Blog · Comparisons

Casdoor vs Keycloak vs authentik vs Zitadel: which open-source IdP?

A side-by-side comparison of the four most popular self-hostable identity providers: license, stack, protocols, authorization, multi-tenancy and managed hosting.

Casdoor Team · October 8, 2026 · 3 min read

This article is written by the team that builds Casdoor, so we are not neutral, and we say where we think Casdoor fits and where it doesn't. Facts about other products come from their own websites as of October 8, 2026 (listed under Sources) and may have changed. Spotted something out of date? Tell us.

If you have decided to self-host your identity provider, the shortlist is usually the same four projects. They overlap a lot, but each was built with a different user in mind, and that shows in the details.

The table

Casdoor Keycloak authentik Zitadel
License Apache-2.0 Apache-2.0 MIT, enterprise features under a separate license AGPL-3.0
Written in Go and React Java Python and TypeScript Go
GitHub stars (Oct 2026) 14.5k 37.2k 25.9k 15.3k
OIDC and OAuth 2.0 Yes Yes Yes Yes
SAML Yes Yes Yes Yes
CAS Yes No No No
Serves LDAP to apps Yes No (federates from LDAP) Yes, through an outpost No
Serves RADIUS Yes No Yes, through an outpost No
Authorization model Casbin: ACL, RBAC, ABAC, custom Authorization Services (policies, UMA) Policies on applications and flows Roles per project
Multi-tenancy Organizations Realms Single tenant Instances and organizations
Managed cloud from the maintainers Casdoor Cloud, flat price per instance None None Zitadel Cloud, priced by daily active users

Casdoor: the broadest, with a flat-priced cloud

Casdoor's strength is coverage. It is the only one of the four that speaks CAS and can itself serve both LDAP and RADIUS, which matters at universities, in hospitals and anywhere with VPNs, Wi-Fi or old apps that only know LDAP. Authorization is built on Casbin, so you can model ACL, RBAC or ABAC permissions in the console and check them through the API, instead of building a permission system next to your identity system. Syncers keep users in step with Active Directory, LDAP, Entra ID, Google Workspace, Okta, Keycloak and databases, and Casdoor can be the OAuth authorization server for MCP servers and AI agents.

It is a single Go binary with a React console, starts in seconds and runs on a small VM with MySQL, PostgreSQL or SQLite. If you don't want to run it at all, Casdoor Cloud is the same software as a dedicated, managed instance from $24.17/month billed yearly.

Choose Casdoor if you want one system for customers, employees, devices and AI agents, permissive licensing, and the option to have it hosted at a flat price.

Keycloak: the incumbent

Keycloak is the reference implementation many people learn OIDC on, a CNCF incubating project with Red Hat behind it. Its realm model, identity brokering and authentication flows are deep and well documented, and auditors know it.

The cost is weight: a Java service that needs tuning, careful upgrades and work to theme. There is no hosted Keycloak from the project.

Choose Keycloak if you want the most widely deployed option and have a platform team to run it, or you already pay Red Hat. See Casdoor vs Keycloak for more detail.

authentik: the self-hoster's favourite

authentik shines at putting SSO in front of things that have none. Its outposts act as a proxy, LDAP server or RADIUS server, and its visual flow designer makes custom login and enrollment flows approachable. That's why it's a homelab staple.

It is single-tenant, has no hosted version, and some features sit in an enterprise edition priced per internal user.

Choose authentik for internal SSO across self-hosted apps, especially behind a reverse proxy.

Zitadel: built for B2B SaaS

Zitadel was designed around multi-tenancy: instances contain organizations, each with its own users, policies and delegated admins, which maps neatly onto a B2B SaaS product where every customer is a company. Its event-sourced storage gives a full audit trail.

Since version 3 it is AGPL-3.0, so check with your legal team before modifying it. Its cloud is priced by daily active users.

Choose Zitadel if you are building B2B SaaS, want delegated administration per customer, and AGPL is acceptable.

Our recommendation

Start from your hardest requirement:

  1. Legacy protocols (CAS, LDAP, RADIUS) or fine-grained authorization: Casdoor.
  2. Red Hat support or the largest community: Keycloak.
  3. SSO in front of self-hosted apps without login: authentik.
  4. Per-customer tenants with delegated admins: Zitadel or Casdoor organizations.

All four are free to try. Casdoor's Docker quick start takes a few minutes, or skip the setup with Casdoor Cloud.