Repository files navigation

Awesome Authentication & Authorization & SSO & IAM Awesome

Quality Authentication & Authorization & SSO & IAM software and libraries.

Authentication (aka AuthN) and authorization (aka AuthZ) are both security measures. Authentication is the process of verifying who you are. Authorization is the process of verifying that you have access to something. Authorization occurs after successful authentication.

Contents

SSO (Single-Sign-On), IAM (Identity Access Management)

  • Casdoor - UI-first centralized authentication / Single-Sign-On (SSO) platform supporting OAuth 2.0 / OIDC and SAML.
  • Keycloak - Open Source Identity and Access Management.
  • Authelia - The Single Sign-On Multi-Factor portal for web apps.
  • ZITADEL - Cloud-native Identity & Access Management platform for secure authentication, authorization and identity management.
  • Authentik - authentik is an open-source Identity Provider that emphasizes flexibility and versatility. It can be seamlessly integrated into existing environments to support new protocols.
  • Stack Auth - Open-source, developer-friendly authentication, authorization, and IAM solution.
  • Scalekit – Add enterprise SSO (SAML, OIDC) and SCIM provisioning on top of existing auth systems alongside additive auth stack for MCP and Agent Auth.
  • Cloud-IAM - Managed Keycloak SaaS platform supporting OpenID Connect, OAuth 2.0 and SAML, with ISO 27001, SOC 2 Type 2, NIS 2, GDPR, HDS and SecNumCloud 3.2 certifications.
  • SSOJet – Add enterprise SSO (SAML, OIDC) and SCIM user provisioning to your app without changing your existing authentication system.
  • Logto - An IAM infrastructure with AuthN, AuthZ, MFA, SSO, user management, and multi-tenancy features, supporting OAuth 2.0, OIDC, and SAML.
  • Neon Auth - Managed authentication built on Better Auth that syncs users directly into your Neon Postgres database.
  • NanoIDP - Local development Identity Provider for testing OAuth2, OpenID Connect, and SAML flows without running a full IAM stack.

Authentication

C#

Golang

  • Casdoor - UI-first centralized authentication / Single-Sign-On (SSO) platform supporting OAuth 2.0 / OIDC and SAML.
  • OIDC - OpenID Connect Library (client and server) for Go
  • Ory Hydra - OpenID Connect certified OAuth2 server.
  • Ory Kratos - API-first Identity and User Management system built for cloud applications.
  • Ory Oathkeeper - Identity/Access proxy inspired by the BeyondCorp/Zero-Trust white paper.
  • Ory Fosite - Extensible OAuth 2.0 and OpenID Connect SDK for Golang.
  • ZITADEL - Cloud-native Identity & Access Management platform for secure authentication, authorization and identity management.

Java

  • Apache Shiro - Powerful and easy-to-use Java security framework that performs authentication, authorization, cryptography, and session management.
  • pac4j - Security engine for Java (authentication, authorization, multi frameworks): OAuth, CAS, SAML, OpenID Connect, LDAP, JWT.
  • Spring Security OAuth - Provides support for using Spring Security with OAuth (1a) and OAuth2.

Node.js

  • Passport - Simple, unobtrusive authentication for Node.js. A comprehensive set of strategies support authentication using a username and password, Facebook, Twitter, and more.
  • bell - Third-party authentication plugin for hapi. Ships with built-in support for various well-known sites and simple configuration object will support other OAuth 1.0a and OAuth 2.0 sites.
  • Stack Auth - Open-source authN & authZ for modern web apps, comes with pre-built components for Next.js.
  • client-certificate-auth - Mutual TLS (mTLS) client certificate authentication middleware for Node.js with reverse proxy support, composable verification callbacks, and X.509 certificate parsing.

Python

  • Keystone - Provides authentication, authorization and service discovery mechanisms via HTTP primarily for use by projects in the OpenStack family.
  • Authomatic - Simple yet powerful authorization & authentication client library for Python web applications.
  • Python Social Auth - Easy to setup social authentication/registration mechanism with support for several frameworks and auth providers.
  • Raider - Web authentication testing framework, which treats the authentication process as finite state machines.

Ruby

  • Authlogic - Clean, simple, and unobtrusive Ruby authentication solution.

Flutter

  • Authgear SDK for Flutter - With Authgear SDK for Flutter, you can easily integrate authentication features into your Flutter apps. In most cases, it involves just a few lines of code to enable multiple authentication methods.

Authorization

Android

  • AndPermission - Android runtime permission, support the right to apply for permission at any place.
  • Authgear SDK for Android - Android SDK to authenticate and authorize users based on the OAuth 2.0 authorization framework.

C#

  • Casbin.NET - Authorization library that supports access control models like ACL, RBAC, ABAC in .NET (C#).
  • Cerbos - Open-source authorization layer with a .NET SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Golang

  • Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Golang.
  • goRBAC - Lightweight role-based access control implementation in Go.
  • Ladon - SDK for access control policies: authorization for the microservice and IoT age.
  • OIDC - OpenID Connect Library (client and server) for Go
  • Ory Keto - Access control server capable of solving complex use cases (multi-tenant, attribute-based access control, etc.) with access control policies.
  • Oso - Batteries-included framework for building authorization in your Go application.
  • Topaz - Fine-grained authorization for cloud-native applications. Combining the best of OPA and Zanzibar
  • SpiceDB - Open-source implementation of the Zanzibar paper, a performant database for fine-grained permissions.
  • ZITADEL - Cloud-native Identity & Access Management platform for secure authentication, authorization and identity management.
  • Cerbos - Open-source authorization layer with a Go SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Rust

  • Casbin-Rs - Authorization library that supports access control models like ACL, RBAC, ABAC in Rust.
  • Oso - Batteries-included framework for building authorization in your Rust application.
  • Cerbos - Open-source authorization layer with a Rust SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

iOS

  • Permission - Unified API to ask for permissions on iOS.
  • Authgear SDK for iOS - With Authgear SDK for iOS, you can easily integrate authorization features into your iOS apps.

Java

  • jCasbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Java.
  • Apache Shiro - Powerful and easy-to-use Java security framework that performs authentication, authorization, cryptography, and session management.
  • pac4j - Security engine for Java (authentication, authorization, multi-frameworks): OAuth, CAS, SAML, OpenID Connect, LDAP, JWT.
  • AT&T XACML - XACML 3.0 implementation from AT&T.
  • TOTP Server-Side Library - TOTP server-side library.
  • Oso - Batteries-included framework for building authorization in your Java application.
  • Cerbos - Open-source authorization layer with a Java SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Node.js

  • Node-Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Node.js.
  • RBAC - Hierarchical role-based access control for Node.js.
  • ABAC - Attribute-based access control for Node.js.
  • accesscontrol - Role and attribute-based access control for Node.js.
  • Oso - Batteries-included framework for building authorization in your Node.js application.
  • Stack Auth - Open-source authN & authZ for modern web apps, comes with pre-built components for Next.js.
  • pundit-ts - Fully type-safe authorization library inspired by awesome pundit gem. Can be used for RBAC, ABAC access control models or any other model you wish.
  • Cerbos - Open-source authorization layer with a JavaScript/Node.js SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

PHP

  • PHP-Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in PHP.
  • PHP-RBAC - Authorization library for PHP which provides developers with NIST Level 2 hierarchical role-based access control.
  • ezRbac - Simple yet easy to implement role-based access control library for popular PHP framework: Codeigniter.
  • php-abac - Attribute-based access control library.
  • laravel-permission - Allows you to manage user permissions and roles in a database.
  • logical-permissions-php - This is a generic library that provides support for array-based permissions with logic gates such as AND and OR.
  • symfony-logical-authorization-bundle - This Symfony bundle provides a unifying solution for authorization that aims to be flexible, convenient and consistent.
  • Cerbos - Open-source authorization layer with a PHP SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Python

  • PyCasbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Python.
  • casbin-fastapi-decorator - Decorator-based authorization for FastAPI using PyCasbin, providing per-route permissions with no middleware and support for JWT, async SQLAlchemy, and Casdoor.
  • Flask-RBAC - Adds RBAC support to Flask.
  • Vakt - Attribute-based access control (ABAC) SDK for Python.
  • Oso - Batteries-included framework for building authorization in your Python application.
  • Cerbos - Open-source authorization layer with a Python SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Ruby

  • Oso - Batteries-included framework for building authorization in your Ruby application.
  • Pundit - Minimal authorization through OO design and pure Ruby classes.
  • Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Ruby.
  • CanCanCan - Authorization for Ruby on Rails.
  • Cerbos - Open-source authorization layer with a Ruby SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

AI Agent Auth

  • Arcade - Tool-calling platform with user approvals and authenticated actions for AI agents.
  • authsome - Local-first credential broker for AI agents with an encrypted local vault and HTTPS proxy injection; no hosted service required.
  • Composio - Hosted integration platform with managed OAuth and tool calling for 1000+ apps.
  • Nango - Open-source OAuth and API key handling for 700+ APIs with token refresh and a unified API for agent workloads.
  • Cerbos - Open-source, policy-based authorization for AI agents, agentic workflows, and MCP servers, with fine-grained access control and full decision logging at runtime.

Articles

Contribute

PR is welcomed.

License

This project is licensed under the CC0-1.0 license.

