Logto
Overview
Logto is an open-source authentication and authorization infrastructure designed for modern SaaS and AI applications, built on OpenID Connect (OIDC) and OAuth 2.1 standards. It provides a complete identity solution with sign-in/up experiences, user management, multi-tenancy, single sign-on (SSO), and role-based access control (RBAC) — all accessible through simple SDKs and APIs. Logto aims to be the drop-in replacement for commercial auth services like Auth0 and Clerk for developers who want to self-host.
With its MIT-licensed core, Logto ships with a developer-friendly console, pre-built UI components, and SDKs for React, Vue, Angular, iOS, Android, and Flutter. It handles the entire user identity lifecycle from registration through to role management, with built-in support for email/password, passwordless sign-in, social login, and enterprise SSO via SAML 2.0. Its multi-tenancy architecture makes it particularly well-suited for B2B SaaS platforms needing organization-level isolation.
Key Features
- OIDC & OAuth 2.1: Built on modern authentication standards with support for PKCE, JWT, and all OAuth 2.1 grant types.
- User-Friendly Console: Web-based admin interface for managing users, roles, applications, and authentication experiences.
- Multi-Tenancy: Native organizational structure with isolated user directories, roles, and SSO configurations per tenant.
- Enterprise SSO: SAML 2.0, OIDC, and social login providers for enterprise identity federation.
- Role-Based Access Control: Built-in RBAC with roles, permissions, and resource-level access management.
- Passwordless Authentication: Magic link email, verification code SMS, and social login — no password required.
- Pre-Built UI Components: Customizable sign-in and sign-up experiences with mobile-responsive design and multi-language support.
- Developer SDKs: Native SDKs for React, Vue, Angular, Next.js, iOS, Android, Flutter, and Node.js backends.
Use Cases
- Adding authentication to new SaaS applications with minimal development overhead.
- B2B multi-tenant platforms requiring per-organization user directories and SSO.
- Building AI applications needing JWT-based auth with standard OIDC integration.
- Self-hosting an Auth0/Clerk alternative with complete control over user data.
Platforms
Linux, Docker, Kubernetes (Node.js-based, runs anywhere with Docker)
Licence
MPL-2.0 (open source)
Website
logto.io | github.com/logto-io/logto
Views: 7