On this page
Overview
Logto is authentication and authorization infrastructure built around OIDC and OAuth 2.1, with sign-in, MFA, SSO, SAML, multi-tenancy, and organization RBAC. More than 30 framework SDKs and management APIs support SaaS, MCP, and agent-based AI architectures.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Connect applications and identity providers with OIDC, OAuth 2.1, and SAML
Integrate SPAs, web and mobile applications, APIs, machine-to-machine clients, and CLIs through standard protocols while connecting social and enterprise identity providers.
Sources: [2]
Model SaaS tenants with organizations and RBAC
Organizations, memberships, roles, and scopes provide tenant boundaries and authorization for B2B applications, including JIT provisioning and enterprise SSO flows.
Sources: [2]
Best fit
Fits SaaS teams centralizing customer organizations, SSO, and MFA in one identity platform
It is relevant when several applications and APIs should share authentication, authorization, tenant organizations, and management APIs instead of implementing login separately.
Sources: [2]
Before adoption
Treat the repository Docker Compose file as a demo stack
docker-compose.yml explicitly says it is for demonstration only and includes a fixed PostgreSQL password and exposed ports. Production deployments need hardened credentials, TLS, public endpoints, and backups.
Sources: [4]
Review database migrations and alterations during upgrades
Logto releases can include schema changes. Follow the upgrade guide and release notes and apply required database migration or alteration steps before starting a new version.
Sources: [3]
Review MPL-2.0 file-level copyleft requirements
Logto is released under MPL-2.0. When modified Covered Software is distributed, the source obligations for MPL-covered files should be reviewed.
Sources: [5]
Official sources
- [1]logto-io/logto repository(2026-10-01)
- [2]Logto README(2026-10-01)
- [3]Logto v1.44.0 release(2026-10-01)
- [4]Logto Docker Compose(2026-10-01)
- [5]Logto MPL-2.0 license(2026-10-01)
Supplemental curator note
Logto covers more than a sign-in UI by combining multi-tenancy, enterprise SSO, organization RBAC, MFA, and management APIs. v1.44.0 adds trusted MFA devices, refresh tokens for dynamic MCP clients, and self-hosted Cap CAPTCHA support.
Try it in 3 steps
- 1
Download the official Docker Compose file
Fetch the repository's demonstration Compose stack for local evaluation. It is not a production configuration.
curl -fsSL https://raw.githubusercontent.com/logto-io/logto/master/docker-compose.yml -o docker-compose.yml - 2
Start Logto and PostgreSQL
Pin Logto to v1.44.0 and start the application together with PostgreSQL.
TAG=v1.44.0 docker compose -p logto up -d - 3
Open the Admin Console
Complete initial setup, create an application, and test OIDC/OAuth integration. Replace the fixed database password and public endpoint settings for production.
Open http://localhost:3002
Growth
Growth trends · Last 30 days
14,646 Stars
Trend data is still being collected.
Built with
Categories and tags
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- authentication
- authorization
- identity
- jwt
- login
- logto
- mfa
- oauth2
- openid-connect
- password
- passwordless
- Stars
- 14,646
- Forks
- 1,215
- Watchers
- 104
- Open issues
- 157
- Owner type
- Organization
- Primary language
- TypeScript
- License
- MPL-2.0
- Repository last updated
- Sep 30, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- Supabase110,918 Stars
4 shared tag(s) · 1 shared category(s) · Same language
Build on Postgres with integrated Auth, REST/GraphQL APIs, Realtime, Storage, and Functions
TypeScript - authentik25,777 Stars
3 shared tag(s) · 3 shared category(s)
Unify SAML, OIDC/OAuth2, LDAP, RADIUS, and proxy outposts in a self-hosted Identity Provider and SSO platform
Python - Budibase28,327 Stars
3 shared tag(s) · 2 shared category(s) · Same language
Build internal apps, automations, and AI agents visually on top of data sources and approval policies
TypeScript - Tiledesk Dashboard16 Stars
3 shared tag(s) · 2 shared category(s) · Same language
Manage Tiledesk conversations, support teams, tickets, knowledge bases, and AI agents from the platform's web console
TypeScript - n8n206,322 Stars
3 shared tag(s) · 1 shared category(s) · Same language
Connect visual workflows, code, AI agents, and human approvals in one automation runtime
TypeScript - Dify157,552 Stars
3 shared tag(s) · 1 shared category(s) · Same language
design and publish AI workflows, retrieval, and agents on one platform
TypeScript
Report incorrect information
Tell us if any listing information is incorrect or outdated.