WHAT IS IT?
VoidAuth is a single sign-on server written in TypeScript that sits in front of your self-hosted apps. It acts as an OpenID Connect provider for apps that support it, guards the rest through ForwardAuth at the reverse proxy, and has a web UI for managing accounts, groups and invitations. That puts it in the same slot as Authelia. The docs include OIDC setup guides for about thirty apps common in self-hosting, among them Immich, Jellyfin, Paperless-ngx, Vaultwarden and Proxmox VE.
WHY IS IT INTERESTING?
- Two ways to protect an app: OIDC for apps that speak it, ForwardAuth for the others, through
/api/authz/forward-authfor Caddy and Traefik or/api/authz/auth-requestfor NGINX and NGINX Proxy Manager. Access to each protected domain is granted per group. - OIDC clients declared as Docker labels: a
voidauth.oidc.<client-id>.client_secretlabel on a container creates the client, and VoidAuth picks up containers as they start and stop. This needs/var/run/docker.sockmounted read-only.OIDC_<client-id>_*environment variables do the same without the socket. - Accounts managed from the UI: invitation links, self-registration that is off by default and gated by admin approval once enabled, email password resets and a log of sent mail.
- MFA and passkeys: authenticator app codes, passkeys and passwordless passkey-only accounts. MFA can be required for everyone (
MFA_REQUIRED) or per OIDC app. - Read-only LDAP directory: an experimental feature that exposes users and groups to services that only speak LDAP. Users who need MFA cannot bind, since a simple LDAP bind has no way to ask for a second factor.
- Postgres or SQLite: SQLite is enough for a small setup, and
voidauth migratecopies data from one database to the other without touching the source. - Branding: logo, title, theme color, font and email templates.
VoidAuth is Docker-only and does not terminate HTTPS, so it needs a reverse proxy with a certificate in front, and APP_URL must hold its full public URL. The first admin account is unlocked with a password reset link printed in the logs on first start. The encryption at rest mentioned in the README covers stored secrets (keys, OIDC client secrets), which are encrypted with a STORAGE_KEY of at least 32 characters that a secondary key lets you rotate. The README also warns that the project has not been audited and relies heavily on third-party packages.
The code is AGPL-3.0. The repository dates from April 2025, and v1.16.0 shipped on September 26, 2026, the tenth release since mid-June. A single maintainer authored most of the commits.
USE CASES
- Put one login page in front of services that have no authentication of their own, through ForwardAuth on Caddy or Traefik.
- Connect Immich, Jellyfin or Seafile over OIDC by following the guides in the docs.
- Invite family or colleagues with a link instead of creating their account by hand in every app.
- Give an LDAP directory to a service that supports nothing else, on a private network or over LDAPS.
