OSS Tanbou

centralize authentication, authorization, and organizations for SaaS and AI apps on OIDC and OAuth 2.1

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
14,646
Primary language
TypeScript
License
MPL-2.0
Repository last updated
Sep 30, 2026
On this page

Overview

Logto is authentication and authorization infrastructure built around OIDC and OAuth 2.1, with sign-in, MFA, SSO, SAML, multi-tenancy, and organization RBAC. More than 30 framework SDKs and management APIs support SaaS, MCP, and agent-based AI architectures.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Connect applications and identity providers with OIDC, OAuth 2.1, and SAML

Integrate SPAs, web and mobile applications, APIs, machine-to-machine clients, and CLIs through standard protocols while connecting social and enterprise identity providers.

Sources: [2]

Model SaaS tenants with organizations and RBAC

Organizations, memberships, roles, and scopes provide tenant boundaries and authorization for B2B applications, including JIT provisioning and enterprise SSO flows.

Sources: [2]

Support authentication flows for MCP and AI agents

The README explicitly targets MCP and agent architectures, while v1.44.0 adds refresh-token support for dynamic application clients so MCP clients such as ChatGPT and Codex can avoid repeated sign-ins.

Sources: [2][3]

Best fit

Fits SaaS teams centralizing customer organizations, SSO, and MFA in one identity platform

It is relevant when several applications and APIs should share authentication, authorization, tenant organizations, and management APIs instead of implementing login separately.

Sources: [2]

Before adoption

Treat the repository Docker Compose file as a demo stack

docker-compose.yml explicitly says it is for demonstration only and includes a fixed PostgreSQL password and exposed ports. Production deployments need hardened credentials, TLS, public endpoints, and backups.

Sources: [4]

Review database migrations and alterations during upgrades

Logto releases can include schema changes. Follow the upgrade guide and release notes and apply required database migration or alteration steps before starting a new version.

Sources: [3]

Review MPL-2.0 file-level copyleft requirements

Logto is released under MPL-2.0. When modified Covered Software is distributed, the source obligations for MPL-covered files should be reviewed.

Sources: [5]

Official sources

  1. [1]logto-io/logto repository(2026-10-01)
  2. [2]Logto README(2026-10-01)
  3. [3]Logto v1.44.0 release(2026-10-01)
  4. [4]Logto Docker Compose(2026-10-01)
  5. [5]Logto MPL-2.0 license(2026-10-01)
Supplemental curator note

Logto covers more than a sign-in UI by combining multi-tenancy, enterprise SSO, organization RBAC, MFA, and management APIs. v1.44.0 adds trusted MFA devices, refresh tokens for dynamic MCP clients, and self-hosted Cap CAPTCHA support.

Try it in 3 steps

  1. 1

    Download the official Docker Compose file

    Fetch the repository's demonstration Compose stack for local evaluation. It is not a production configuration.

    curl -fsSL https://raw.githubusercontent.com/logto-io/logto/master/docker-compose.yml -o docker-compose.yml
  2. 2

    Start Logto and PostgreSQL

    Pin Logto to v1.44.0 and start the application together with PostgreSQL.

    TAG=v1.44.0 docker compose -p logto up -d
  3. 3

    Open the Admin Console

    Complete initial setup, create an application, and test OIDC/OAuth integration. Replace the fixed database password and public endpoint settings for production.

    Open http://localhost:3002
Check the official README

Growth

Growth trends · Last 30 days

14,646 Stars

Trend data is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • authentication
  • authorization
  • email
  • identity
  • jwt
  • login
  • logto
  • mfa
  • oauth2
  • openid-connect
  • password
  • passwordless
Stars
14,646
Forks
1,215
Watchers
104
Open issues
157
Owner type
Organization
Primary language
TypeScript
License
MPL-2.0
Repository last updated
Sep 30, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?