This article is written by the team that builds Casdoor, so we are not neutral, and we say where we think Casdoor fits and where it doesn't. Facts about other products come from their own websites as of October 8, 2026 (listed under Sources) and may have changed. Spotted something out of date? Tell us.
Five years ago, "open-source identity provider" mostly meant Keycloak. Today there are a dozen serious projects, and they differ a lot: some are full IAM platforms with a web console, some are headless APIs, and some are just a login portal in front of a reverse proxy. This list ranks the ten we think are worth evaluating in 2026, with what each one is good at and where it falls short.
We only included projects whose source is available under an OSI-approved license. Star counts are from GitHub in October 2026.
How we compared them
- Scope. Does it cover single sign-on, user management, MFA and authorization, or only part of that?
- Protocols. OAuth 2.0 and OpenID Connect are table stakes. SAML, LDAP, CAS, RADIUS and SCIM decide whether it can replace the identity server you have, not just sit next to it.
- Operations. How heavy is it to run, and can you pay someone to run it for you?
- License. Permissive (Apache-2.0, MIT) or copyleft (MPL-2.0, AGPL-3.0), and whether some features sit behind a commercial license.
At a glance
| # | Project | License | Language | GitHub stars | Best for |
|---|---|---|---|---|---|
| 1 | Casdoor | Apache-2.0 | Go, React | 14.5k | All-in-one IAM with a managed cloud option |
| 2 | Keycloak | Apache-2.0 | Java | 37.2k | Enterprises standardised on Red Hat |
| 3 | authentik | MIT (enterprise features separate) | Python, TypeScript | 25.9k | Homelabs and proxy-based SSO |
| 4 | Zitadel | AGPL-3.0 | Go | 15.3k | Multi-tenant B2B SaaS |
| 5 | Ory | Apache-2.0 | Go | 17.6k (Hydra) | Headless, API-first auth |
| 6 | Logto | MPL-2.0 | TypeScript | 14.7k | Developer-friendly customer login |
| 7 | Authelia | Apache-2.0 | Go | 29.2k | Login portal in front of a reverse proxy |
| 8 | SuperTokens | Apache-2.0 (enterprise features separate) | Java, SDKs | 15.3k | Login embedded in your own UI |
| 9 | Dex | Apache-2.0 | Go | 11.2k | Kubernetes and federated OIDC |
| 10 | Kanidm | MPL-2.0 | Rust | 5.4k | Linux and Unix accounts |
1. Casdoor
Casdoor is a complete identity and access management platform: sign-up and login pages, single sign-on, MFA, users and organizations, an admin console and a REST API, in one Go binary with a React frontend.
What puts it first is breadth. Casdoor speaks OAuth 2.0, OIDC, SAML, CAS, LDAP, RADIUS and SCIM, both as an identity provider and as a client of other providers, so it can replace an old LDAP or CAS server instead of sitting next to it. Authorization is built in through Casbin, so ACL, RBAC and ABAC permissions live next to the identities instead of in your application code. It has syncers that import users from Active Directory, LDAP, Entra ID, Google Workspace, Okta, Keycloak and databases, and it can act as the OAuth authorization server for MCP servers and AI agents.
Casdoor is also the only project on this list whose maintainers sell a managed, single-tenant version at a flat price: Casdoor Cloud runs a dedicated instance and database for you from $24.17/month billed yearly, with no per-user fees, and you can move between Cloud and self-hosting because it is the same code.
Where it falls short: it has a smaller community than Keycloak, and users say the documentation lags behind the features. Casdoor Cloud does not have SOC 2 or ISO 27001 reports yet.
2. Keycloak
Keycloak is the most widely deployed open-source identity server and a CNCF incubating project, with Red Hat behind it. It is mature, well understood by auditors, and supports OIDC, OAuth 2.0 and SAML with a deep set of options for realms, flows and identity brokering. It connects to LDAP and Active Directory for user federation.
Where it falls short: it is a Java application that takes real effort to tune, upgrade and theme, and the project itself offers no hosted service. Commercial support comes through Red Hat subscriptions or third parties. See our Casdoor vs Keycloak comparison.