Releases

Packages

Used by

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

Awesome Authentication & Authorization & SSO & IAM Awesome

Quality Authentication & Authorization & SSO & IAM software and libraries.

Authentication (aka AuthN) and authorization (aka AuthZ) are both security measures. Authentication is the process of verifying who you are. Authorization is the process of verifying that you have access to something. Authorization occurs after successful authentication.

Contents

SSO (Single-Sign-On), IAM (Identity Access Management)

  • Casdoor - UI-first centralized authentication / Single-Sign-On (SSO) platform supporting OAuth 2.0 / OIDC and SAML.
  • Keycloak - Open Source Identity and Access Management.
  • Authelia - The Single Sign-On Multi-Factor portal for web apps.
  • ZITADEL - Cloud-native Identity & Access Management platform for secure authentication, authorization and identity management.
  • Authentik - authentik is an open-source Identity Provider that emphasizes flexibility and versatility. It can be seamlessly integrated into existing environments to support new protocols.
  • Stack Auth - Open-source, developer-friendly authentication, authorization, and IAM solution.
  • Scalekit – Add enterprise SSO (SAML, OIDC) and SCIM provisioning on top of existing auth systems alongside additive auth stack for MCP and Agent Auth.
  • Cloud-IAM - Managed Keycloak SaaS platform supporting OpenID Connect, OAuth 2.0 and SAML, with ISO 27001, SOC 2 Type 2, NIS 2, GDPR, HDS and SecNumCloud 3.2 certifications.
  • SSOJet – Add enterprise SSO (SAML, OIDC) and SCIM user provisioning to your app without changing your existing authentication system.
  • Logto - An IAM infrastructure with AuthN, AuthZ, MFA, SSO, user management, and multi-tenancy features, supporting OAuth 2.0, OIDC, and SAML.
  • Neon Auth - Managed authentication built on Better Auth that syncs users directly into your Neon Postgres database.
  • NanoIDP - Local development Identity Provider for testing OAuth2, OpenID Connect, and SAML flows without running a full IAM stack.

Authentication

C#

Golang

  • Casdoor - UI-first centralized authentication / Single-Sign-On (SSO) platform supporting OAuth 2.0 / OIDC and SAML.
  • OIDC - OpenID Connect Library (client and server) for Go
  • Ory Hydra - OpenID Connect certified OAuth2 server.
  • Ory Kratos - API-first Identity and User Management system built for cloud applications.
  • Ory Oathkeeper - Identity/Access proxy inspired by the BeyondCorp/Zero-Trust white paper.
  • Ory Fosite - Extensible OAuth 2.0 and OpenID Connect SDK for Golang.
  • ZITADEL - Cloud-native Identity & Access Management platform for secure authentication, authorization and identity management.

Java

  • Apache Shiro - Powerful and easy-to-use Java security framework that performs authentication, authorization, cryptography, and session management.
  • pac4j - Security engine for Java (authentication, authorization, multi frameworks): OAuth, CAS, SAML, OpenID Connect, LDAP, JWT.
  • Spring Security OAuth - Provides support for using Spring Security with OAuth (1a) and OAuth2.

Node.js

  • Passport - Simple, unobtrusive authentication for Node.js. A comprehensive set of strategies support authentication using a username and password, Facebook, Twitter, and more.
  • bell - Third-party authentication plugin for hapi. Ships with built-in support for various well-known sites and simple configuration object will support other OAuth 1.0a and OAuth 2.0 sites.
  • Stack Auth - Open-source authN & authZ for modern web apps, comes with pre-built components for Next.js.
  • client-certificate-auth - Mutual TLS (mTLS) client certificate authentication middleware for Node.js with reverse proxy support, composable verification callbacks, and X.509 certificate parsing.

Python

  • Keystone - Provides authentication, authorization and service discovery mechanisms via HTTP primarily for use by projects in the OpenStack family.
  • Authomatic - Simple yet powerful authorization & authentication client library for Python web applications.
  • Python Social Auth - Easy to setup social authentication/registration mechanism with support for several frameworks and auth providers.
  • Raider - Web authentication testing framework, which treats the authentication process as finite state machines.

Ruby

  • Authlogic - Clean, simple, and unobtrusive Ruby authentication solution.

Flutter

  • Authgear SDK for Flutter - With Authgear SDK for Flutter, you can easily integrate authentication features into your Flutter apps. In most cases, it involves just a few lines of code to enable multiple authentication methods.

Authorization

Android

  • AndPermission - Android runtime permission, support the right to apply for permission at any place.
  • Authgear SDK for Android - Android SDK to authenticate and authorize users based on the OAuth 2.0 authorization framework.

C#

  • Casbin.NET - Authorization library that supports access control models like ACL, RBAC, ABAC in .NET (C#).
  • Cerbos - Open-source authorization layer with a .NET SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Golang

  • Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Golang.
  • goRBAC - Lightweight role-based access control implementation in Go.
  • Ladon - SDK for access control policies: authorization for the microservice and IoT age.
  • OIDC - OpenID Connect Library (client and server) for Go
  • Ory Keto - Access control server capable of solving complex use cases (multi-tenant, attribute-based access control, etc.) with access control policies.
  • Oso - Batteries-included framework for building authorization in your Go application.
  • Topaz - Fine-grained authorization for cloud-native applications. Combining the best of OPA and Zanzibar
  • SpiceDB - Open-source implementation of the Zanzibar paper, a performant database for fine-grained permissions.
  • ZITADEL - Cloud-native Identity & Access Management platform for secure authentication, authorization and identity management.
  • Cerbos - Open-source authorization layer with a Go SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Rust

  • Casbin-Rs - Authorization library that supports access control models like ACL, RBAC, ABAC in Rust.
  • Oso - Batteries-included framework for building authorization in your Rust application.
  • Cerbos - Open-source authorization layer with a Rust SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

iOS

  • Permission - Unified API to ask for permissions on iOS.
  • Authgear SDK for iOS - With Authgear SDK for iOS, you can easily integrate authorization features into your iOS apps.

Java

  • jCasbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Java.
  • Apache Shiro - Powerful and easy-to-use Java security framework that performs authentication, authorization, cryptography, and session management.
  • pac4j - Security engine for Java (authentication, authorization, multi-frameworks): OAuth, CAS, SAML, OpenID Connect, LDAP, JWT.
  • AT&T XACML - XACML 3.0 implementation from AT&T.
  • TOTP Server-Side Library - TOTP server-side library.
  • Oso - Batteries-included framework for building authorization in your Java application.
  • Cerbos - Open-source authorization layer with a Java SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Node.js

  • Node-Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Node.js.
  • RBAC - Hierarchical role-based access control for Node.js.
  • ABAC - Attribute-based access control for Node.js.
  • accesscontrol - Role and attribute-based access control for Node.js.
  • Oso - Batteries-included framework for building authorization in your Node.js application.
  • Stack Auth - Open-source authN & authZ for modern web apps, comes with pre-built components for Next.js.
  • pundit-ts - Fully type-safe authorization library inspired by awesome pundit gem. Can be used for RBAC, ABAC access control models or any other model you wish.
  • Cerbos - Open-source authorization layer with a JavaScript/Node.js SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

PHP

  • PHP-Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in PHP.
  • PHP-RBAC - Authorization library for PHP which provides developers with NIST Level 2 hierarchical role-based access control.
  • ezRbac - Simple yet easy to implement role-based access control library for popular PHP framework: Codeigniter.
  • php-abac - Attribute-based access control library.
  • laravel-permission - Allows you to manage user permissions and roles in a database.
  • logical-permissions-php - This is a generic library that provides support for array-based permissions with logic gates such as AND and OR.
  • symfony-logical-authorization-bundle - This Symfony bundle provides a unifying solution for authorization that aims to be flexible, convenient and consistent.
  • Cerbos - Open-source authorization layer with a PHP SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Python

  • PyCasbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Python.
  • casbin-fastapi-decorator - Decorator-based authorization for FastAPI using PyCasbin, providing per-route permissions with no middleware and support for JWT, async SQLAlchemy, and Casdoor.
  • Flask-RBAC - Adds RBAC support to Flask.
  • Vakt - Attribute-based access control (ABAC) SDK for Python.
  • Oso - Batteries-included framework for building authorization in your Python application.
  • Cerbos - Open-source authorization layer with a Python SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Ruby

  • Oso - Batteries-included framework for building authorization in your Ruby application.
  • Pundit - Minimal authorization through OO design and pure Ruby classes.
  • Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Ruby.
  • CanCanCan - Authorization for Ruby on Rails.
  • Cerbos - Open-source authorization layer with a Ruby SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

AI Agent Auth

  • Arcade - Tool-calling platform with user approvals and authenticated actions for AI agents.
  • authsome - Local-first credential broker for AI agents with an encrypted local vault and HTTPS proxy injection; no hosted service required.
  • Composio - Hosted integration platform with managed OAuth and tool calling for 1000+ apps.
  • Nango - Open-source OAuth and API key handling for 700+ APIs with token refresh and a unified API for agent workloads.
  • Cerbos - Open-source, policy-based authorization for AI agents, agentic workflows, and MCP servers, with fine-grained access control and full decision logging at runtime.

Articles

Contribute

PR is welcomed.

License

This project is licensed under the CC0-1.0 license.

Releases

Packages

Used by

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Awesome Authentication & Authorization & SSO & IAM Awesome

Quality Authentication & Authorization & SSO & IAM software and libraries.

Authentication (aka AuthN) and authorization (aka AuthZ) are both security measures. Authentication is the process of verifying who you are. Authorization is the process of verifying that you have access to something. Authorization occurs after successful authentication.

Contents

SSO (Single-Sign-On), IAM (Identity Access Management)

  • Casdoor - UI-first centralized authentication / Single-Sign-On (SSO) platform supporting OAuth 2.0 / OIDC and SAML.
  • Keycloak - Open Source Identity and Access Management.
  • Authelia - The Single Sign-On Multi-Factor portal for web apps.
  • ZITADEL - Cloud-native Identity & Access Management platform for secure authentication, authorization and identity management.
  • Authentik - authentik is an open-source Identity Provider that emphasizes flexibility and versatility. It can be seamlessly integrated into existing environments to support new protocols.
  • Stack Auth - Open-source, developer-friendly authentication, authorization, and IAM solution.
  • Scalekit – Add enterprise SSO (SAML, OIDC) and SCIM provisioning on top of existing auth systems alongside additive auth stack for MCP and Agent Auth.
  • Cloud-IAM - Managed Keycloak SaaS platform supporting OpenID Connect, OAuth 2.0 and SAML, with ISO 27001, SOC 2 Type 2, NIS 2, GDPR, HDS and SecNumCloud 3.2 certifications.
  • SSOJet – Add enterprise SSO (SAML, OIDC) and SCIM user provisioning to your app without changing your existing authentication system.
  • Logto - An IAM infrastructure with AuthN, AuthZ, MFA, SSO, user management, and multi-tenancy features, supporting OAuth 2.0, OIDC, and SAML.
  • Neon Auth - Managed authentication built on Better Auth that syncs users directly into your Neon Postgres database.
  • NanoIDP - Local development Identity Provider for testing OAuth2, OpenID Connect, and SAML flows without running a full IAM stack.

Authentication

C#

Golang

  • Casdoor - UI-first centralized authentication / Single-Sign-On (SSO) platform supporting OAuth 2.0 / OIDC and SAML.
  • OIDC - OpenID Connect Library (client and server) for Go
  • Ory Hydra - OpenID Connect certified OAuth2 server.
  • Ory Kratos - API-first Identity and User Management system built for cloud applications.
  • Ory Oathkeeper - Identity/Access proxy inspired by the BeyondCorp/Zero-Trust white paper.
  • Ory Fosite - Extensible OAuth 2.0 and OpenID Connect SDK for Golang.
  • ZITADEL - Cloud-native Identity & Access Management platform for secure authentication, authorization and identity management.

Java

  • Apache Shiro - Powerful and easy-to-use Java security framework that performs authentication, authorization, cryptography, and session management.
  • pac4j - Security engine for Java (authentication, authorization, multi frameworks): OAuth, CAS, SAML, OpenID Connect, LDAP, JWT.
  • Spring Security OAuth - Provides support for using Spring Security with OAuth (1a) and OAuth2.

Node.js

  • Passport - Simple, unobtrusive authentication for Node.js. A comprehensive set of strategies support authentication using a username and password, Facebook, Twitter, and more.
  • bell - Third-party authentication plugin for hapi. Ships with built-in support for various well-known sites and simple configuration object will support other OAuth 1.0a and OAuth 2.0 sites.
  • Stack Auth - Open-source authN & authZ for modern web apps, comes with pre-built components for Next.js.
  • client-certificate-auth - Mutual TLS (mTLS) client certificate authentication middleware for Node.js with reverse proxy support, composable verification callbacks, and X.509 certificate parsing.

Python

  • Keystone - Provides authentication, authorization and service discovery mechanisms via HTTP primarily for use by projects in the OpenStack family.
  • Authomatic - Simple yet powerful authorization & authentication client library for Python web applications.
  • Python Social Auth - Easy to setup social authentication/registration mechanism with support for several frameworks and auth providers.
  • Raider - Web authentication testing framework, which treats the authentication process as finite state machines.

Ruby

  • Authlogic - Clean, simple, and unobtrusive Ruby authentication solution.

Flutter

  • Authgear SDK for Flutter - With Authgear SDK for Flutter, you can easily integrate authentication features into your Flutter apps. In most cases, it involves just a few lines of code to enable multiple authentication methods.

Authorization

Android

  • AndPermission - Android runtime permission, support the right to apply for permission at any place.
  • Authgear SDK for Android - Android SDK to authenticate and authorize users based on the OAuth 2.0 authorization framework.

C#

  • Casbin.NET - Authorization library that supports access control models like ACL, RBAC, ABAC in .NET (C#).
  • Cerbos - Open-source authorization layer with a .NET SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Golang

  • Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Golang.
  • goRBAC - Lightweight role-based access control implementation in Go.
  • Ladon - SDK for access control policies: authorization for the microservice and IoT age.
  • OIDC - OpenID Connect Library (client and server) for Go
  • Ory Keto - Access control server capable of solving complex use cases (multi-tenant, attribute-based access control, etc.) with access control policies.
  • Oso - Batteries-included framework for building authorization in your Go application.
  • Topaz - Fine-grained authorization for cloud-native applications. Combining the best of OPA and Zanzibar
  • SpiceDB - Open-source implementation of the Zanzibar paper, a performant database for fine-grained permissions.
  • ZITADEL - Cloud-native Identity & Access Management platform for secure authentication, authorization and identity management.
  • Cerbos - Open-source authorization layer with a Go SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Rust

  • Casbin-Rs - Authorization library that supports access control models like ACL, RBAC, ABAC in Rust.
  • Oso - Batteries-included framework for building authorization in your Rust application.
  • Cerbos - Open-source authorization layer with a Rust SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

iOS

  • Permission - Unified API to ask for permissions on iOS.
  • Authgear SDK for iOS - With Authgear SDK for iOS, you can easily integrate authorization features into your iOS apps.

Java

  • jCasbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Java.
  • Apache Shiro - Powerful and easy-to-use Java security framework that performs authentication, authorization, cryptography, and session management.
  • pac4j - Security engine for Java (authentication, authorization, multi-frameworks): OAuth, CAS, SAML, OpenID Connect, LDAP, JWT.
  • AT&T XACML - XACML 3.0 implementation from AT&T.
  • TOTP Server-Side Library - TOTP server-side library.
  • Oso - Batteries-included framework for building authorization in your Java application.
  • Cerbos - Open-source authorization layer with a Java SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Node.js

  • Node-Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Node.js.
  • RBAC - Hierarchical role-based access control for Node.js.
  • ABAC - Attribute-based access control for Node.js.
  • accesscontrol - Role and attribute-based access control for Node.js.
  • Oso - Batteries-included framework for building authorization in your Node.js application.
  • Stack Auth - Open-source authN & authZ for modern web apps, comes with pre-built components for Next.js.
  • pundit-ts - Fully type-safe authorization library inspired by awesome pundit gem. Can be used for RBAC, ABAC access control models or any other model you wish.
  • Cerbos - Open-source authorization layer with a JavaScript/Node.js SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

PHP

  • PHP-Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in PHP.
  • PHP-RBAC - Authorization library for PHP which provides developers with NIST Level 2 hierarchical role-based access control.
  • ezRbac - Simple yet easy to implement role-based access control library for popular PHP framework: Codeigniter.
  • php-abac - Attribute-based access control library.
  • laravel-permission - Allows you to manage user permissions and roles in a database.
  • logical-permissions-php - This is a generic library that provides support for array-based permissions with logic gates such as AND and OR.
  • symfony-logical-authorization-bundle - This Symfony bundle provides a unifying solution for authorization that aims to be flexible, convenient and consistent.
  • Cerbos - Open-source authorization layer with a PHP SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Python

  • PyCasbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Python.
  • casbin-fastapi-decorator - Decorator-based authorization for FastAPI using PyCasbin, providing per-route permissions with no middleware and support for JWT, async SQLAlchemy, and Casdoor.
  • Flask-RBAC - Adds RBAC support to Flask.
  • Vakt - Attribute-based access control (ABAC) SDK for Python.
  • Oso - Batteries-included framework for building authorization in your Python application.
  • Cerbos - Open-source authorization layer with a Python SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Ruby

  • Oso - Batteries-included framework for building authorization in your Ruby application.
  • Pundit - Minimal authorization through OO design and pure Ruby classes.
  • Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Ruby.
  • CanCanCan - Authorization for Ruby on Rails.
  • Cerbos - Open-source authorization layer with a Ruby SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

AI Agent Auth

  • Arcade - Tool-calling platform with user approvals and authenticated actions for AI agents.
  • authsome - Local-first credential broker for AI agents with an encrypted local vault and HTTPS proxy injection; no hosted service required.
  • Composio - Hosted integration platform with managed OAuth and tool calling for 1000+ apps.
  • Nango - Open-source OAuth and API key handling for 700+ APIs with token refresh and a unified API for agent workloads.
  • Cerbos - Open-source, policy-based authorization for AI agents, agentic workflows, and MCP servers, with fine-grained access control and full decision logging at runtime.

Articles

Contribute

PR is welcomed.

License

This project is licensed under the CC0-1.0 license.

