OSS TanbouSign in with GitHub

Put authentication in front of web applications and pass through authorized users

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
15,046
Primary language
Go
License
MIT
Repository last updated
Oct 5, 2026
On this page

Overview

OAuth2 Proxy is a reverse proxy that sits between users and a web application and handles OAuth 2.0 or OpenID Connect authentication. It can connect to Google, Microsoft Entra ID, GitHub, generic OIDC providers, and others, forwarding only authenticated requests to the application.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Move authentication outside the application

The proxy handles login initiation, callbacks, and session cookies. It can also pass authenticated user information to an upstream application in HTTP headers.

Sources: [1][2]

Support multiple identity providers and deployment patterns

Built-in provider configurations and generic OIDC are available. OAuth2 Proxy can run as the reverse proxy or integrate with mechanisms such as Nginx auth_request.

Sources: [1][2]

Best fit

Protect internal web applications that lack authentication

It fits dashboards and administration tools that need organization login without changing the application. Public deployments must account for provider registration, forwarded headers, TLS, and cookie scope.

Sources: [1][3]

Before adoption

Define boundaries for secrets and forwarded identity

Production requires real client credentials, an unpredictable cookie secret, and an exact redirect URL registered with the identity provider. Wildcard email domains and identity headers should be limited to intended users and trusted upstreams.

Sources: [2][3]

Treat the local example as configuration-only validation

The quick start uses fake Google credentials to check configuration parsing, a 32-byte cookie secret, and the local /ping endpoint. It does not test Google login, callback handling, or an upstream application.

Sources: [2][4]

Official sources

  1. [1]OAuth2 Proxy README at v7.15.5(2026-10-05)
  2. [2]OAuth2 Proxy configuration overview at v7.15.5(2026-10-05)
  3. [3]OAuth2 Proxy Google provider guide at v7.15.5(2026-10-05)
  4. [4]OAuth2 Proxy endpoints documentation at v7.15.5(2026-10-05)
  5. [5]OAuth2 Proxy LICENSE at v7.15.5(2026-10-05)
  6. [6]OAuth2 Proxy v7.15.5 release(2026-10-05)
Supplemental curator note

Evaluate both provider support and the trust boundary for headers and cookies sent upstream. Start with fake credentials and a loopback-only endpoint before connecting a real provider.

Try it in 3 steps

  1. 1

    Pull the pinned container

    Use Docker to fetch the official OAuth2 Proxy v7.15.5 image.

    docker pull quay.io/oauth2-proxy/oauth2-proxy:v7.15.5
  2. 2

    Create a configuration with fake credentials

    Create a Google provider example without real secrets and verify that the decoded cookie secret is exactly 32 bytes.

    mkdir oauth2-proxy-demo && cd oauth2-proxy-demo && printf '%s\n' 'provider = "google"' 'client_id = "example-client-id"' 'client_secret = "example-client-secret"' 'redirect_url = "http://127.0.0.1:4180/oauth2/callback"' 'http_address = "0.0.0.0:4180"' 'email_domains = ["example.com"]' 'cookie_secret = "MDEyMzQ1Njc4OWFiY2RlZjAxMjM0NTY3ODlhYmNkZWY="' > oauth2-proxy.cfg && test "$(sed -n 's/^cookie_secret = "\(.*\)"$/\1/p' oauth2-proxy.cfg | base64 -d | wc -c | tr -d ' ')" = 32
  3. 3

    Load the configuration and check local health

    Start the container on an allocated local port and check /ping within a bound of about 30 seconds. Cleanup targets only the captured container ID; no real Google login occurs.

    ( cid=''; cleanup() { if test -n "$cid"; then docker rm -f "$cid" >/dev/null 2>&1 || true; fi; }; trap cleanup EXIT INT TERM; cid=$(docker run -d --rm -p 127.0.0.1::4180 -v "$PWD/oauth2-proxy.cfg:/etc/oauth2-proxy.cfg:ro" quay.io/oauth2-proxy/oauth2-proxy:v7.15.5 --config=/etc/oauth2-proxy.cfg) || exit 1; test -n "$cid" || exit 1; port=$(docker port "$cid" 4180/tcp | sed -n 's/.*://p') || exit 1; test -n "$port" || exit 1; ready=0; for attempt in 1 2 3 4 5 6 7 8 9 10; do if curl -fsS --connect-timeout 1 --max-time 2 "http://127.0.0.1:$port/ping" -o ping.txt; then ready=1; break; fi; sleep 1; done; test "$ready" = 1 )
Check the official README

Growth

Growth trends · Last 30 days

15,046 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
13
Open PRs
130
Issues opened
24
Issues closed
24
PRs opened
70
PRs merged
25

Issues

24 / 24

Jul 8Oct 5
Issues openedIssues closed

Pull requests

70 / 25

Jul 8Oct 5
PRs openedPRs merged

Maintenance

Median first response
Not specified
Issue response rate
0% (0/23)

Based on up to the 100 newest issues opened by external users in the last 90 days. A first comment from an OWNER, MEMBER, or COLLABORATOR counts as a response; issues whose full comment history cannot be checked are excluded. The median and response rate update weekly.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • cloud-infrastructure
  • oauth2-proxy
  • ssl
  • sso
  • hacktoberfest
  • oauth2
  • oidc
  • oidc-proxy
Stars
15,046
Forks
2,207
Watchers
104
Open issues
153
Contributors
414
Owner type
Organization
Primary language
Go
License
MIT
Repository last updated
Oct 5, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?