Logto

Overview

Logto is an open-source authentication and authorization infrastructure designed for modern SaaS and AI applications, built on OpenID Connect (OIDC) and OAuth 2.1 standards. It provides a complete identity solution with sign-in/up experiences, user management, multi-tenancy, single sign-on (SSO), and role-based access control (RBAC) — all accessible through simple SDKs and APIs. Logto aims to be the drop-in replacement for commercial auth services like Auth0 and Clerk for developers who want to self-host.

With its MIT-licensed core, Logto ships with a developer-friendly console, pre-built UI components, and SDKs for React, Vue, Angular, iOS, Android, and Flutter. It handles the entire user identity lifecycle from registration through to role management, with built-in support for email/password, passwordless sign-in, social login, and enterprise SSO via SAML 2.0. Its multi-tenancy architecture makes it particularly well-suited for B2B SaaS platforms needing organization-level isolation.

Key Features

  • OIDC & OAuth 2.1: Built on modern authentication standards with support for PKCE, JWT, and all OAuth 2.1 grant types.
  • User-Friendly Console: Web-based admin interface for managing users, roles, applications, and authentication experiences.
  • Multi-Tenancy: Native organizational structure with isolated user directories, roles, and SSO configurations per tenant.
  • Enterprise SSO: SAML 2.0, OIDC, and social login providers for enterprise identity federation.
  • Role-Based Access Control: Built-in RBAC with roles, permissions, and resource-level access management.
  • Passwordless Authentication: Magic link email, verification code SMS, and social login — no password required.
  • Pre-Built UI Components: Customizable sign-in and sign-up experiences with mobile-responsive design and multi-language support.
  • Developer SDKs: Native SDKs for React, Vue, Angular, Next.js, iOS, Android, Flutter, and Node.js backends.

Use Cases

  • Adding authentication to new SaaS applications with minimal development overhead.
  • B2B multi-tenant platforms requiring per-organization user directories and SSO.
  • Building AI applications needing JWT-based auth with standard OIDC integration.
  • Self-hosting an Auth0/Clerk alternative with complete control over user data.

Platforms

Linux, Docker, Kubernetes (Node.js-based, runs anywhere with Docker)

Licence

MPL-2.0 (open source)

Website

logto.io | github.com/logto-io/logto

Sign In

Register

Reset Password

Please enter your username or email address, you will receive a link to create a new password via email.