Releases

Packages

Used by

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Awesome Authentication & Authorization & SSO & IAM Awesome

Quality Authentication & Authorization & SSO & IAM software and libraries.

Authentication (aka AuthN) and authorization (aka AuthZ) are both security measures. Authentication is the process of verifying who you are. Authorization is the process of verifying that you have access to something. Authorization occurs after successful authentication.

Contents

SSO (Single-Sign-On), IAM (Identity Access Management)

  • Casdoor - UI-first centralized authentication / Single-Sign-On (SSO) platform supporting OAuth 2.0 / OIDC and SAML.
  • Keycloak - Open Source Identity and Access Management.
  • Authelia - The Single Sign-On Multi-Factor portal for web apps.
  • ZITADEL - Cloud-native Identity & Access Management platform for secure authentication, authorization and identity management.
  • Authentik - authentik is an open-source Identity Provider that emphasizes flexibility and versatility. It can be seamlessly integrated into existing environments to support new protocols.
  • Stack Auth - Open-source, developer-friendly authentication, authorization, and IAM solution.
  • Scalekit – Add enterprise SSO (SAML, OIDC) and SCIM provisioning on top of existing auth systems alongside additive auth stack for MCP and Agent Auth.
  • Cloud-IAM - Managed Keycloak SaaS platform supporting OpenID Connect, OAuth 2.0 and SAML, with ISO 27001, SOC 2 Type 2, NIS 2, GDPR, HDS and SecNumCloud 3.2 certifications.
  • SSOJet – Add enterprise SSO (SAML, OIDC) and SCIM user provisioning to your app without changing your existing authentication system.
  • Logto - An IAM infrastructure with AuthN, AuthZ, MFA, SSO, user management, and multi-tenancy features, supporting OAuth 2.0, OIDC, and SAML.
  • Neon Auth - Managed authentication built on Better Auth that syncs users directly into your Neon Postgres database.
  • NanoIDP - Local development Identity Provider for testing OAuth2, OpenID Connect, and SAML flows without running a full IAM stack.

Authentication

C#

Golang

  • Casdoor - UI-first centralized authentication / Single-Sign-On (SSO) platform supporting OAuth 2.0 / OIDC and SAML.
  • OIDC - OpenID Connect Library (client and server) for Go
  • Ory Hydra - OpenID Connect certified OAuth2 server.
  • Ory Kratos - API-first Identity and User Management system built for cloud applications.
  • Ory Oathkeeper - Identity/Access proxy inspired by the BeyondCorp/Zero-Trust white paper.
  • Ory Fosite - Extensible OAuth 2.0 and OpenID Connect SDK for Golang.
  • ZITADEL - Cloud-native Identity & Access Management platform for secure authentication, authorization and identity management.

Java

  • Apache Shiro - Powerful and easy-to-use Java security framework that performs authentication, authorization, cryptography, and session management.
  • pac4j - Security engine for Java (authentication, authorization, multi frameworks): OAuth, CAS, SAML, OpenID Connect, LDAP, JWT.
  • Spring Security OAuth - Provides support for using Spring Security with OAuth (1a) and OAuth2.

Node.js

  • Passport - Simple, unobtrusive authentication for Node.js. A comprehensive set of strategies support authentication using a username and password, Facebook, Twitter, and more.
  • bell - Third-party authentication plugin for hapi. Ships with built-in support for various well-known sites and simple configuration object will support other OAuth 1.0a and OAuth 2.0 sites.
  • Stack Auth - Open-source authN & authZ for modern web apps, comes with pre-built components for Next.js.
  • client-certificate-auth - Mutual TLS (mTLS) client certificate authentication middleware for Node.js with reverse proxy support, composable verification callbacks, and X.509 certificate parsing.

Python

  • Keystone - Provides authentication, authorization and service discovery mechanisms via HTTP primarily for use by projects in the OpenStack family.
  • Authomatic - Simple yet powerful authorization & authentication client library for Python web applications.
  • Python Social Auth - Easy to setup social authentication/registration mechanism with support for several frameworks and auth providers.
  • Raider - Web authentication testing framework, which treats the authentication process as finite state machines.

Ruby

  • Authlogic - Clean, simple, and unobtrusive Ruby authentication solution.

Flutter

  • Authgear SDK for Flutter - With Authgear SDK for Flutter, you can easily integrate authentication features into your Flutter apps. In most cases, it involves just a few lines of code to enable multiple authentication methods.

Authorization

Android

  • AndPermission - Android runtime permission, support the right to apply for permission at any place.
  • Authgear SDK for Android - Android SDK to authenticate and authorize users based on the OAuth 2.0 authorization framework.

C#

  • Casbin.NET - Authorization library that supports access control models like ACL, RBAC, ABAC in .NET (C#).
  • Cerbos - Open-source authorization layer with a .NET SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Golang

  • Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Golang.
  • goRBAC - Lightweight role-based access control implementation in Go.
  • Ladon - SDK for access control policies: authorization for the microservice and IoT age.
  • OIDC - OpenID Connect Library (client and server) for Go
  • Ory Keto - Access control server capable of solving complex use cases (multi-tenant, attribute-based access control, etc.) with access control policies.
  • Oso - Batteries-included framework for building authorization in your Go application.
  • Topaz - Fine-grained authorization for cloud-native applications. Combining the best of OPA and Zanzibar
  • SpiceDB - Open-source implementation of the Zanzibar paper, a performant database for fine-grained permissions.
  • ZITADEL - Cloud-native Identity & Access Management platform for secure authentication, authorization and identity management.
  • Cerbos - Open-source authorization layer with a Go SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Rust

  • Casbin-Rs - Authorization library that supports access control models like ACL, RBAC, ABAC in Rust.
  • Oso - Batteries-included framework for building authorization in your Rust application.
  • Cerbos - Open-source authorization layer with a Rust SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

iOS

  • Permission - Unified API to ask for permissions on iOS.
  • Authgear SDK for iOS - With Authgear SDK for iOS, you can easily integrate authorization features into your iOS apps.

Java

  • jCasbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Java.
  • Apache Shiro - Powerful and easy-to-use Java security framework that performs authentication, authorization, cryptography, and session management.
  • pac4j - Security engine for Java (authentication, authorization, multi-frameworks): OAuth, CAS, SAML, OpenID Connect, LDAP, JWT.
  • AT&T XACML - XACML 3.0 implementation from AT&T.
  • TOTP Server-Side Library - TOTP server-side library.
  • Oso - Batteries-included framework for building authorization in your Java application.
  • Cerbos - Open-source authorization layer with a Java SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Node.js

  • Node-Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Node.js.
  • RBAC - Hierarchical role-based access control for Node.js.
  • ABAC - Attribute-based access control for Node.js.
  • accesscontrol - Role and attribute-based access control for Node.js.
  • Oso - Batteries-included framework for building authorization in your Node.js application.
  • Stack Auth - Open-source authN & authZ for modern web apps, comes with pre-built components for Next.js.
  • pundit-ts - Fully type-safe authorization library inspired by awesome pundit gem. Can be used for RBAC, ABAC access control models or any other model you wish.
  • Cerbos - Open-source authorization layer with a JavaScript/Node.js SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

PHP

  • PHP-Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in PHP.
  • PHP-RBAC - Authorization library for PHP which provides developers with NIST Level 2 hierarchical role-based access control.
  • ezRbac - Simple yet easy to implement role-based access control library for popular PHP framework: Codeigniter.
  • php-abac - Attribute-based access control library.
  • laravel-permission - Allows you to manage user permissions and roles in a database.
  • logical-permissions-php - This is a generic library that provides support for array-based permissions with logic gates such as AND and OR.
  • symfony-logical-authorization-bundle - This Symfony bundle provides a unifying solution for authorization that aims to be flexible, convenient and consistent.
  • Cerbos - Open-source authorization layer with a PHP SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Python

  • PyCasbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Python.
  • casbin-fastapi-decorator - Decorator-based authorization for FastAPI using PyCasbin, providing per-route permissions with no middleware and support for JWT, async SQLAlchemy, and Casdoor.
  • Flask-RBAC - Adds RBAC support to Flask.
  • Vakt - Attribute-based access control (ABAC) SDK for Python.
  • Oso - Batteries-included framework for building authorization in your Python application.
  • Cerbos - Open-source authorization layer with a Python SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Ruby

  • Oso - Batteries-included framework for building authorization in your Ruby application.
  • Pundit - Minimal authorization through OO design and pure Ruby classes.
  • Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Ruby.
  • CanCanCan - Authorization for Ruby on Rails.
  • Cerbos - Open-source authorization layer with a Ruby SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

AI Agent Auth

  • Arcade - Tool-calling platform with user approvals and authenticated actions for AI agents.
  • authsome - Local-first credential broker for AI agents with an encrypted local vault and HTTPS proxy injection; no hosted service required.
  • Composio - Hosted integration platform with managed OAuth and tool calling for 1000+ apps.
  • Nango - Open-source OAuth and API key handling for 700+ APIs with token refresh and a unified API for agent workloads.
  • Cerbos - Open-source, policy-based authorization for AI agents, agentic workflows, and MCP servers, with fine-grained access control and full decision logging at runtime.

Articles

Contribute

PR is welcomed.

License

This project is licensed under the CC0-1.0 license.

Releases

Packages

Used by

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

Awesome Authentication & Authorization & SSO & IAM Awesome

Quality Authentication & Authorization & SSO & IAM software and libraries.

Authentication (aka AuthN) and authorization (aka AuthZ) are both security measures. Authentication is the process of verifying who you are. Authorization is the process of verifying that you have access to something. Authorization occurs after successful authentication.

Contents

SSO (Single-Sign-On), IAM (Identity Access Management)

  • Casdoor - UI-first centralized authentication / Single-Sign-On (SSO) platform supporting OAuth 2.0 / OIDC and SAML.
  • Keycloak - Open Source Identity and Access Management.
  • Authelia - The Single Sign-On Multi-Factor portal for web apps.
  • ZITADEL - Cloud-native Identity & Access Management platform for secure authentication, authorization and identity management.
  • Authentik - authentik is an open-source Identity Provider that emphasizes flexibility and versatility. It can be seamlessly integrated into existing environments to support new protocols.
  • Stack Auth - Open-source, developer-friendly authentication, authorization, and IAM solution.
  • Scalekit – Add enterprise SSO (SAML, OIDC) and SCIM provisioning on top of existing auth systems alongside additive auth stack for MCP and Agent Auth.
  • Cloud-IAM - Managed Keycloak SaaS platform supporting OpenID Connect, OAuth 2.0 and SAML, with ISO 27001, SOC 2 Type 2, NIS 2, GDPR, HDS and SecNumCloud 3.2 certifications.
  • SSOJet – Add enterprise SSO (SAML, OIDC) and SCIM user provisioning to your app without changing your existing authentication system.
  • Logto - An IAM infrastructure with AuthN, AuthZ, MFA, SSO, user management, and multi-tenancy features, supporting OAuth 2.0, OIDC, and SAML.
  • Neon Auth - Managed authentication built on Better Auth that syncs users directly into your Neon Postgres database.
  • NanoIDP - Local development Identity Provider for testing OAuth2, OpenID Connect, and SAML flows without running a full IAM stack.

Authentication

C#

Golang

  • Casdoor - UI-first centralized authentication / Single-Sign-On (SSO) platform supporting OAuth 2.0 / OIDC and SAML.
  • OIDC - OpenID Connect Library (client and server) for Go
  • Ory Hydra - OpenID Connect certified OAuth2 server.
  • Ory Kratos - API-first Identity and User Management system built for cloud applications.
  • Ory Oathkeeper - Identity/Access proxy inspired by the BeyondCorp/Zero-Trust white paper.
  • Ory Fosite - Extensible OAuth 2.0 and OpenID Connect SDK for Golang.
  • ZITADEL - Cloud-native Identity & Access Management platform for secure authentication, authorization and identity management.

Java

  • Apache Shiro - Powerful and easy-to-use Java security framework that performs authentication, authorization, cryptography, and session management.
  • pac4j - Security engine for Java (authentication, authorization, multi frameworks): OAuth, CAS, SAML, OpenID Connect, LDAP, JWT.
  • Spring Security OAuth - Provides support for using Spring Security with OAuth (1a) and OAuth2.

Node.js

  • Passport - Simple, unobtrusive authentication for Node.js. A comprehensive set of strategies support authentication using a username and password, Facebook, Twitter, and more.
  • bell - Third-party authentication plugin for hapi. Ships with built-in support for various well-known sites and simple configuration object will support other OAuth 1.0a and OAuth 2.0 sites.
  • Stack Auth - Open-source authN & authZ for modern web apps, comes with pre-built components for Next.js.
  • client-certificate-auth - Mutual TLS (mTLS) client certificate authentication middleware for Node.js with reverse proxy support, composable verification callbacks, and X.509 certificate parsing.

Python

  • Keystone - Provides authentication, authorization and service discovery mechanisms via HTTP primarily for use by projects in the OpenStack family.
  • Authomatic - Simple yet powerful authorization & authentication client library for Python web applications.
  • Python Social Auth - Easy to setup social authentication/registration mechanism with support for several frameworks and auth providers.
  • Raider - Web authentication testing framework, which treats the authentication process as finite state machines.

Ruby

  • Authlogic - Clean, simple, and unobtrusive Ruby authentication solution.

Flutter

  • Authgear SDK for Flutter - With Authgear SDK for Flutter, you can easily integrate authentication features into your Flutter apps. In most cases, it involves just a few lines of code to enable multiple authentication methods.

Authorization

Android

  • AndPermission - Android runtime permission, support the right to apply for permission at any place.
  • Authgear SDK for Android - Android SDK to authenticate and authorize users based on the OAuth 2.0 authorization framework.

C#

  • Casbin.NET - Authorization library that supports access control models like ACL, RBAC, ABAC in .NET (C#).
  • Cerbos - Open-source authorization layer with a .NET SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Golang

  • Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Golang.
  • goRBAC - Lightweight role-based access control implementation in Go.
  • Ladon - SDK for access control policies: authorization for the microservice and IoT age.
  • OIDC - OpenID Connect Library (client and server) for Go
  • Ory Keto - Access control server capable of solving complex use cases (multi-tenant, attribute-based access control, etc.) with access control policies.
  • Oso - Batteries-included framework for building authorization in your Go application.
  • Topaz - Fine-grained authorization for cloud-native applications. Combining the best of OPA and Zanzibar
  • SpiceDB - Open-source implementation of the Zanzibar paper, a performant database for fine-grained permissions.
  • ZITADEL - Cloud-native Identity & Access Management platform for secure authentication, authorization and identity management.
  • Cerbos - Open-source authorization layer with a Go SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Rust

  • Casbin-Rs - Authorization library that supports access control models like ACL, RBAC, ABAC in Rust.
  • Oso - Batteries-included framework for building authorization in your Rust application.
  • Cerbos - Open-source authorization layer with a Rust SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

iOS

  • Permission - Unified API to ask for permissions on iOS.
  • Authgear SDK for iOS - With Authgear SDK for iOS, you can easily integrate authorization features into your iOS apps.

Java

  • jCasbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Java.
  • Apache Shiro - Powerful and easy-to-use Java security framework that performs authentication, authorization, cryptography, and session management.
  • pac4j - Security engine for Java (authentication, authorization, multi-frameworks): OAuth, CAS, SAML, OpenID Connect, LDAP, JWT.
  • AT&T XACML - XACML 3.0 implementation from AT&T.
  • TOTP Server-Side Library - TOTP server-side library.
  • Oso - Batteries-included framework for building authorization in your Java application.
  • Cerbos - Open-source authorization layer with a Java SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Node.js

  • Node-Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Node.js.
  • RBAC - Hierarchical role-based access control for Node.js.
  • ABAC - Attribute-based access control for Node.js.
  • accesscontrol - Role and attribute-based access control for Node.js.
  • Oso - Batteries-included framework for building authorization in your Node.js application.
  • Stack Auth - Open-source authN & authZ for modern web apps, comes with pre-built components for Next.js.
  • pundit-ts - Fully type-safe authorization library inspired by awesome pundit gem. Can be used for RBAC, ABAC access control models or any other model you wish.
  • Cerbos - Open-source authorization layer with a JavaScript/Node.js SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

PHP

  • PHP-Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in PHP.
  • PHP-RBAC - Authorization library for PHP which provides developers with NIST Level 2 hierarchical role-based access control.
  • ezRbac - Simple yet easy to implement role-based access control library for popular PHP framework: Codeigniter.
  • php-abac - Attribute-based access control library.
  • laravel-permission - Allows you to manage user permissions and roles in a database.
  • logical-permissions-php - This is a generic library that provides support for array-based permissions with logic gates such as AND and OR.
  • symfony-logical-authorization-bundle - This Symfony bundle provides a unifying solution for authorization that aims to be flexible, convenient and consistent.
  • Cerbos - Open-source authorization layer with a PHP SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Python

  • PyCasbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Python.
  • casbin-fastapi-decorator - Decorator-based authorization for FastAPI using PyCasbin, providing per-route permissions with no middleware and support for JWT, async SQLAlchemy, and Casdoor.
  • Flask-RBAC - Adds RBAC support to Flask.
  • Vakt - Attribute-based access control (ABAC) SDK for Python.
  • Oso - Batteries-included framework for building authorization in your Python application.
  • Cerbos - Open-source authorization layer with a Python SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Ruby

  • Oso - Batteries-included framework for building authorization in your Ruby application.
  • Pundit - Minimal authorization through OO design and pure Ruby classes.
  • Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Ruby.
  • CanCanCan - Authorization for Ruby on Rails.
  • Cerbos - Open-source authorization layer with a Ruby SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

AI Agent Auth

  • Arcade - Tool-calling platform with user approvals and authenticated actions for AI agents.
  • authsome - Local-first credential broker for AI agents with an encrypted local vault and HTTPS proxy injection; no hosted service required.
  • Composio - Hosted integration platform with managed OAuth and tool calling for 1000+ apps.
  • Nango - Open-source OAuth and API key handling for 700+ APIs with token refresh and a unified API for agent workloads.
  • Cerbos - Open-source, policy-based authorization for AI agents, agentic workflows, and MCP servers, with fine-grained access control and full decision logging at runtime.

Articles

Contribute

PR is welcomed.

License

This project is licensed under the CC0-1.0 license.

Releases

Packages

Used by

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Awesome Authentication & Authorization & SSO & IAM Awesome

Quality Authentication & Authorization & SSO & IAM software and libraries.

