Ross ROSS = Recommend OSS · open-source software intelligence for agents

logto-io/logto

🧑‍🚀 Authentication and authorization infrastructure for SaaS and AI apps, built on OIDC and OAuth 2.1 with multi-tenancy, SSO, and RBAC. observed · 2026-08-28

github.com/logto-io/logto · homepage · TypeScript · MPL-2.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

98/100

  • Activity 99
  • Release rhythm 95
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 29.0
  • age_days: 1901
  • days_rel: 34
  • days_push: 7
  • n_releases_24m: 27

Full methodology

Adoption not part of the score

14468 stars · 1184 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Logto is an open-source identity and access management (IAM) infrastructure for SaaS and AI applications, built on OIDC, OAuth 2.1, and SAML. It provides multi-tenancy, enterprise SSO, RBAC, MFA, and pre-built sign-in flows with SDKs for 30+ frameworks, deployable self-hosted or via Logto Cloud.

Use cases

  • add authentication to my SaaS app without building it from scratch
  • implement enterprise SSO with SAML for B2B customers
  • set up role-based access control and multi-tenancy for a multi-tenant product
  • add social login and passwordless sign-in with email or SMS codes
  • secure an AI agent or MCP-based application with OAuth 2.1
  • self-host an OIDC identity provider on my own infrastructure
  • add MFA and passkey support to my existing login flow

When to choose

  • you need a complete, production-ready auth solution with OIDC/OAuth 2.1/SAML support out of the box
  • you want multi-tenancy, organizations, and enterprise SSO without custom workarounds
  • you are building SaaS, AI agents, or MCP-based apps and need token-based auth infrastructure
  • you prefer a self-hosted option with a web console, management API, and SDKs for many frameworks
  • you want pre-built, customizable sign-in UIs with social, passwordless, passkey, and MFA flows

When to avoid

  • you only need a lightweight library to validate JWTs inside a single monolithic app
  • you want a fully managed service and prefer not to run any infrastructure yourself (though Logto Cloud exists)
  • your project requires a protocol other than OIDC, OAuth 2.1, or SAML
  • you need a minimal embedded auth component rather than a standalone identity service

Facets

service · maturity active

auth authorization http-server api-framework middleware self-hosted sdk webhook logging security security web-development backend developer-tools artificial-intelligence large-language-models self-hosted apis self-hosted cloud cross-platform oidc oauth2 saml sso rbac multi-tenancy mfa passkey passwordless social-login jwt identity-management mcp ai-agents saas enterprise-sso totp magic-link user-management audit-logs nodejs typescript docker web-server

6 sources

Member repositories

RepositoryRoleHealth v2
logto-io/logtomain98

For agents

markdown · JSON · MCP: product_card(name="logto-io/logto")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem