Sign inSign up

abhiraheja/authly

By abhiraheja

โ€ขUpdated 16 days ago

Open-source self-hostable IDaaS: OAuth2/OIDC, SSO, MFA, passkeys, social login, multi-tenant

Image
Security
API management
Developer tools
0

3.5K

abhiraheja/authly repository overview

โ Authly โ€” Open-source Identity-as-a-Service (IDaaS)

A free, open-source, multi-tenant identity platform you can self-host in minutes โ€” a drop-in alternative to Auth0, Microsoft Entra, Google Identity, and Supabase Auth, with differentiators they lack: WhatsApp OTP, BYOK messaging/email, white-label login, and cloud or self-host from one codebase.

โ Features

  • ๐Ÿ”‘ OAuth2 / OIDC server (OpenIddict): Auth Code + PKCE, refresh-token rotation, client credentials, discovery/JWKS
  • ๐Ÿ›ก๏ธ MFA & passwordless: TOTP, passkeys (WebAuthn), magic links, WhatsApp/email OTP
  • ๐ŸŒ Social & enterprise login: Google, Microsoft, GitHub, Facebook + generic OAuth2/OIDC
  • ๐Ÿข Multi-tenant with per-org RBAC, conditional access, impersonation, device management, audit logs
  • ๐ŸŽจ White-label hosted login โ€” fully brandable (logo, colors, layouts, backgrounds, copy)
  • ๐Ÿ“ˆ Pluggable observability (OpenTelemetry โ†’ OTLP / Grafana / Azure Monitor)
  • ๐Ÿ”’ Argon2id password hashing, AES-256-GCM encryption at rest, PostgreSQL row-level security

โ Quick start

Authly needs PostgreSQL and Redis alongside it, so the supported way to run is Docker Compose. Save the file below as docker-compose.yml, then run it โ€” Postgres and Redis are included.

services:
  postgres:
    image: postgres:16
    environment:
      POSTGRES_USER: authly
      POSTGRES_PASSWORD: authly
      POSTGRES_DB: authly
    volumes:
      - pgdata:/var/lib/postgresql/data
    healthcheck:
      test: ["CMD-SHELL", "pg_isready -U authly"]
      interval: 5s
      timeout: 5s
      retries: 10

  redis:
    image: redis:7

  authly:
    image: abhiraheja/authly:latest
    depends_on:
      postgres:
        condition: service_healthy
      redis:
        condition: service_started
    environment:
      # Postgres connection string (Npgsql format) โ€” points at the bundled service below
      - DATABASE_URL=Host=postgres;Database=authly;Username=authly;Password=authly
      # Redis host:port โ€” points at the bundled service below
      - REDIS_URL=redis:6379
      # REQUIRED. 32-byte base64 key for AES-256-GCM secret encryption.
      # Generate one with:  openssl rand -base64 32
      - ENCRYPTION_KEY=CHANGE_ME_openssl_rand_base64_32
      # Serve the public marketing website + docs at "/". If left false (the default),
      # "/" redirects to the admin console and only the IdP/login/OIDC routes are served.
      - Website__Enabled=true
    ports:
      - "8080:8080"
    restart: unless-stopped

volumes:
  pgdata:
# 1. Generate an encryption key and paste it into ENCRYPTION_KEY above
openssl rand -base64 32

# 2. Start everything (pulls Postgres, Redis and the Authly image)
docker compose up -d

# 3. Watch the app apply EF Core migrations on first boot
docker compose logs -f authly

Then open http://localhost:8080โ  and click Sign up โ€” the account you create becomes the first administrator of its workspace. Your OIDC discovery document is at http://localhost:8080/.well-known/openid-configuration.

Production: generate a fresh ENCRYPTION_KEY, use strong DB/Redis passwords, and put a TLS reverse proxy (Traefik / nginx / Caddy) in front. See the in-product Production deployment guideโ .

โ Required environment variables
VariableRequiredWhat it is
ENCRYPTION_KEYYes32-byte base64 key (AES-256-GCM). App refuses to start without it. openssl rand -base64 32.
DATABASE_URLYesPostgreSQL connection string (Npgsql format), e.g. Host=postgres;Database=authly;Username=authly;Password=authly.
REDIS_URLYesRedis host:port (cache/sessions, rate limiting, login lockout โ€” shared across instances).
Website__EnabledNotrue serves the public marketing website + docs; default false redirects / to the admin console.
CORS_ALLOWED_ORIGINSNoExtra trusted browser origins for SPA CORS (app redirect URIs are allowed automatically).
RETENTION_AUDIT_DAYS / RETENTION_LOGIN_HISTORY_DAYSNoRetention windows (default 365 / 90).
OTEL_EXPORTER_OTLP_ENDPOINTNoOpenTelemetry collector endpoint for traces/metrics/logs.

โ Tech stack

ASP.NET Core 10 (MVC + Razor) ยท OpenIddict (OAuth2/OIDC) ยท PostgreSQL + EF Core ยท Redis ยท Hangfire ยท Docker.

Tags: identity, authentication, authorization, oauth2, oidc, sso, mfa, passkeys, iam, idaas, self-hosted, auth0-alternative

Tag summary

Content type

Image

Digest

sha256:23bb2bf34โ€ฆ

Size

104 MB

Last updated

16 days ago

docker pull abhiraheja/authly