Blog · Top lists

Top 10 open-source IAM and SSO solutions in 2026

Casdoor, Keycloak, authentik, Zitadel, Ory and five more open-source identity providers compared: licenses, protocols, languages and who each one fits.

Casdoor Team · October 8, 2026 · 6 min read

This article is written by the team that builds Casdoor, so we are not neutral, and we say where we think Casdoor fits and where it doesn't. Facts about other products come from their own websites as of October 8, 2026 (listed under Sources) and may have changed. Spotted something out of date? Tell us.

Five years ago, "open-source identity provider" mostly meant Keycloak. Today there are a dozen serious projects, and they differ a lot: some are full IAM platforms with a web console, some are headless APIs, and some are just a login portal in front of a reverse proxy. This list ranks the ten we think are worth evaluating in 2026, with what each one is good at and where it falls short.

We only included projects whose source is available under an OSI-approved license. Star counts are from GitHub in October 2026.

How we compared them

  • Scope. Does it cover single sign-on, user management, MFA and authorization, or only part of that?
  • Protocols. OAuth 2.0 and OpenID Connect are table stakes. SAML, LDAP, CAS, RADIUS and SCIM decide whether it can replace the identity server you have, not just sit next to it.
  • Operations. How heavy is it to run, and can you pay someone to run it for you?
  • License. Permissive (Apache-2.0, MIT) or copyleft (MPL-2.0, AGPL-3.0), and whether some features sit behind a commercial license.

At a glance

# Project License Language GitHub stars Best for
1 Casdoor Apache-2.0 Go, React 14.5k All-in-one IAM with a managed cloud option
2 Keycloak Apache-2.0 Java 37.2k Enterprises standardised on Red Hat
3 authentik MIT (enterprise features separate) Python, TypeScript 25.9k Homelabs and proxy-based SSO
4 Zitadel AGPL-3.0 Go 15.3k Multi-tenant B2B SaaS
5 Ory Apache-2.0 Go 17.6k (Hydra) Headless, API-first auth
6 Logto MPL-2.0 TypeScript 14.7k Developer-friendly customer login
7 Authelia Apache-2.0 Go 29.2k Login portal in front of a reverse proxy
8 SuperTokens Apache-2.0 (enterprise features separate) Java, SDKs 15.3k Login embedded in your own UI
9 Dex Apache-2.0 Go 11.2k Kubernetes and federated OIDC
10 Kanidm MPL-2.0 Rust 5.4k Linux and Unix accounts

1. Casdoor

Casdoor is a complete identity and access management platform: sign-up and login pages, single sign-on, MFA, users and organizations, an admin console and a REST API, in one Go binary with a React frontend.

What puts it first is breadth. Casdoor speaks OAuth 2.0, OIDC, SAML, CAS, LDAP, RADIUS and SCIM, both as an identity provider and as a client of other providers, so it can replace an old LDAP or CAS server instead of sitting next to it. Authorization is built in through Casbin, so ACL, RBAC and ABAC permissions live next to the identities instead of in your application code. It has syncers that import users from Active Directory, LDAP, Entra ID, Google Workspace, Okta, Keycloak and databases, and it can act as the OAuth authorization server for MCP servers and AI agents.

Casdoor is also the only project on this list whose maintainers sell a managed, single-tenant version at a flat price: Casdoor Cloud runs a dedicated instance and database for you from $24.17/month billed yearly, with no per-user fees, and you can move between Cloud and self-hosting because it is the same code.

Where it falls short: it has a smaller community than Keycloak, and users say the documentation lags behind the features. Casdoor Cloud does not have SOC 2 or ISO 27001 reports yet.

2. Keycloak

Keycloak is the most widely deployed open-source identity server and a CNCF incubating project, with Red Hat behind it. It is mature, well understood by auditors, and supports OIDC, OAuth 2.0 and SAML with a deep set of options for realms, flows and identity brokering. It connects to LDAP and Active Directory for user federation.