Authentication (aka AuthN) and authorization (aka AuthZ) are both security measures. Authentication is the process of verifying who you are. Authorization is the process of verifying that you have access to something. Authorization occurs after successful authentication.

Contents

SSO (Single-Sign-On), IAM (Identity Access Management)

  • Casdoor - UI-first centralized authentication / Single-Sign-On (SSO) platform supporting OAuth 2.0 / OIDC and SAML.
  • Keycloak - Open Source Identity and Access Management.
  • Authelia - The Single Sign-On Multi-Factor portal for web apps.
  • ZITADEL - Cloud-native Identity & Access Management platform for secure authentication, authorization and identity management.
  • Authentik - authentik is an open-source Identity Provider that emphasizes flexibility and versatility. It can be seamlessly integrated into existing environments to support new protocols.
  • Stack Auth - Open-source, developer-friendly authentication, authorization, and IAM solution.
  • Scalekit – Add enterprise SSO (SAML, OIDC) and SCIM provisioning on top of existing auth systems alongside additive auth stack for MCP and Agent Auth.
  • Cloud-IAM - Managed Keycloak SaaS platform supporting OpenID Connect, OAuth 2.0 and SAML, with ISO 27001, SOC 2 Type 2, NIS 2, GDPR, HDS and SecNumCloud 3.2 certifications.
  • SSOJet – Add enterprise SSO (SAML, OIDC) and SCIM user provisioning to your app without changing your existing authentication system.
  • Logto - An IAM infrastructure with AuthN, AuthZ, MFA, SSO, user management, and multi-tenancy features, supporting OAuth 2.0, OIDC, and SAML.
  • Neon Auth - Managed authentication built on Better Auth that syncs users directly into your Neon Postgres database.
  • NanoIDP - Local development Identity Provider for testing OAuth2, OpenID Connect, and SAML flows without running a full IAM stack.

Authentication

C#

Golang

  • Casdoor - UI-first centralized authentication / Single-Sign-On (SSO) platform supporting OAuth 2.0 / OIDC and SAML.
  • OIDC - OpenID Connect Library (client and server) for Go
  • Ory Hydra - OpenID Connect certified OAuth2 server.
  • Ory Kratos - API-first Identity and User Management system built for cloud applications.
  • Ory Oathkeeper - Identity/Access proxy inspired by the BeyondCorp/Zero-Trust white paper.
  • Ory Fosite - Extensible OAuth 2.0 and OpenID Connect SDK for Golang.
  • ZITADEL - Cloud-native Identity & Access Management platform for secure authentication, authorization and identity management.

Java

  • Apache Shiro - Powerful and easy-to-use Java security framework that performs authentication, authorization, cryptography, and session management.
  • pac4j - Security engine for Java (authentication, authorization, multi frameworks): OAuth, CAS, SAML, OpenID Connect, LDAP, JWT.
  • Spring Security OAuth - Provides support for using Spring Security with OAuth (1a) and OAuth2.

Node.js

  • Passport - Simple, unobtrusive authentication for Node.js. A comprehensive set of strategies support authentication using a username and password, Facebook, Twitter, and more.
  • bell - Third-party authentication plugin for hapi. Ships with built-in support for various well-known sites and simple configuration object will support other OAuth 1.0a and OAuth 2.0 sites.
  • Stack Auth - Open-source authN & authZ for modern web apps, comes with pre-built components for Next.js.
  • client-certificate-auth - Mutual TLS (mTLS) client certificate authentication middleware for Node.js with reverse proxy support, composable verification callbacks, and X.509 certificate parsing.

Python

  • Keystone - Provides authentication, authorization and service discovery mechanisms via HTTP primarily for use by projects in the OpenStack family.
  • Authomatic - Simple yet powerful authorization & authentication client library for Python web applications.
  • Python Social Auth - Easy to setup social authentication/registration mechanism with support for several frameworks and auth providers.
  • Raider - Web authentication testing framework, which treats the authentication process as finite state machines.

Ruby

  • Authlogic - Clean, simple, and unobtrusive Ruby authentication solution.

Flutter

  • Authgear SDK for Flutter - With Authgear SDK for Flutter, you can easily integrate authentication features into your Flutter apps. In most cases, it involves just a few lines of code to enable multiple authentication methods.

Authorization

Android

  • AndPermission - Android runtime permission, support the right to apply for permission at any place.
  • Authgear SDK for Android - Android SDK to authenticate and authorize users based on the OAuth 2.0 authorization framework.

C#

  • Casbin.NET - Authorization library that supports access control models like ACL, RBAC, ABAC in .NET (C#).
  • Cerbos - Open-source authorization layer with a .NET SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Golang

  • Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Golang.
  • goRBAC - Lightweight role-based access control implementation in Go.
  • Ladon - SDK for access control policies: authorization for the microservice and IoT age.
  • OIDC - OpenID Connect Library (client and server) for Go
  • Ory Keto - Access control server capable of solving complex use cases (multi-tenant, attribute-based access control, etc.) with access control policies.
  • Oso - Batteries-included framework for building authorization in your Go application.
  • Topaz - Fine-grained authorization for cloud-native applications. Combining the best of OPA and Zanzibar
  • SpiceDB - Open-source implementation of the Zanzibar paper, a performant database for fine-grained permissions.
  • ZITADEL - Cloud-native Identity & Access Management platform for secure authentication, authorization and identity management.
  • Cerbos - Open-source authorization layer with a Go SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Rust

  • Casbin-Rs - Authorization library that supports access control models like ACL, RBAC, ABAC in Rust.
  • Oso - Batteries-included framework for building authorization in your Rust application.
  • Cerbos - Open-source authorization layer with a Rust SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

iOS

  • Permission - Unified API to ask for permissions on iOS.
  • Authgear SDK for iOS - With Authgear SDK for iOS, you can easily integrate authorization features into your iOS apps.

Java

  • jCasbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Java.
  • Apache Shiro - Powerful and easy-to-use Java security framework that performs authentication, authorization, cryptography, and session management.
  • pac4j - Security engine for Java (authentication, authorization, multi-frameworks): OAuth, CAS, SAML, OpenID Connect, LDAP, JWT.
  • AT&T XACML - XACML 3.0 implementation from AT&T.
  • TOTP Server-Side Library - TOTP server-side library.
  • Oso - Batteries-included framework for building authorization in your Java application.
  • Cerbos - Open-source authorization layer with a Java SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Node.js

  • Node-Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Node.js.
  • RBAC - Hierarchical role-based access control for Node.js.
  • ABAC - Attribute-based access control for Node.js.
  • accesscontrol - Role and attribute-based access control for Node.js.
  • Oso - Batteries-included framework for building authorization in your Node.js application.
  • Stack Auth - Open-source authN & authZ for modern web apps, comes with pre-built components for Next.js.
  • pundit-ts - Fully type-safe authorization library inspired by awesome pundit gem. Can be used for RBAC, ABAC access control models or any other model you wish.
  • Cerbos - Open-source authorization layer with a JavaScript/Node.js SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

PHP

  • PHP-Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in PHP.
  • PHP-RBAC - Authorization library for PHP which provides developers with NIST Level 2 hierarchical role-based access control.
  • ezRbac - Simple yet easy to implement role-based access control library for popular PHP framework: Codeigniter.
  • php-abac - Attribute-based access control library.
  • laravel-permission - Allows you to manage user permissions and roles in a database.
  • logical-permissions-php - This is a generic library that provides support for array-based permissions with logic gates such as AND and OR.
  • symfony-logical-authorization-bundle - This Symfony bundle provides a unifying solution for authorization that aims to be flexible, convenient and consistent.
  • Cerbos - Open-source authorization layer with a PHP SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Python

  • PyCasbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Python.
  • casbin-fastapi-decorator - Decorator-based authorization for FastAPI using PyCasbin, providing per-route permissions with no middleware and support for JWT, async SQLAlchemy, and Casdoor.
  • Flask-RBAC - Adds RBAC support to Flask.
  • Vakt - Attribute-based access control (ABAC) SDK for Python.
  • Oso - Batteries-included framework for building authorization in your Python application.
  • Cerbos - Open-source authorization layer with a Python SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Ruby

  • Oso - Batteries-included framework for building authorization in your Ruby application.
  • Pundit - Minimal authorization through OO design and pure Ruby classes.
  • Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Ruby.
  • CanCanCan - Authorization for Ruby on Rails.
  • Cerbos - Open-source authorization layer with a Ruby SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

AI Agent Auth

  • Arcade - Tool-calling platform with user approvals and authenticated actions for AI agents.
  • authsome - Local-first credential broker for AI agents with an encrypted local vault and HTTPS proxy injection; no hosted service required.
  • Composio - Hosted integration platform with managed OAuth and tool calling for 1000+ apps.
  • Nango - Open-source OAuth and API key handling for 700+ APIs with token refresh and a unified API for agent workloads.
  • Cerbos - Open-source, policy-based authorization for AI agents, agentic workflows, and MCP servers, with fine-grained access control and full decision logging at runtime.

Articles

Contribute

PR is welcomed.

License

This project is licensed under the CC0-1.0 license.

Releases

Packages

Used by

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Awesome Authentication & Authorization & SSO & IAM Awesome

Quality Authentication & Authorization & SSO & IAM software and libraries.

