Ross ROSS = Recommend OSS · open-source software intelligence for agents

authgear/authgear-server

Open source Auth0/Clerk/Firebase alternative. Passkeys, SSO, MFA, passwordless, biometric login. Self-hosted or cloud. Enterprise-ready for SaaS & mobile apps observed · 2026-08-28

github.com/authgear/authgear-server · homepage · Go · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

95/100

  • Activity 99
  • Release rhythm 87
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 32
  • age_days: 2269
  • days_rel: 7
  • days_push: 7
  • n_releases_24m: 24

Full methodology

Adoption not part of the score

2010 stars · 125 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Authgear is an open-source customer identity and access management (CIAM) platform serving as a self-hostable alternative to Auth0, Clerk, and Firebase Auth. It provides pre-built login and account settings pages, passkeys, passwordless OTP/magic links, biometric login, MFA, SSO via OIDC/OAuth 2.0/SAML, RBAC, and attack protection features like bot detection and rate limiting.

Use cases

  • self-host an auth0 alternative for my saas app
  • add passkey and passwordless login to a mobile app
  • implement sso with oidc for multiple web apps
  • add mfa and 2fa to user sign-in
  • replace firebase auth with a self-hosted identity provider
  • add social login with google apple and github
  • protect login flows from bots and brute-force attacks
  • manage user roles and rbac for a b2b saas

When to choose

  • you need consumer-facing authentication (CIAM) with pre-built, brandable login UI
  • you want modern login methods like passkeys, biometrics, and WhatsApp/SMS OTP out of the box
  • you need an open-source, self-hostable alternative to Auth0, Clerk, or Firebase Auth
  • you need enterprise protocols like OIDC, OAuth 2.0, SAML, LDAP, or ADFS federation
  • you want built-in attack protection: bot detection, rate limits, breached password checks, SMS pumping defense

When to avoid

  • you only need simple internal workforce SSO with no consumer identity features
  • you want a lightweight embeddable auth library rather than a full identity server to operate
  • your stack requires a solution in a language other than Go or without a hosted option
  • you need deep customization beyond the portal, admin API, hooks, and custom auth flows

Facets

service · maturity active

auth authorization security api-framework self-hosted security web-development developer-tools apis privacy self-hosted go cloud cross-platform identity-provider oauth2 oidc sso passkeys webauthn mfa passwordless ciam auth0-alternative clerk-alternative firebase-auth-alternative biometric-login saml rbac audit-logs brute-force-protection bot-detection social-login admin-api docker web-server

10 sources

Member repositories

RepositoryRoleHealth v2
authgear/authgear-servermain95

For agents

markdown · JSON · MCP: product_card(name="authgear/authgear-server")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem