Skip to content

rauthy

Secrets & Credentials

A lightweight, secure Identity Provider supporting OpenID Connect, OAuth 2, PAM, with strong passkey focus and optional HA deployment

Rust Latest v0.35.2 · 15d ago Security brief →

Features

  • Supports OpenID Connect, OAuth 2 and PAM for Single Sign‑On
  • Emphasizes passkey (FIDO 2/WebAuthn) login with passwordless or MFA options
  • Runs on virtually any hardware; default embeds Hiqlite DB (no external DB required) or can use Postgres
  • High‑availability mode via Hiqlite’s built‑in HA cache and persistence
  • Admin UI for full management plus per‑user account dashboard

Recent releases

View all 7 releases →
Upgrade now
v0.35.2 Mixed
Dependencies

preferred_username, MCP AS, device_code nonce, UI client ID

v0.35.1 New feature
Notable features
  • Postgres Unix Domain Socket connections with custom root CA and TLS mode configuration
  • Russian (ru) and French (fr) i18n translations
  • Optional redirect from /auth/v1/ to /auth/v1/account
v0.35.0 Breaking risk
Breaking changes
  • issuer URL format change from /auth/v1 to /auth/v1/
  • custom attribute value types changed from strings to typed JSON
Notable features
  • global KV store for policies and metadata
v0.34.3 New feature
Notable features
  • OpenContainer labels
  • Register With auth provider buttons
  • user value revalidation during login
v0.34.2 New feature
Notable features
  • ToS template creation from existing ToS
  • markdown rendering for ToS
  • content negotiation for /auth/v1/tos/latest

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
1,162
Forks
105
Languages
Rust Svelte TypeScript

Alternative to

Keycloak

Beta — feedback welcome: [email protected]