Self-hosted SSO: which open-source tool to pick

Five open-source tools put a single sign-in in front of self-hosted applications, but they don't play the same part. Authelia and VoidAuth sit in front of the reverse proxy: they guard services that have no login of their own, and they also act as OpenID Connect providers. Authelia has no account management and no admin interface. authentik, Keycloak and Zitadel are full identity providers, with SAML and SCIM. Keycloak needs a JVM and 1,250 MB per instance, Zitadel moved to the AGPL with version 3, and authentik keeps part of its features for a paid edition.

A portal in front of the proxy, or a full identity provider

A ForwardAuth portal sits between the reverse proxy and the application: the proxy asks it whether the user is signed in, then passes the identity on in headers such as Remote-User. Authelia documents this setup for Traefik, Caddy, NGINX, NGINX Proxy Manager, SWAG, HAProxy, Envoy and Skipper, and VoidAuth for Caddy, Traefik, NGINX and NGINX Proxy Manager. authentik does the same through its Proxy provider.

On protocols, all five serve OpenID Connect, though Authelia's, certified as it is, is still labelled beta by the project. SAML is only available in authentik, Keycloak and Zitadel: Authelia is still choosing a library for it, and VoidAuth's docs don't mention it. SCIM is in authentik, in Keycloak since 26.8.0, and in Zitadel, while VoidAuth only has an open request for it. authentik also serves LDAP and RADIUS to applications through outposts, and VoidAuth exposes a read-only LDAP server that is still experimental.

Where the users live

Authelia has no directory of its own: accounts sit in a YAML file, which it rewrites on a password reset, or in an external LDAP such as OpenLDAP, Active Directory, FreeIPA or LLDAP. It offers no sign-up and no admin screen; an admin panel is on its roadmap. VoidAuth keeps accounts in its own database and manages them in a web interface: accounts are created by invitation, and open sign-up is off by default. authentik stores users in PostgreSQL and can sync them from LDAP or Active Directory. Keycloak splits them into isolated realms in its database, or federates an LDAP, Active Directory or Kerberos directory. Zitadel groups them by organisation inside an instance, and organisations let you delegate the management of users and roles, which the project pitches for B2B applications.

All five offer TOTP and passkeys (WebAuthn). authentik and Zitadel add codes by email or SMS, and Authelia and authentik support Duo push.

What each tool needs to run

Read from the repositories and documentation on 6 October 2026.

ToolLicenceWhat you runProtocolsAccountsLatest release
AutheliaApache-2.0a Go service, an SQL database; Redis and SMTP in productionForwardAuth, OIDC (beta)YAML file or external LDAP4.39.28, 17 Sep 2026
VoidAuthAGPL-3.0one container, PostgreSQL or SQLiteForwardAuth, OIDC, read-only LDAPits own database, by invitation1.16.0, 26 Sep 2026
authentikMIT, except the enterprise/ directoryserver, worker and PostgreSQL; at least 2 cores and 2 GBOIDC, SAML, SCIM, LDAP, RADIUS, proxyits own database, syncable with LDAP or AD2026.8.3, 17 Sep 2026
KeycloakApache-2.0a JVM and a relational database; 1,250 MB per instanceOIDC, SAML, SCIMrealms in its database, or a federated directory26.8.0, 1 Oct 2026
ZitadelAGPL-3.0 since v3Go API, Next.js login UI, PostgreSQL; at least 2 GB with ComposeOIDC, SAML, SCIMits own database, by organisation4.19.4, 1 Oct 2026

Authelia claims memory use usually under 30 MB, a figure from the project rather than a published measurement. Keycloak documents 1,250 MB per instance, caches and 10,000 sessions included, and a typical production setup runs at least two. Zitadel puts its own process at about 512 MB but asks for 2 GB for its Compose stack, and authentik sets a minimum of 2 cores and 2 GB. authentik no longer needs Redis since version 2025.10; Authelia recommends it in production for its sessions, which it otherwise keeps in memory. Authelia requires HTTPS even for a trial, and VoidAuth doesn't terminate TLS itself, so it needs a reverse proxy serving HTTPS.

Where the projects stand

Keycloak has been a CNCF incubating project since April 2023 and announces four minor releases a year. Zitadel has shipped eleven minor versions in 2026 and still patches its 3.4 branch. authentik releases every three months, but its security policy only covers the last two branches. Authelia keeps shipping 4.39 patch releases, eight of them in September 2026; its README asks you to pin a version rather than latest and says the team is raising funds for a security audit. VoidAuth is the youngest: repository created in April 2025, 57 releases since 1.0.0 in July 2025, one developer behind 1,132 of the 1,236 commits, and a README warning that the code hasn't been audited.

Licences and paid editions

Authelia and Keycloak are under Apache-2.0. Zitadel was too, up to its 2.x branch: since v3.0.0 on 2 May 2025 the core is under AGPL-3.0, with a commercial licence for anyone who wants to keep their changes private. Its cloud runs the same code, free up to 100 daily active users, then from 100 dollars a month. authentik is under MIT except for its enterprise/ directory, which is proprietary: those features need a subscription in production, at 5 dollars per user per month, and the vendor commits to never moving an open-source feature into the paid edition. VoidAuth is under AGPL-3.0.