VoidAuth

VoidAuth

WHAT IS IT?

VoidAuth is a single sign-on server written in TypeScript that sits in front of your self-hosted apps. It acts as an OpenID Connect provider for apps that support it, guards the rest through ForwardAuth at the reverse proxy, and has a web UI for managing accounts, groups and invitations. That puts it in the same slot as Authelia. The docs include OIDC setup guides for about thirty apps common in self-hosting, among them Immich, Jellyfin, Paperless-ngx, Vaultwarden and Proxmox VE.

WHY IS IT INTERESTING?

  • Two ways to protect an app: OIDC for apps that speak it, ForwardAuth for the others, through /api/authz/forward-auth for Caddy and Traefik or /api/authz/auth-request for NGINX and NGINX Proxy Manager. Access to each protected domain is granted per group.
  • OIDC clients declared as Docker labels: a voidauth.oidc.<client-id>.client_secret label on a container creates the client, and VoidAuth picks up containers as they start and stop. This needs /var/run/docker.sock mounted read-only. OIDC_<client-id>_* environment variables do the same without the socket.
  • Accounts managed from the UI: invitation links, self-registration that is off by default and gated by admin approval once enabled, email password resets and a log of sent mail.
  • MFA and passkeys: authenticator app codes, passkeys and passwordless passkey-only accounts. MFA can be required for everyone (MFA_REQUIRED) or per OIDC app.
  • Read-only LDAP directory: an experimental feature that exposes users and groups to services that only speak LDAP. Users who need MFA cannot bind, since a simple LDAP bind has no way to ask for a second factor.
  • Postgres or SQLite: SQLite is enough for a small setup, and voidauth migrate copies data from one database to the other without touching the source.
  • Branding: logo, title, theme color, font and email templates.

VoidAuth is Docker-only and does not terminate HTTPS, so it needs a reverse proxy with a certificate in front, and APP_URL must hold its full public URL. The first admin account is unlocked with a password reset link printed in the logs on first start. The encryption at rest mentioned in the README covers stored secrets (keys, OIDC client secrets), which are encrypted with a STORAGE_KEY of at least 32 characters that a secondary key lets you rotate. The README also warns that the project has not been audited and relies heavily on third-party packages.

The code is AGPL-3.0. The repository dates from April 2025, and v1.16.0 shipped on September 26, 2026, the tenth release since mid-June. A single maintainer authored most of the commits.

USE CASES

  • Put one login page in front of services that have no authentication of their own, through ForwardAuth on Caddy or Traefik.
  • Connect Immich, Jellyfin or Seafile over OIDC by following the guides in the docs.
  • Invite family or colleagues with a link instead of creating their account by hand in every app.
  • Give an LDAP directory to a service that supports nothing else, on a private network or over LDAPS.