Authentication (aka AuthN) and authorization (aka AuthZ) are both security measures. Authentication is the process of verifying who you are. Authorization is the process of verifying that you have access to something. Authorization occurs after successful authentication.

Contents

SSO (Single-Sign-On), IAM (Identity Access Management)

  • Casdoor - UI-first centralized authentication / Single-Sign-On (SSO) platform supporting OAuth 2.0 / OIDC and SAML.
  • Keycloak - Open Source Identity and Access Management.
  • Authelia - The Single Sign-On Multi-Factor portal for web apps.
  • ZITADEL - Cloud-native Identity & Access Management platform for secure authentication, authorization and identity management.
  • Authentik - authentik is an open-source Identity Provider that emphasizes flexibility and versatility. It can be seamlessly integrated into existing environments to support new protocols.
  • Stack Auth - Open-source, developer-friendly authentication, authorization, and IAM solution.
  • Scalekit – Add enterprise SSO (SAML, OIDC) and SCIM provisioning on top of existing auth systems alongside additive auth stack for MCP and Agent Auth.
  • Cloud-IAM - Managed Keycloak SaaS platform supporting OpenID Connect, OAuth 2.0 and SAML, with ISO 27001, SOC 2 Type 2, NIS 2, GDPR, HDS and SecNumCloud 3.2 certifications.
  • SSOJet – Add enterprise SSO (SAML, OIDC) and SCIM user provisioning to your app without changing your existing authentication system.
  • Logto - An IAM infrastructure with AuthN, AuthZ, MFA, SSO, user management, and multi-tenancy features, supporting OAuth 2.0, OIDC, and SAML.
  • Neon Auth - Managed authentication built on Better Auth that syncs users directly into your Neon Postgres database.
  • NanoIDP - Local development Identity Provider for testing OAuth2, OpenID Connect, and SAML flows without running a full IAM stack.

Authentication

C#

Golang

  • Casdoor - UI-first centralized authentication / Single-Sign-On (SSO) platform supporting OAuth 2.0 / OIDC and SAML.
  • OIDC - OpenID Connect Library (client and server) for Go
  • Ory Hydra - OpenID Connect certified OAuth2 server.
  • Ory Kratos - API-first Identity and User Management system built for cloud applications.
  • Ory Oathkeeper - Identity/Access proxy inspired by the BeyondCorp/Zero-Trust white paper.
  • Ory Fosite - Extensible OAuth 2.0 and OpenID Connect SDK for Golang.
  • ZITADEL - Cloud-native Identity & Access Management platform for secure authentication, authorization and identity management.

Java

  • Apache Shiro - Powerful and easy-to-use Java security framework that performs authentication, authorization, cryptography, and session management.
  • pac4j - Security engine for Java (authentication, authorization, multi frameworks): OAuth, CAS, SAML, OpenID Connect, LDAP, JWT.
  • Spring Security OAuth - Provides support for using Spring Security with OAuth (1a) and OAuth2.

Node.js

  • Passport - Simple, unobtrusive authentication for Node.js. A comprehensive set of strategies support authentication using a username and password, Facebook, Twitter, and more.
  • bell - Third-party authentication plugin for hapi. Ships with built-in support for various well-known sites and simple configuration object will support other OAuth 1.0a and OAuth 2.0 sites.
  • Stack Auth - Open-source authN & authZ for modern web apps, comes with pre-built components for Next.js.
  • client-certificate-auth - Mutual TLS (mTLS) client certificate authentication middleware for Node.js with reverse proxy support, composable verification callbacks, and X.509 certificate parsing.

Python

  • Keystone - Provides authentication, authorization and service discovery mechanisms via HTTP primarily for use by projects in the OpenStack family.
  • Authomatic - Simple yet powerful authorization & authentication client library for Python web applications.
  • Python Social Auth - Easy to setup social authentication/registration mechanism with support for several frameworks and auth providers.
  • Raider - Web authentication testing framework, which treats the authentication process as finite state machines.

Ruby

  • Authlogic - Clean, simple, and unobtrusive Ruby authentication solution.

Flutter

  • Authgear SDK for Flutter - With Authgear SDK for Flutter, you can easily integrate authentication features into your Flutter apps. In most cases, it involves just a few lines of code to enable multiple authentication methods.

Authorization

Android

  • AndPermission - Android runtime permission, support the right to apply for permission at any place.
  • Authgear SDK for Android - Android SDK to authenticate and authorize users based on the OAuth 2.0 authorization framework.

C#

  • Casbin.NET - Authorization library that supports access control models like ACL, RBAC, ABAC in .NET (C#).
  • Cerbos - Open-source authorization layer with a .NET SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Golang

  • Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Golang.
  • goRBAC - Lightweight role-based access control implementation in Go.
  • Ladon - SDK for access control policies: authorization for the microservice and IoT age.
  • OIDC - OpenID Connect Library (client and server) for Go
  • Ory Keto - Access control server capable of solving complex use cases (multi-tenant, attribute-based access control, etc.) with access control policies.
  • Oso - Batteries-included framework for building authorization in your Go application.
  • Topaz - Fine-grained authorization for cloud-native applications. Combining the best of OPA and Zanzibar
  • SpiceDB - Open-source implementation of the Zanzibar paper, a performant database for fine-grained permissions.
  • ZITADEL - Cloud-native Identity & Access Management platform for secure authentication, authorization and identity management.
  • Cerbos - Open-source authorization layer with a Go SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Rust

  • Casbin-Rs - Authorization library that supports access control models like ACL, RBAC, ABAC in Rust.
  • Oso - Batteries-included framework for building authorization in your Rust application.
  • Cerbos - Open-source authorization layer with a Rust SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

iOS

  • Permission - Unified API to ask for permissions on iOS.
  • Authgear SDK for iOS - With Authgear SDK for iOS, you can easily integrate authorization features into your iOS apps.

Java

  • jCasbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Java.
  • Apache Shiro - Powerful and easy-to-use Java security framework that performs authentication, authorization, cryptography, and session management.
  • pac4j - Security engine for Java (authentication, authorization, multi-frameworks): OAuth, CAS, SAML, OpenID Connect, LDAP, JWT.
  • AT&T XACML - XACML 3.0 implementation from AT&T.
  • TOTP Server-Side Library - TOTP server-side library.
  • Oso - Batteries-included framework for building authorization in your Java application.
  • Cerbos - Open-source authorization layer with a Java SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Node.js

  • Node-Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Node.js.
  • RBAC - Hierarchical role-based access control for Node.js.
  • ABAC - Attribute-based access control for Node.js.
  • accesscontrol - Role and attribute-based access control for Node.js.
  • Oso - Batteries-included framework for building authorization in your Node.js application.
  • Stack Auth - Open-source authN & authZ for modern web apps, comes with pre-built components for Next.js.
  • pundit-ts - Fully type-safe authorization library inspired by awesome pundit gem. Can be used for RBAC, ABAC access control models or any other model you wish.
  • Cerbos - Open-source authorization layer with a JavaScript/Node.js SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

PHP

  • PHP-Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in PHP.
  • PHP-RBAC - Authorization library for PHP which provides developers with NIST Level 2 hierarchical role-based access control.
  • ezRbac - Simple yet easy to implement role-based access control library for popular PHP framework: Codeigniter.
  • php-abac - Attribute-based access control library.
  • laravel-permission - Allows you to manage user permissions and roles in a database.
  • logical-permissions-php - This is a generic library that provides support for array-based permissions with logic gates such as AND and OR.
  • symfony-logical-authorization-bundle - This Symfony bundle provides a unifying solution for authorization that aims to be flexible, convenient and consistent.
  • Cerbos - Open-source authorization layer with a PHP SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Python

  • PyCasbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Python.
  • casbin-fastapi-decorator - Decorator-based authorization for FastAPI using PyCasbin, providing per-route permissions with no middleware and support for JWT, async SQLAlchemy, and Casdoor.
  • Flask-RBAC - Adds RBAC support to Flask.
  • Vakt - Attribute-based access control (ABAC) SDK for Python.
  • Oso - Batteries-included framework for building authorization in your Python application.
  • Cerbos - Open-source authorization layer with a Python SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Ruby

  • Oso - Batteries-included framework for building authorization in your Ruby application.
  • Pundit - Minimal authorization through OO design and pure Ruby classes.
  • Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Ruby.
  • CanCanCan - Authorization for Ruby on Rails.
  • Cerbos - Open-source authorization layer with a Ruby SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

AI Agent Auth

  • Arcade - Tool-calling platform with user approvals and authenticated actions for AI agents.
  • authsome - Local-first credential broker for AI agents with an encrypted local vault and HTTPS proxy injection; no hosted service required.
  • Composio - Hosted integration platform with managed OAuth and tool calling for 1000+ apps.
  • Nango - Open-source OAuth and API key handling for 700+ APIs with token refresh and a unified API for agent workloads.
  • Cerbos - Open-source, policy-based authorization for AI agents, agentic workflows, and MCP servers, with fine-grained access control and full decision logging at runtime.

Articles

Contribute

PR is welcomed.

License

This project is licensed under the CC0-1.0 license.

Releases

Packages

Used by

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

Awesome Authentication & Authorization & SSO & IAM Awesome

Quality Authentication & Authorization & SSO & IAM software and libraries.

