# logto-io/logto

🧑‍🚀 Authentication and authorization infrastructure for SaaS and AI apps, built on OIDC and OAuth 2.1 with multi-tenancy, SSO, and RBAC.

Repository: https://github.com/logto-io/logto
Canonical: https://ross.abutalabs.com/products/logto
Homepage: https://logto.io
Language: TypeScript
License: MPL-2.0
License Family: copyleft
Topics: authentication, authorization, identity, openid-connect, passwordless, social-login, oauth2, typescript, email, sms, jwt, login, mfa, password, rbac, signup, sso, totp, logto, saml
Last push: 2026-08-27T00:18:22+00:00

## Health v2 (maintenance only)
Score: 98/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 95, longevity 100
- inputs: {"age_days": 1901, "days_push": 7, "days_rel": 34, "gap_med": 29.0, "n_releases_24m": 27}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 14468, forks 1184 (observed 2026-08-28T04:11:07.089141+00:00)

## What it is
Logto is an open-source identity and access management (IAM) infrastructure for SaaS and AI applications, built on OIDC, OAuth 2.1, and SAML. It provides multi-tenancy, enterprise SSO, RBAC, MFA, and pre-built sign-in flows with SDKs for 30+ frameworks, deployable self-hosted or via Logto Cloud.

## Use cases
- add authentication to my SaaS app without building it from scratch
- implement enterprise SSO with SAML for B2B customers
- set up role-based access control and multi-tenancy for a multi-tenant product
- add social login and passwordless sign-in with email or SMS codes
- secure an AI agent or MCP-based application with OAuth 2.1
- self-host an OIDC identity provider on my own infrastructure
- add MFA and passkey support to my existing login flow

## When to choose
- you need a complete, production-ready auth solution with OIDC/OAuth 2.1/SAML support out of the box
- you want multi-tenancy, organizations, and enterprise SSO without custom workarounds
- you are building SaaS, AI agents, or MCP-based apps and need token-based auth infrastructure
- you prefer a self-hosted option with a web console, management API, and SDKs for many frameworks
- you want pre-built, customizable sign-in UIs with social, passwordless, passkey, and MFA flows

## When to avoid
- you only need a lightweight library to validate JWTs inside a single monolithic app
- you want a fully managed service and prefer not to run any infrastructure yourself (though Logto Cloud exists)
- your project requires a protocol other than OIDC, OAuth 2.1, or SAML
- you need a minimal embedded auth component rather than a standalone identity service

## Facets
- artifact type: service
- maturity: active
- function: auth, authorization, http-server, api-framework, middleware, self-hosted, sdk, webhook, logging, security
- domain: security, web-development, backend, developer-tools, artificial-intelligence, large-language-models, self-hosted, apis
- platform: self-hosted, cloud, cross-platform
- tags: oidc, oauth2, saml, sso, rbac, multi-tenancy, mfa, passkey, passwordless, social-login, jwt, identity-management, mcp, ai-agents, saas, enterprise-sso, totp, magic-link, user-management, audit-logs, nodejs, typescript, docker, web-server

## Member repositories
- logto-io/logto (main) score 98

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:11:07.089141+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:12:32.328889+00:00, confidence not recorded.
  - readme: https://github.com/logto-io/logto (fetched 2026-08-28T04:11:07.089141+00:00, sha 5d4422b3eabc)
  - homepage: https://logto.io (fetched 2026-08-29T08:06:16.499052+00:00, sha f7cab94b81ac)
  - site_page: https://docs.logto.io/introduction (fetched 2026-08-29T08:06:16.510491+00:00, sha eae4d086531c)
  - site_page: https://logto.io/about (fetched 2026-08-29T08:06:16.514102+00:00, sha f32376ca117b)
  - site_page: https://logto.io/pricing (fetched 2026-08-29T08:06:16.508297+00:00, sha 699fdbae668a)
  - site_page: https://blog.logto.io/categories/changelogs (fetched 2026-08-29T08:06:16.512275+00:00, sha 5756fc3fe535)
- Data as of 2026-08-30T08:39:29.467469+00:00.
