On this page
Overview
manage SSO, MFA, passkeys, and B2B multi-tenancy through an API-first IAM
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Key characteristics
manage SSO, MFA, passkeys, and B2B multi-tenancy through an API-first IAM
Sources: [1]
Best fit
Good fit for
A comparison candidate for Cloud Native, Identity & Access, Self-hosted, Authentication, Go, Identity and access management use cases. Check the official README and installation instructions for exact fit and requirements.
Before adoption
Check before adopting
The registered primary language is Go and the license is AGPL-3.0. Verify version-specific runtime requirements, breaking changes, and additional dependencies in the official README and latest release notes.
Sources: [1]
Official sources
- [1]zitadel/zitadel — GitHub(2026-09-15)
Supplemental curator note
ZITADEL is aimed at more than single-application login, with an infrastructure-level hierarchy for B2B organizations and projects. v4.19.2 fixed multiple authentication vulnerabilities, and Login V2 deployments should also configure a session-cookie signing secret.
Try it in 3 steps
- 1
Download the official Compose configuration
Fetch ZITADEL's official Docker Compose file and environment template.
curl -LO https://raw.githubusercontent.com/zitadel/zitadel/main/deploy/compose/docker-compose.yml && curl -LO https://raw.githubusercontent.com/zitadel/zitadel/main/deploy/compose/.env.example && cp .env.example .env - 2
Set v4.19.3 and unique secrets
Use an exactly 32-character master key and a session-cookie secret of at least 32 characters. Do not keep the documented insecure defaults.
Edit .env: set ZITADEL_VERSION=v4.19.3 and replace ZITADEL_MASTERKEY, LOGIN_SESSION_COOKIE_SECRET, and PostgreSQL passwords - 3
Start ZITADEL
Start PostgreSQL, the ZITADEL API, Login UI, and proxy. The default local configuration is available at http://localhost:8080.
docker compose up -d --wait
Growth
Growth trends · Last 30 days
15,137 Stars
Trend data is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- 2fa
- authentication
- authorization
- fido2
- fips-140-3
- identity
- login
- mfa
- multitenancy
- oauth2
- oidc
- openid-connect
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- NetBird29,628 Stars
2 shared tag(s) · 2 shared category(s) · Same language
Connect devices, users, and agents with WireGuard mesh and identity-aware policy
Go - Rancher25,942 Stars
2 shared tag(s) · 2 shared category(s) · Same language
Unify access and operations across multiple Kubernetes clusters
Go - LiveKit21,165 Stars
2 shared tag(s) · 2 shared category(s) · Same language
Add realtime audio, video, and data to applications through shared rooms
Go - Coder16,778 Stars
2 shared tag(s) · 2 shared category(s) · Same language
provision secure Terraform-defined environments for developers and coding agents
Go - Hanko9,035 Stars
2 shared tag(s) · 2 shared category(s) · Same language
API-first authentication from passkeys to SSO with native multi-tenancy
Go - Inngest5,901 Stars
2 shared tag(s) · 2 shared category(s) · Same language
Turn events into durable steps and delegate retries, waits, and flow control to the orchestration layer
Go
Report incorrect information
Tell us if any listing information is incorrect or outdated.