Open Source Alternatives
Identity and access management platform. — 8 open source alternatives tracked.
auth0.com ↗Identity infrastructure, simplified
ZITADEL is identity infrastructure for SaaS teams who don't want to become Keycloak administrators. Multi-tenancy, event sourcing for complete audit trails, and strong security defaults — all in a single Go binary that deploys in minutes, not days.
Open source alternative to Auth0/Firebase Auth/Cognito
SuperTokens is the auth solution for developers who want to own their user data without building auth from scratch. Email/password, social login, passwordless, MFA, session management — all self-hosted with prebuilt UI components.
Auth infrastructure for SaaS and AI apps
Logto is auth infrastructure that doesn't make you choose between open-source control and modern developer experience. Full OAuth 2.1, OIDC, multi-tenancy, RBAC, and social login — with a clean admin console that makes Keycloak's UI look like a 2005 enterprise portal.
Headless cloud-native identity management
Ory Kratos is headless identity management for developers who want auth as an API, not a UI library. It handles registration, login, MFA, account recovery, and profile management through pure API calls — you build the frontend exactly how you want.
Simple, unobtrusive authentication for Node.js
Passport.js is the authentication middleware that every Express.js tutorial teaches — plug in a "strategy" for Google OAuth, GitHub login, JWT, or local username/password, and it handles the session dance. With 500+ strategies, it supports practically every auth method that exists.
Authentication, simple and clean
Lucia was the auth library every indie hacker recommended — simple session management without the bloat of NextAuth or the vendor lock-in of Auth0. Clean API, framework-agnostic, TypeScript-first.
Flexible identity provider
Authentik is the identity provider that makes Keycloak look like enterprise bloatware. Written in Python with a visual flow editor, it lets you build custom auth journeys — passwordless for some users, MFA for others — without touching code.
SSO multi-factor portal for web apps
Authelia is the authentication portal for people who self-host everything. Drop it in front of your reverse proxy (Nginx, Traefik, Caddy) and get SSO, two-factor authentication, and access policies for all your self-hosted apps.
The Open Source Drop — the best new open source tools, analyzed. Free.