3. authentik
authentik is popular with homelabs and small IT teams. Its "flows" let you design login, enrollment and recovery steps in the UI, and its outposts add SSO to apps that have no login integration by sitting in front of them as a proxy. It supports OIDC, SAML, LDAP and RADIUS.
Where it falls short: the core is MIT, but some features live in an enterprise directory under a separate license, sold at $5 per internal user per month. There is no managed cloud from the authentik team.
4. Zitadel
Zitadel is built in Go around an event-sourced data model, with first-class multi-tenancy: organizations, projects and delegated administration for B2B SaaS. It offers a managed cloud with a free tier of 100 daily active users and a Pro plan at $100 per month.
Where it falls short: since version 3 it is licensed under AGPL-3.0, which some companies' legal teams will not accept for code they modify. Its cloud is priced by daily active users.
5. Ory
Ory is a set of headless services: Kratos for identity, Hydra for OAuth 2.0 and OIDC, Keto for permissions and Oathkeeper as a proxy. Hydra is OpenID Certified and runs at very large scale. You bring your own UI.
Where it falls short: you assemble and operate several services and build every screen yourself. The hosted Ory Network starts at $770 per year for production use.
6. Logto
Logto focuses on developer experience for customer login: polished sign-in pages, many SDKs, organizations and RBAC. Its cloud has a generous free tier of 50,000 MAU.
Where it falls short: in its cloud, RBAC, organizations, MFA, enterprise SSO and custom domains are paid add-ons. It does not speak LDAP, CAS or RADIUS, so it won't replace an existing directory or campus SSO server.
7. Authelia
Authelia is a lightweight login portal that works with reverse proxies such as NGINX, Traefik and Caddy through forward authentication, adding 2FA and SSO to self-hosted apps. It also includes an OpenID Connect provider.
Where it falls short: users come from a file or an LDAP server; there is no user self-service sign-up or full user management, and no SAML.
8. SuperTokens
SuperTokens gives you login building blocks (email and password, passwordless, social login, sessions) that you embed in your own frontend and backend using its SDKs.
Where it falls short: it is a library-style auth layer for your own app rather than an SSO server for many apps. Features in its enterprise directory, such as MFA and account linking, are paid. The managed version charges $0.02 per MAU after 5,000.
9. Dex
Dex is an OpenID Connect provider that federates to other identity sources (LDAP, SAML, GitHub, Google and more). It is widely used to put SSO in front of Kubernetes and its tooling.
Where it falls short: it is a federation layer, not an IAM platform: no user management console, no MFA of its own and no self-service.
10. Kanidm
Kanidm is a Rust identity management server aimed at Linux and Unix estates: it manages POSIX accounts, offers LDAP and RADIUS, OAuth 2.0 and OIDC, and passkeys.
Where it falls short: it is younger and smaller than the others, and it targets infrastructure accounts more than customer login.
Not on the list: FusionAuth
FusionAuth is often recommended as an open-source option, but its Community edition is free to use and not open source. It is a capable product with paid plans from $162 per month billed yearly; we left it out only because of the license.
Which one should you pick?
- You want one platform for customers, employees and AI agents, with the option to have it hosted: Casdoor.
- Your organisation already runs Red Hat and wants a vendor-supported Java server: Keycloak.
- You need SSO in front of self-hosted apps that have no login of their own: authentik or Authelia.
- You are building multi-tenant B2B SaaS and AGPL is acceptable: Zitadel.
- You want fully headless APIs and will build every screen: Ory.
If you want to try the first pick without running anything, start a free Casdoor Cloud trial, or self-host it with Docker in a few minutes.
Sources
- Casdoor on GitHub
- Keycloak on GitHub
- authentik license
- authentik pricing
- Zitadel on GitHub
- Zitadel pricing
- Ory Kratos on GitHub
- Ory Hydra on GitHub
- Logto on GitHub
- Authelia on GitHub
- SuperTokens core license
- Dex on GitHub
- Kanidm on GitHub
- FusionAuth pricing
Product names are trademarks of their respective owners.