Ory Hydra screenshot thumbnail

Ory Hydra

Ory Hydra is an OpenID Certified OAuth 2.0 and OpenID Connect provider that plugs into any existing user database or authentication system through a headless consent and login bridge, letting you own your authorization infrastructure without rebuilding identity management from scratch. The Go binary ships at under 15MB with zero system dependencies and exposes two distinct API surfaces: a public endpoint on port 4444 handling authorization code flows, token exchanges, PKCE challenges, device authorization grants per RFC 8628, and OpenID Connect discovery, plus an admin endpoint on port 4445 managing client registration, token introspection, consent session lifecycle, and JWKS rotation. Access tokens can be issued as opaque reference tokens or signed JWTs for stateless validation at resource servers, while refresh token rotation, token revocation per RFC 7009, and pairwise subject identifiers provide granular security controls. Persistent storage spans PostgreSQL, MySQL, and CockroachDB with automatic schema migrations, and the architecture supports horizontal scaling behind load balancers with shared database state. Dynamic client registration per RFC 7591 enables automated provisioning, and the OAuth 2.0 Threat Model security considerations are implemented as default behaviors rather than optional add-ons. Trusted by OpenAI and other internet-scale platforms. Helm charts and Docker Compose quickstarts provide production-ready deployment paths alongside the broader Ory ecosystem including Kratos for identity management, Oathkeeper for zero-trust API proxying, and Keto for fine-grained permissions. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.

Deploy
Nhost screenshot thumbnail

Nhost

Backed by 9,200 GitHub stars and venture funding led by Nauta Capital, Nhost is the open-source Firebase alternative that replaces Google's proprietary document store with a relational PostgreSQL foundation from day one. The Hasura integration auto-generates a real-time GraphQL API with subscriptions, role-based permissions, and remote schemas from your PostgreSQL tables, while event triggers and cron triggers automate backend workflows without custom infrastructure. Authentication supports email and password, magic links, phone OTP via SMS, social OAuth providers including Google and GitHub, WebAuthn for passwordless login with Face ID, fingerprints, and YubiKeys, plus two-factor authentication. Since the Q1 2026 release, Nhost Auth also functions as a full OAuth2 and OpenID Connect provider, allowing your Nhost project to issue tokens to third-party applications the same way GitHub or Google do. The S3-compatible storage service handles file uploads with automatic image optimization, virus scanning, and presigned URLs for secure direct downloads. Node.js serverless functions deploy JavaScript and TypeScript backend logic without managing servers, while the Nhost CLI spins up the complete local stack via Docker for development with automatic database migration tracking and Hasura metadata management. The MCP server integration exposes project documentation and data schemas to AI assistants for intelligent query building. SDKs cover JavaScript, TypeScript, React, Vue, Next.js, and Dart for Flutter. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.

Deploy
Hanko screenshot thumbnail

Hanko

Backed by 9,000+ GitHub stars and developed by a Germany-based team with deep FIDO2 expertise, Hanko delivers the open-source authentication platform that replaces Auth0, Clerk, and Firebase Auth with a passkey-first architecture built on phishing-resistant WebAuthn credentials. The Go backend exposes both public and administrative HTTP APIs handling passkey registration and login, password authentication, email passcodes, TOTP-based MFA, security key verification, server-side sessions with remote revocation, and JWT issuing with configurable expiry and refresh policies. OAuth SSO connects Apple, Google, GitHub, Microsoft, and custom OIDC providers, while SAML Enterprise SSO integrates corporate identity providers for single sign-on across the organization. Hanko Elements provides framework-agnostic web components that embed complete onboarding, login, and user profile flows into any application with two lines of code, fully customizable via CSS variables and supporting i18n with custom translations. The JavaScript frontend SDK handles API communication, credential management, and session state for teams building custom authentication UIs without the pre-built components. Webhooks notify external services of authentication events including user creation, login, email verification, and password changes. Privacy-first design principles enforce data minimalism with user-deletable passwords and configurable identifier strategies supporting email-only, username-only, or combined approaches. Docker deployment starts the backend with PostgreSQL or MySQL, serving both APIs on configurable ports. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 (backend) / MIT (frontend) licensed.

Deploy
Authorizer screenshot thumbnail

Authorizer

Your users belong in your own database - Authorizer, an open-source authentication and authorization server shipping as a single Go binary, keeps them there. It connects to 13+ backends - PostgreSQL, MySQL, SQLite, SQL Server, MariaDB, MongoDB, Cassandra, ScyllaDB, ArangoDB, DynamoDB, Couchbase, YugabyteDB, PlanetScale, and CockroachDB - so identity data lives beside the application it protects instead of in an auth vendor's cloud. The server is fully OAuth 2.0 and OpenID Connect compliant, including authorization code flow with PKCE, a JWKS endpoint, token revocation, and nine JWT signing algorithms. Login options cover email/password, magic links, TOTP multi-factor, SMS OTP via Twilio, and social providers including Google, GitHub, Apple, Microsoft, and Discord. Authorization goes beyond roles: an embedded OpenFGA engine provides Zanzibar-style relationship-based permission checks in process. APIs are exposed over GraphQL, REST, and gRPC, with SDKs for JavaScript, React, Go, and Python, plus themeable built-in login pages and an admin dashboard. Apache 2.0 licensed.

Deploy
Unkey screenshot thumbnail

Unkey

Unkey is the open-source platform that unifies API key management, rate limiting, deployment, and observability into a single control plane. The Go API service validates keys with sub-millisecond latency using regional Redis caches and MySQL 8.0 persistent storage, while ClickHouse captures every verification event for per-key and per-keyspace analytics with filterable time-series charts, request counters, and active key tracking. Keyspaces organize API keys by product, environment, or tier, each configurable with custom prefixes, byte lengths, IP whitelists, encrypted key recovery, and delete protection. Per-key settings include expiration dates, rate limit quotas with configurable windows, RBAC roles and permissions, owner identities linking multiple keys to a single user or organization, and key rotation with grace periods from immediate revocation through 24-hour overlap. The deployment pipeline connects GitHub repositories for automatic Docker container builds, generates preview environments per commit, promotes tested versions to production, and validates releases with OpenAPI diff detection flagging breaking changes before production. The edge gateway authenticates and rate-limits requests at the closest region before routing to the nearest API instance. Immutable audit logs track every key creation, verification, deletion, and configuration change with actor, timestamp, and event metadata. The CLI provides terminal access to key management, analytics queries, and deployment operations. On RepoCloud, deploy Unkey on a dedicated VPS with Docker, root SSH access, and complete control over your API infrastructure, all under the AGPL license.

Deploy