awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
logto-io avatar

logto-io/logto

0
View on GitHub↗
12,161 stars·824 forks·TypeScript·MPL-2.0·71 viewslogto.io↗

Logto

Logto is an open-source identity provider that serves as a centralized authentication and authorization server for web, mobile, and command-line applications. It implements the OpenID Connect and OAuth 2.1 standards to handle secure user sign-in and the issuance of identity tokens.

The platform is specifically designed as a multi-tenant authentication framework for software-as-a-service environments, featuring built-in organization management and tenant isolation. It includes an enterprise single sign-on gateway to integrate external identity providers and supports role-based access control to manage permissions through organizational hierarchies.

The system covers identity and access management through user onboarding flows, multi-factor authentication, and custom sign-in interfaces. It also provides tools for organization-level membership management and the automation of user and role provisioning.

The software is distributed via container images to ensure consistent deployment across different computing environments.

Features

  • Identity and Access Management Servers - Serves as a centralized platform for managing user identities, authentication, and authorization policies across applications.
  • Identity Providers - Provides a centralized identity provider that manages authentication and authorization for web, mobile, and CLI applications.
  • Enterprise Identity Providers - Implements a gateway to integrate enterprise-grade identity providers using protocols like SAML and OIDC for single sign-on.
  • Permission-Based Security - Manages feature permissions across organizations by assigning access rights to roles rather than individual users.
  • Multi-Tenant Identity Management - Manages organization-level permissions and member invitations to support secure multi-tenancy in B2B environments.
  • Identity Servers - Ships an identity server that handles secure user sign-in and issues OIDC and OAuth 2.1 identity tokens.
  • Multi-Tenant Isolation Layers - Implements data-level isolation to separate user identities and organizational settings for multiple independent customers.
  • Multi-Tenant Authentication Services - Offers a multi-tenant authentication framework with isolated user pools and tenant-specific login configurations for SaaS environments.
  • OAuth 2.1 Implementations - Implements the OAuth 2.1 protocol to issue and validate secure access tokens for managing permissions.
  • Role-Based Access Control - Enforces role-based permissions and organization-level restrictions to manage feature access across multi-tenant environments.
  • Role-Based Access Control Systems - Implements a role-based access control system to manage user permissions and access levels through organizational hierarchies.
  • User Identity Management - Centralizes the handling of user identities and access control using standard protocols for secure verification.
  • Identity Federation - Uses the OpenID Connect protocol to standardize identity exchange and authentication across different service providers.
  • External Identity Provider Integration - Allows users to authenticate using third-party accounts such as Google or Facebook via standardized protocols.
  • Web Sign-in Flows - Supports the creation of custom web-based interfaces for sign-up, social login, and multi-factor authentication.
  • User Role Management - Provides a command line interface to automate the bulk creation of organizational roles and permission settings.
  • Open-Source Authentication Platforms - Provides an open-source, self-hosted identity platform for session management and identity linking via OIDC and OAuth.
  • Enterprise SSO Integrations - Connects to external enterprise identity providers via industry protocols to enable single sign-on for users.
  • Client Application Connectivity - Enables secure communication for web apps, mobile apps, and CLI tools using standardized machine-to-machine protocols.
  • Authentication Services - Authentication service with cloud and self-hosted deployment options.
  • Authentication Services - OIDC and OAuth 2.1 infrastructure for SaaS and AI apps.
  • Security And Privacy - Identity platform for user authentication.

Star history

Star history chart for logto-io/logtoStar history chart for logto-io/logto

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does logto-io/logto do?

Logto is an open-source identity provider that serves as a centralized authentication and authorization server for web, mobile, and command-line applications. It implements the OpenID Connect and OAuth 2.1 standards to handle secure user sign-in and the issuance of identity tokens.

What are the main features of logto-io/logto?

The main features of logto-io/logto are: Identity and Access Management Servers, Identity Providers, Enterprise Identity Providers, Permission-Based Security, Multi-Tenant Identity Management, Identity Servers, Multi-Tenant Isolation Layers, Multi-Tenant Authentication Services.

Which projects share features with logto-io/logto?

Projects with overlapping indexed features include: authorizerdev/authorizer — Authorizer is an open-source identity provider that functions as a centralized authentication and authorization… supertokens/supertokens-core — SuperTokens Core is an open-source, self-hosted authentication and identity management platform designed for… stack-auth/stack — Stack is an open-source identity provider that manages user authentication, passkeys, and OAuth tokens. It provides an… teamhanko/hanko — Hanko is an open-source identity provider and customer identity and access management system. It serves as a passkey… kanidm/kanidm — Kanidm is a centralized identity management server designed to handle authentication, authorization, and directory… killbill/killbill — Kill Bill is a subscription billing platform and usage-based billing engine designed to manage recurring invoicing and…

Projects sharing features with Logto

These projects share indexed features with Logto. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • authorizerdev/authorizerauthorizerdev avatar

    authorizerdev/authorizer

    1,968View on GitHub↗

    Authorizer is an open-source identity provider that functions as a centralized authentication and authorization platform. It manages user identities and session lifecycles by implementing standard OpenID Connect protocols, allowing for secure verification across web, mobile, and backend applications. The service is designed as a containerized microservice that provides a unified interface for administrative and authentication operations. The platform distinguishes itself through a multi-tenant architecture that isolates authentication rules and user data across different business domains. It

    Go2faauthauthentication
    View on GitHub↗1,968
  • supertokens/supertokens-coresupertokens avatar

    supertokens/supertokens-core

    14,922View on GitHub↗

    SuperTokens Core is an open-source, self-hosted authentication and identity management platform designed for deployment within private infrastructure. It provides a comprehensive suite for managing user accounts, roles, and secure authentication flows, utilizing a modular, recipe-based architecture that allows developers to enable specific security features without modifying the core codebase. The platform distinguishes itself through its robust multi-tenancy capabilities, which allow for the logical or physical isolation of user records and configuration settings across different organizatio

    Javaauth0authenticationaws-cognito
    View on GitHub↗14,922
  • stack-auth/stackstack-auth avatar

    stack-auth/stack

    6,815View on GitHub↗

    Stack is an open-source identity provider that manages user authentication, passkeys, and OAuth tokens. It provides an identity infrastructure that handles user data storage and authentication flows via a centralized administrative dashboard. The platform differentiates itself by integrating a multi-tenant user management system that organizes users into team workspaces through invitation flows. It includes a secure secret vault for storing encrypted API keys and user tokens using encryption keys that remain hidden from the service provider. The system covers a broad range of administrative

    TypeScript
    View on GitHub↗6,815
  • teamhanko/hankoteamhanko avatar

    teamhanko/hanko

    8,801View on GitHub↗

    Hanko is an open-source identity provider and customer identity and access management system. It serves as a passkey authentication service and an OAuth and SAML SSO gateway, allowing applications to authenticate users and issue tokens via standard identity protocols. The project distinguishes itself through a strong focus on passwordless access using WebAuthn-based passkeys and email-based passcodes. It provides framework-agnostic authentication interfaces as customizable web components that can be embedded directly into web applications to handle login, registration, and profile management.

    Go2faauthenticationciam
    View on GitHub↗8,801
Compare all 30 related projects→