Ross ROSS = Recommend OSS · open-source software intelligence for agents

pocket-id/pocket-id

The most user-friendly OpenID Connect Certified™ and OAuth 2.0 provider that lets users sign in to your applications with passkeys. observed · 2026-08-28

github.com/pocket-id/pocket-id · homepage · Go · BSD-2-Clause (permissive) observed · 2026-08-28

Health v2 · maintenance only

85/100

  • Activity 99
  • Release rhythm 86
  • Longevity 53
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 2
  • age_days: 752
  • days_rel: 15
  • days_push: 7
  • n_releases_24m: 122

Full methodology

Adoption not part of the score

9029 stars · 304 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Pocket ID is a self-hosted, OpenID Connect Certified identity provider that lets users sign in to applications using passkeys instead of passwords. It is designed to be a lightweight, simple alternative to complex providers like Keycloak or ORY Hydra for homelab and small-scale SSO use cases.

Use cases

  • add passkey-based single sign-on to my self-hosted apps
  • self-host a simple OIDC provider instead of Keycloak
  • sign in to homelab services with a Yubikey
  • add OAuth2 login to my web application
  • centralize authentication for docker services behind a reverse proxy
  • issue access tokens with scoped permissions for my API
  • protect an MCP server with OIDC authentication

When to choose

  • you want passwordless passkey-only authentication for self-hosted services
  • you find Keycloak or ORY Hydra too complex for your needs
  • you run a homelab or small deployment needing lightweight SSO
  • you want an OpenID Connect Certified provider with minimal resource usage

When to avoid

  • you need password-based or multi-method authentication (it is passkey-only)
  • you need enterprise features like complex federation, SAML, or extensive user federation beyond LDAP/SCIM
  • your users cannot use passkeys or hardware security keys

Facets

application · maturity active

auth authorization http-server security security self-hosted web-development backend self-hosted go oidc-provider oauth2 passkeys identity-provider sso passwordless webauthn single-sign-on docker linux web-server

7 sources

Member repositories

RepositoryRoleHealth v2
pocket-id/pocket-idmain85

For agents

markdown · JSON · MCP: product_card(name="pocket-id/pocket-id")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem