On this page
Overview
OAuth2 Proxy is a reverse proxy that sits between users and a web application and handles OAuth 2.0 or OpenID Connect authentication. It can connect to Google, Microsoft Entra ID, GitHub, generic OIDC providers, and others, forwarding only authenticated requests to the application.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Move authentication outside the application
The proxy handles login initiation, callbacks, and session cookies. It can also pass authenticated user information to an upstream application in HTTP headers.
Best fit
Before adoption
Define boundaries for secrets and forwarded identity
Production requires real client credentials, an unpredictable cookie secret, and an exact redirect URL registered with the identity provider. Wildcard email domains and identity headers should be limited to intended users and trusted upstreams.
Official sources
- [1]OAuth2 Proxy README at v7.15.5(2026-10-05)
- [2]OAuth2 Proxy configuration overview at v7.15.5(2026-10-05)
- [3]OAuth2 Proxy Google provider guide at v7.15.5(2026-10-05)
- [4]OAuth2 Proxy endpoints documentation at v7.15.5(2026-10-05)
- [5]OAuth2 Proxy LICENSE at v7.15.5(2026-10-05)
- [6]OAuth2 Proxy v7.15.5 release(2026-10-05)
Supplemental curator note
Evaluate both provider support and the trust boundary for headers and cookies sent upstream. Start with fake credentials and a loopback-only endpoint before connecting a real provider.
Try it in 3 steps
- 1
Pull the pinned container
Use Docker to fetch the official OAuth2 Proxy v7.15.5 image.
docker pull quay.io/oauth2-proxy/oauth2-proxy:v7.15.5 - 2
Create a configuration with fake credentials
Create a Google provider example without real secrets and verify that the decoded cookie secret is exactly 32 bytes.
mkdir oauth2-proxy-demo && cd oauth2-proxy-demo && printf '%s\n' 'provider = "google"' 'client_id = "example-client-id"' 'client_secret = "example-client-secret"' 'redirect_url = "http://127.0.0.1:4180/oauth2/callback"' 'http_address = "0.0.0.0:4180"' 'email_domains = ["example.com"]' 'cookie_secret = "MDEyMzQ1Njc4OWFiY2RlZjAxMjM0NTY3ODlhYmNkZWY="' > oauth2-proxy.cfg && test "$(sed -n 's/^cookie_secret = "\(.*\)"$/\1/p' oauth2-proxy.cfg | base64 -d | wc -c | tr -d ' ')" = 32 - 3
Load the configuration and check local health
Start the container on an allocated local port and check /ping within a bound of about 30 seconds. Cleanup targets only the captured container ID; no real Google login occurs.
( cid=''; cleanup() { if test -n "$cid"; then docker rm -f "$cid" >/dev/null 2>&1 || true; fi; }; trap cleanup EXIT INT TERM; cid=$(docker run -d --rm -p 127.0.0.1::4180 -v "$PWD/oauth2-proxy.cfg:/etc/oauth2-proxy.cfg:ro" quay.io/oauth2-proxy/oauth2-proxy:v7.15.5 --config=/etc/oauth2-proxy.cfg) || exit 1; test -n "$cid" || exit 1; port=$(docker port "$cid" 4180/tcp | sed -n 's/.*://p') || exit 1; test -n "$port" || exit 1; ready=0; for attempt in 1 2 3 4 5 6 7 8 9 10; do if curl -fsS --connect-timeout 1 --max-time 2 "http://127.0.0.1:$port/ping" -o ping.txt; then ready=1; break; fi; sleep 1; done; test "$ready" = 1 )
Growth
Growth trends · Last 30 days
15,046 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 13
- Open PRs
- 130
- Issues opened
- 24
- Issues closed
- 24
- PRs opened
- 70
- PRs merged
- 25
Issues
24 / 24
Pull requests
70 / 25
Maintenance
- Median first response
- Not specified
- Issue response rate
- 0% (0/23)
Based on up to the 100 newest issues opened by external users in the last 90 days. A first comment from an OWNER, MEMBER, or COLLABORATOR counts as a response; issues whose full comment history cannot be checked are excluded. The median and response rate update weekly.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- cloud-infrastructure
- oauth2-proxy
- ssl
- sso
- hacktoberfest
- oauth2
- oidc
- oidc-proxy
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- Keycloak37,134 Stars
2 shared tag(s) · 1 shared category(s)
an IAM server providing authentication and authorization to applications
Java - omniauth8,102 Stars
2 shared tag(s) · 1 shared category(s)
Add multiple authentication strategies to Rack applications through one flow
Ruby - Supabase111,098 Stars
2 shared tag(s)
Build on Postgres with integrated Auth, REST/GraphQL APIs, Realtime, Storage, and Functions
TypeScript - SPIRE2,571 Stars
1 shared tag(s) · 1 shared category(s) · Same language
attest running workloads and issue short-lived SVID credentials bound to SPIFFE identities
Go - Better Auth30,165 Stars
1 shared tag(s) · 1 shared category(s)
control authentication, authorization, OAuth/OIDC, and plugins inside a TypeScript application
TypeScript - Envoy29,037 Stars
1 shared tag(s) · 1 shared category(s)
a cloud-native high-performance proxy for edge and service traffic
C++
Report incorrect information
Tell us if any listing information is incorrect or outdated.