This article is written by the team that builds Casdoor, so we are not neutral, and we say where we think Casdoor fits and where it doesn't. Facts about other products come from their own websites as of October 8, 2026 (listed under Sources) and may have changed. Spotted something out of date? Tell us.
If you have decided to self-host your identity provider, the shortlist is usually the same four projects. They overlap a lot, but each was built with a different user in mind, and that shows in the details.
The table
| Casdoor | Keycloak | authentik | Zitadel | |
|---|---|---|---|---|
| License | Apache-2.0 | Apache-2.0 | MIT, enterprise features under a separate license | AGPL-3.0 |
| Written in | Go and React | Java | Python and TypeScript | Go |
| GitHub stars (Oct 2026) | 14.5k | 37.2k | 25.9k | 15.3k |
| OIDC and OAuth 2.0 | Yes | Yes | Yes | Yes |
| SAML | Yes | Yes | Yes | Yes |
| CAS | Yes | No | No | No |
| Serves LDAP to apps | Yes | No (federates from LDAP) | Yes, through an outpost | No |
| Serves RADIUS | Yes | No | Yes, through an outpost | No |
| Authorization model | Casbin: ACL, RBAC, ABAC, custom | Authorization Services (policies, UMA) | Policies on applications and flows | Roles per project |
| Multi-tenancy | Organizations | Realms | Single tenant | Instances and organizations |
| Managed cloud from the maintainers | Casdoor Cloud, flat price per instance | None | None | Zitadel Cloud, priced by daily active users |
Casdoor: the broadest, with a flat-priced cloud
Casdoor's strength is coverage. It is the only one of the four that speaks CAS and can itself serve both LDAP and RADIUS, which matters at universities, in hospitals and anywhere with VPNs, Wi-Fi or old apps that only know LDAP. Authorization is built on Casbin, so you can model ACL, RBAC or ABAC permissions in the console and check them through the API, instead of building a permission system next to your identity system. Syncers keep users in step with Active Directory, LDAP, Entra ID, Google Workspace, Okta, Keycloak and databases, and Casdoor can be the OAuth authorization server for MCP servers and AI agents.
It is a single Go binary with a React console, starts in seconds and runs on a small VM with MySQL, PostgreSQL or SQLite. If you don't want to run it at all, Casdoor Cloud is the same software as a dedicated, managed instance from $24.17/month billed yearly.
Choose Casdoor if you want one system for customers, employees, devices and AI agents, permissive licensing, and the option to have it hosted at a flat price.
Keycloak: the incumbent
Keycloak is the reference implementation many people learn OIDC on, a CNCF incubating project with Red Hat behind it. Its realm model, identity brokering and authentication flows are deep and well documented, and auditors know it.
The cost is weight: a Java service that needs tuning, careful upgrades and work to theme. There is no hosted Keycloak from the project.
Choose Keycloak if you want the most widely deployed option and have a platform team to run it, or you already pay Red Hat. See Casdoor vs Keycloak for more detail.
authentik: the self-hoster's favourite
authentik shines at putting SSO in front of things that have none. Its outposts act as a proxy, LDAP server or RADIUS server, and its visual flow designer makes custom login and enrollment flows approachable. That's why it's a homelab staple.
It is single-tenant, has no hosted version, and some features sit in an enterprise edition priced per internal user.
Choose authentik for internal SSO across self-hosted apps, especially behind a reverse proxy.
Zitadel: built for B2B SaaS
Zitadel was designed around multi-tenancy: instances contain organizations, each with its own users, policies and delegated admins, which maps neatly onto a B2B SaaS product where every customer is a company. Its event-sourced storage gives a full audit trail.
Since version 3 it is AGPL-3.0, so check with your legal team before modifying it. Its cloud is priced by daily active users.
Choose Zitadel if you are building B2B SaaS, want delegated administration per customer, and AGPL is acceptable.
Our recommendation
Start from your hardest requirement:
- Legacy protocols (CAS, LDAP, RADIUS) or fine-grained authorization: Casdoor.
- Red Hat support or the largest community: Keycloak.
- SSO in front of self-hosted apps without login: authentik.
- Per-customer tenants with delegated admins: Zitadel or Casdoor organizations.
All four are free to try. Casdoor's Docker quick start takes a few minutes, or skip the setup with Casdoor Cloud.
Sources
- Casdoor on GitHub
- Keycloak documentation
- authentik documentation
- authentik license
- authentik pricing
- Zitadel documentation
- Zitadel pricing
Product names are trademarks of their respective owners.