized single sign-on and multi-factor authentication capabilities to protect access across diverse internal and external applications. The engine operates through event-driven orchestration, triggering modular handlers to process authentication and authorization requests. The system is built on a Java-based middleware architecture that utilizes a dynamic component model
WSO2 Identity Server is a full-featured self-hostable identity and access management suite offering SSO, OAuth2/OIDC, SAML2, MFA, and RBAC, which directly matches your need for an Auth0 alternative.
| Dépôt | Stars | Langage | Licence | Dernier push |
|---|---|---|---|---|
| zitadel/zitadel | 13K | Go | agpl-3.0 | |
| casdoor/casdoor | 13.8K | Go | Apache-2.0 | |
| ory/kratos | 13.5K | Go | apache-2.0 | |
| steveiliop56/tinyauth | 7K | Go | gpl-3.0 | |
| stack-auth/stack-auth | 6.7K | TypeScript | other | |
| logto-io/logto | 12.2K | TypeScript | MPL-2.0 | |
| supertokens/supertokens-core | 14.9K | Java | other | |
| teamhanko/hanko | 8.8K | Go | other | |
| authelia/authelia | 26.8K | Go | apache-2.0 | |
| kanidm/kanidm | 4.6K | Rust | mpl-2.0 |