Where it falls short: it is a Java application that takes real effort to tune, upgrade and theme, and the project itself offers no hosted service. Commercial support comes through Red Hat subscriptions or third parties. See our Casdoor vs Keycloak comparison.

3. authentik

authentik is popular with homelabs and small IT teams. Its "flows" let you design login, enrollment and recovery steps in the UI, and its outposts add SSO to apps that have no login integration by sitting in front of them as a proxy. It supports OIDC, SAML, LDAP and RADIUS.

Where it falls short: the core is MIT, but some features live in an enterprise directory under a separate license, sold at $5 per internal user per month. There is no managed cloud from the authentik team.

4. Zitadel

Zitadel is built in Go around an event-sourced data model, with first-class multi-tenancy: organizations, projects and delegated administration for B2B SaaS. It offers a managed cloud with a free tier of 100 daily active users and a Pro plan at $100 per month.

Where it falls short: since version 3 it is licensed under AGPL-3.0, which some companies' legal teams will not accept for code they modify. Its cloud is priced by daily active users.

5. Ory

Ory is a set of headless services: Kratos for identity, Hydra for OAuth 2.0 and OIDC, Keto for permissions and Oathkeeper as a proxy. Hydra is OpenID Certified and runs at very large scale. You bring your own UI.

Where it falls short: you assemble and operate several services and build every screen yourself. The hosted Ory Network starts at $770 per year for production use.

6. Logto

Logto focuses on developer experience for customer login: polished sign-in pages, many SDKs, organizations and RBAC. Its cloud has a generous free tier of 50,000 MAU.

Where it falls short: in its cloud, RBAC, organizations, MFA, enterprise SSO and custom domains are paid add-ons. It does not speak LDAP, CAS or RADIUS, so it won't replace an existing directory or campus SSO server.

7. Authelia

Authelia is a lightweight login portal that works with reverse proxies such as NGINX, Traefik and Caddy through forward authentication, adding 2FA and SSO to self-hosted apps. It also includes an OpenID Connect provider.

Where it falls short: users come from a file or an LDAP server; there is no user self-service sign-up or full user management, and no SAML.

8. SuperTokens

SuperTokens gives you login building blocks (email and password, passwordless, social login, sessions) that you embed in your own frontend and backend using its SDKs.

Where it falls short: it is a library-style auth layer for your own app rather than an SSO server for many apps. Features in its enterprise directory, such as MFA and account linking, are paid. The managed version charges $0.02 per MAU after 5,000.

9. Dex

Dex is an OpenID Connect provider that federates to other identity sources (LDAP, SAML, GitHub, Google and more). It is widely used to put SSO in front of Kubernetes and its tooling.

Where it falls short: it is a federation layer, not an IAM platform: no user management console, no MFA of its own and no self-service.

10. Kanidm

Kanidm is a Rust identity management server aimed at Linux and Unix estates: it manages POSIX accounts, offers LDAP and RADIUS, OAuth 2.0 and OIDC, and passkeys.

Where it falls short: it is younger and smaller than the others, and it targets infrastructure accounts more than customer login.

Not on the list: FusionAuth

FusionAuth is often recommended as an open-source option, but its Community edition is free to use and not open source. It is a capable product with paid plans from $162 per month billed yearly; we left it out only because of the license.

Which one should you pick?

  • You want one platform for customers, employees and AI agents, with the option to have it hosted: Casdoor.
  • Your organisation already runs Red Hat and wants a vendor-supported Java server: Keycloak.
  • You need SSO in front of self-hosted apps that have no login of their own: authentik or Authelia.
  • You are building multi-tenant B2B SaaS and AGPL is acceptable: Zitadel.
  • You want fully headless APIs and will build every screen: Ory.

If you want to try the first pick without running anything, start a free Casdoor Cloud trial, or self-host it with Docker in a few minutes.