Ross ROSS = Recommend OSS · open-source software intelligence for agents

sebadob/rauthy

Single Sign-On Identity & Access Management via OpenID Connect, OAuth 2, PAM observed · 2026-08-28

github.com/sebadob/rauthy · homepage · Rust · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

95/100

  • Activity 99
  • Release rhythm 96
  • Longevity 82
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 9.0
  • age_days: 1159
  • days_rel: 25
  • days_push: 7
  • n_releases_24m: 45

Full methodology

Adoption not part of the score

1291 stars · 125 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Rauthy is a lightweight, Rust-based Identity Provider offering Single Sign-On via OpenID Connect, OAuth 2, and PAM, with strong emphasis on Passkeys/WebAuthn and secure defaults. It runs standalone on Hiqlite (or Postgres), supports high availability, and includes an admin UI, events, and auditing.

Use cases

  • self-host an OpenID Connect identity provider
  • add single sign-on to multiple applications
  • replace Keycloak with a lightweight alternative
  • enable passwordless login with passkeys and WebAuthn
  • add MFA to user authentication
  • issue JWTs for IoT devices and CLI tools
  • manage users and clients with SCIM provisioning

When to choose

  • you want a simple, memory-efficient SSO provider with secure defaults
  • you need passkey-first or passwordless authentication
  • you want high availability without an external database dependency
  • you need OIDC/OAuth2 for web apps, IoT, or headless CLI tools

When to avoid

  • you need deep ecosystem integrations or plugins available in mature IdPs like Keycloak
  • your clients don't support modern token signing or PKCE and you want strict modern defaults
  • you require LDAP as a primary user store

Facets

application · maturity active

auth authorization security http-server self-hosted security self-hosted backend developer-tools apis windows self-hosted rust openid-connect oauth2 sso identity-provider passkeys webauthn fido2 mfa jwt scim pam keycloak-alternative iam linux macos docker web-server

2 sources

Member repositories

RepositoryRoleHealth v2
sebadob/rauthymain95

For agents

markdown · JSON · MCP: product_card(name="sebadob/rauthy")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem