- Keycloak: IAM and SSO platform with extensive protocol support (OIDC, SAML, LDAP).
- Authentik: Flexible IdP with multiple protocols, self-service features, and extensive customization.
- Authelia: SSO and MFA gateway designed for protecting self-hosted services.
- ZITADEL: Cloud-native IAM with focus on privacy and data protection.
- Okta: Comprehensive identity platform with extensive enterprise features and integrations.
- Azure AD: Microsoft’s cloud-based identity and access management service.
- AWS Cognito: Identity management for AWS applications with user pools and identity pools.
- Google Cloud Identity: Identity and access management for Google Cloud Platform.
- Ping Identity: Enterprise-grade identity and access management solutions.
- ForgeRock: Comprehensive identity platform with API security and customer identity management.
- IBM Security Verify: Identity and access management with adaptive authentication.
- CyberArk Identity: Privileged access management and identity security platform.
| Solution |
Open Source |
Protocols |
Self-Hosting |
Enterprise Features |
| Keycloak |
Yes |
OIDC, SAML, LDAP |
Yes |
Extensive |
| Authentik |
Yes |
OIDC, SAML, LDAP, Radius |
Yes |
Good |
| Authelia |
Yes |
OIDC (client) |
Yes |
Limited |
| ZITADEL |
Yes |
OIDC, SAML |
Yes |
Moderate |
| Okta |
No |
OIDC, SAML |
Cloud only |
Extensive |
| Azure AD |
No |
OIDC, SAML, WS-Fed |
Cloud only |
Extensive |