Authentication (aka AuthN) and authorization (aka AuthZ) are both security measures. Authentication is the process of verifying who you are. Authorization is the process of verifying that you have access to something. Authorization occurs after successful authentication.

Contents

SSO (Single-Sign-On), IAM (Identity Access Management)

  • Casdoor - UI-first centralized authentication / Single-Sign-On (SSO) platform supporting OAuth 2.0 / OIDC and SAML.
  • Keycloak - Open Source Identity and Access Management.
  • Authelia - The Single Sign-On Multi-Factor portal for web apps.
  • ZITADEL - Cloud-native Identity & Access Management platform for secure authentication, authorization and identity management.
  • Authentik - authentik is an open-source Identity Provider that emphasizes flexibility and versatility. It can be seamlessly integrated into existing environments to support new protocols.
  • Stack Auth - Open-source, developer-friendly authentication, authorization, and IAM solution.
  • Scalekit – Add enterprise SSO (SAML, OIDC) and SCIM provisioning on top of existing auth systems alongside additive auth stack for MCP and Agent Auth.
  • Cloud-IAM - Managed Keycloak SaaS platform supporting OpenID Connect, OAuth 2.0 and SAML, with ISO 27001, SOC 2 Type 2, NIS 2, GDPR, HDS and SecNumCloud 3.2 certifications.
  • SSOJet – Add enterprise SSO (SAML, OIDC) and SCIM user provisioning to your app without changing your existing authentication system.
  • Logto - An IAM infrastructure with AuthN, AuthZ, MFA, SSO, user management, and multi-tenancy features, supporting OAuth 2.0, OIDC, and SAML.
  • Neon Auth - Managed authentication built on Better Auth that syncs users directly into your Neon Postgres database.
  • NanoIDP - Local development Identity Provider for testing OAuth2, OpenID Connect, and SAML flows without running a full IAM stack.

Authentication

C#

Golang

  • Casdoor - UI-first centralized authentication / Single-Sign-On (SSO) platform supporting OAuth 2.0 / OIDC and SAML.
  • OIDC - OpenID Connect Library (client and server) for Go
  • Ory Hydra - OpenID Connect certified OAuth2 server.
  • Ory Kratos - API-first Identity and User Management system built for cloud applications.
  • Ory Oathkeeper - Identity/Access proxy inspired by the BeyondCorp/Zero-Trust white paper.
  • Ory Fosite - Extensible OAuth 2.0 and OpenID Connect SDK for Golang.
  • ZITADEL - Cloud-native Identity & Access Management platform for secure authentication, authorization and identity management.

Java

  • Apache Shiro - Powerful and easy-to-use Java security framework that performs authentication, authorization, cryptography, and session management.
  • pac4j - Security engine for Java (authentication, authorization, multi frameworks): OAuth, CAS, SAML, OpenID Connect, LDAP, JWT.
  • Spring Security OAuth - Provides support for using Spring Security with OAuth (1a) and OAuth2.

Node.js

  • Passport - Simple, unobtrusive authentication for Node.js. A comprehensive set of strategies support authentication using a username and password, Facebook, Twitter, and more.
  • bell - Third-party authentication plugin for hapi. Ships with built-in support for various well-known sites and simple configuration object will support other OAuth 1.0a and OAuth 2.0 sites.
  • Stack Auth - Open-source authN & authZ for modern web apps, comes with pre-built components for Next.js.
  • client-certificate-auth - Mutual TLS (mTLS) client certificate authentication middleware for Node.js with reverse proxy support, composable verification callbacks, and X.509 certificate parsing.

Python

  • Keystone - Provides authentication, authorization and service discovery mechanisms via HTTP primarily for use by projects in the OpenStack family.
  • Authomatic - Simple yet powerful authorization & authentication client library for Python web applications.
  • Python Social Auth - Easy to setup social authentication/registration mechanism with support for several frameworks and auth providers.
  • Raider - Web authentication testing framework, which treats the authentication process as finite state machines.

Ruby

  • Authlogic - Clean, simple, and unobtrusive Ruby authentication solution.

Flutter

  • Authgear SDK for Flutter - With Authgear SDK for Flutter, you can easily integrate authentication features into your Flutter apps. In most cases, it involves just a few lines of code to enable multiple authentication methods.

Authorization

Android

  • AndPermission - Android runtime permission, support the right to apply for permission at any place.
  • Authgear SDK for Android - Android SDK to authenticate and authorize users based on the OAuth 2.0 authorization framework.

C#

  • Casbin.NET - Authorization library that supports access control models like ACL, RBAC, ABAC in .NET (C#).
  • Cerbos - Open-source authorization layer with a .NET SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Golang

  • Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Golang.
  • goRBAC - Lightweight role-based access control implementation in Go.
  • Ladon - SDK for access control policies: authorization for the microservice and IoT age.
  • OIDC - OpenID Connect Library (client and server) for Go
  • Ory Keto - Access control server capable of solving complex use cases (multi-tenant, attribute-based access control, etc.) with access control policies.
  • Oso - Batteries-included framework for building authorization in your Go application.
  • Topaz - Fine-grained authorization for cloud-native applications. Combining the best of OPA and Zanzibar
  • SpiceDB - Open-source implementation of the Zanzibar paper, a performant database for fine-grained permissions.
  • ZITADEL - Cloud-native Identity & Access Management platform for secure authentication, authorization and identity management.
  • Cerbos - Open-source authorization layer with a Go SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Rust

  • Casbin-Rs - Authorization library that supports access control models like ACL, RBAC, ABAC in Rust.
  • Oso - Batteries-included framework for building authorization in your Rust application.
  • Cerbos - Open-source authorization layer with a Rust SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

iOS

  • Permission - Unified API to ask for permissions on iOS.
  • Authgear SDK for iOS - With Authgear SDK for iOS, you can easily integrate authorization features into your iOS apps.

Java

  • jCasbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Java.
  • Apache Shiro - Powerful and easy-to-use Java security framework that performs authentication, authorization, cryptography, and session management.
  • pac4j - Security engine for Java (authentication, authorization, multi-frameworks): OAuth, CAS, SAML, OpenID Connect, LDAP, JWT.
  • AT&T XACML - XACML 3.0 implementation from AT&T.
  • TOTP Server-Side Library - TOTP server-side library.
  • Oso - Batteries-included framework for building authorization in your Java application.
  • Cerbos - Open-source authorization layer with a Java SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Node.js

  • Node-Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Node.js.
  • RBAC - Hierarchical role-based access control for Node.js.
  • ABAC - Attribute-based access control for Node.js.
  • accesscontrol - Role and attribute-based access control for Node.js.
  • Oso - Batteries-included framework for building authorization in your Node.js application.
  • Stack Auth - Open-source authN & authZ for modern web apps, comes with pre-built components for Next.js.
  • pundit-ts - Fully type-safe authorization library inspired by awesome pundit gem. Can be used for RBAC, ABAC access control models or any other model you wish.
  • Cerbos - Open-source authorization layer with a JavaScript/Node.js SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

PHP

  • PHP-Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in PHP.
  • PHP-RBAC - Authorization library for PHP which provides developers with NIST Level 2 hierarchical role-based access control.
  • ezRbac - Simple yet easy to implement role-based access control library for popular PHP framework: Codeigniter.
  • php-abac - Attribute-based access control library.
  • laravel-permission - Allows you to manage user permissions and roles in a database.
  • logical-permissions-php - This is a generic library that provides support for array-based permissions with logic gates such as AND and OR.
  • symfony-logical-authorization-bundle - This Symfony bundle provides a unifying solution for authorization that aims to be flexible, convenient and consistent.
  • Cerbos - Open-source authorization layer with a PHP SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Python

  • PyCasbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Python.
  • casbin-fastapi-decorator - Decorator-based authorization for FastAPI using PyCasbin, providing per-route permissions with no middleware and support for JWT, async SQLAlchemy, and Casdoor.
  • Flask-RBAC - Adds RBAC support to Flask.
  • Vakt - Attribute-based access control (ABAC) SDK for Python.
  • Oso - Batteries-included framework for building authorization in your Python application.
  • Cerbos - Open-source authorization layer with a Python SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

Ruby

  • Oso - Batteries-included framework for building authorization in your Ruby application.
  • Pundit - Minimal authorization through OO design and pure Ruby classes.
  • Casbin - Authorization library that supports access control models like ACL, RBAC, ABAC in Ruby.
  • CanCanCan - Authorization for Ruby on Rails.
  • Cerbos - Open-source authorization layer with a Ruby SDK for RBAC, ABAC, and PBAC policies evaluated at runtime.

AI Agent Auth

  • Arcade - Tool-calling platform with user approvals and authenticated actions for AI agents.
  • authsome - Local-first credential broker for AI agents with an encrypted local vault and HTTPS proxy injection; no hosted service required.
  • Composio - Hosted integration platform with managed OAuth and tool calling for 1000+ apps.
  • Nango - Open-source OAuth and API key handling for 700+ APIs with token refresh and a unified API for agent workloads.
  • Cerbos - Open-source, policy-based authorization for AI agents, agentic workflows, and MCP servers, with fine-grained access control and full decision logging at runtime.

Articles

Contribute

PR is welcomed.

License

This project is licensed under the CC0-1.0 license.

Releases

Packages

Used by

Contributors