OSS Tanbou

manage SSO, MFA, passkeys, and B2B multi-tenancy through an API-first IAM

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
15,137
Primary language
Go
License
AGPL-3.0
Repository last updated
Sep 30, 2026
On this page

Overview

manage SSO, MFA, passkeys, and B2B multi-tenancy through an API-first IAM

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Key characteristics

manage SSO, MFA, passkeys, and B2B multi-tenancy through an API-first IAM

Sources: [1]

Best fit

Good fit for

A comparison candidate for Cloud Native, Identity & Access, Self-hosted, Authentication, Go, Identity and access management use cases. Check the official README and installation instructions for exact fit and requirements.

Before adoption

Check before adopting

The registered primary language is Go and the license is AGPL-3.0. Verify version-specific runtime requirements, breaking changes, and additional dependencies in the official README and latest release notes.

Sources: [1]

Official sources

  1. [1]zitadel/zitadel — GitHub(2026-09-15)
Supplemental curator note

ZITADEL is aimed at more than single-application login, with an infrastructure-level hierarchy for B2B organizations and projects. v4.19.2 fixed multiple authentication vulnerabilities, and Login V2 deployments should also configure a session-cookie signing secret.

Try it in 3 steps

  1. 1

    Download the official Compose configuration

    Fetch ZITADEL's official Docker Compose file and environment template.

    curl -LO https://raw.githubusercontent.com/zitadel/zitadel/main/deploy/compose/docker-compose.yml && curl -LO https://raw.githubusercontent.com/zitadel/zitadel/main/deploy/compose/.env.example && cp .env.example .env
  2. 2

    Set v4.19.3 and unique secrets

    Use an exactly 32-character master key and a session-cookie secret of at least 32 characters. Do not keep the documented insecure defaults.

    Edit .env: set ZITADEL_VERSION=v4.19.3 and replace ZITADEL_MASTERKEY, LOGIN_SESSION_COOKIE_SECRET, and PostgreSQL passwords
  3. 3

    Start ZITADEL

    Start PostgreSQL, the ZITADEL API, Login UI, and proxy. The default local configuration is available at http://localhost:8080.

    docker compose up -d --wait
Check the official README

Growth

Growth trends · Last 30 days

15,137 Stars

Trend data is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • 2fa
  • authentication
  • authorization
  • fido2
  • fips-140-3
  • identity
  • login
  • mfa
  • multitenancy
  • oauth2
  • oidc
  • openid-connect
Stars
15,137
Forks
1,328
Watchers
66
Open issues
1,233
Owner type
Organization
Primary language
Go
License
AGPL-3.0
Repository last updated
Sep 30, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?