Sign inSign up

websvcin/loginlink

By websvcin

•Updated 1 day ago

Self-hosted OAuth 2.0 + OpenID Connect identity platform for multi-tenant SaaS.

Image
Security
API management
0

1.0K

websvcin/loginlink repository overview

Self-hosted OAuth 2.0 + OpenID Connect identity platform for multi-tenant SaaS.

A ship-yourself alternative to Auth0 / Okta / Clerk that you fully own — your users' data never leaves your own infrastructure. Built with .NET 8, one image, no external services required to start.

⁠Quick start

docker run -d \
  -p 5000:5000 -p 5443:5443 \
  -v $(pwd)/App_Data:/app/App_Data \
  --name loginlink \
  websvcin/loginlink:latest

Open http://localhost:5000. Three demo accounts are seeded automatically on first boot:

SurfaceURLLogin
Platform admin/admin/loginadmin@local / Admin@123
Tenant console/console/loginacme@local / Acme@123
End user/loginuser@local / User@123

Change these before exposing the container to the internet.

⁠Persistence

App_Data (mounted above) is the entire persistence story — host.db, platform.db, every tenant's own isolated tenant_<id>.db, and self-updating GeoLocation/IP-intelligence data all live under that one directory. Mount it once; nothing else needs to survive a restart.

⁠What's inside

  • Multi-tenant, isolated by design — one SQLite database per tenant; no tenant's data is ever queryable from another's.
  • OAuth 2.0 + OpenID Connect — RS256 signing (auto-rotating keys, per-tenant), PKCE enforced, refresh tokens, a real consent flow.
  • Pluggable sign-in connectors — password (Argon2id), Google/GitHub/Microsoft/Apple/etc. OAuth, Email OTP, SMS OTP, TOTP, WebAuthn/Passkeys, Magic Link, SAML.
  • MFA + recovery — TOTP, Email/SMS OTP as a second factor, recovery codes, a tenant-configurable exhaustion policy.
  • Management REST API + SCIM — self-service client_credentials API keys per tenant for scripting users/roles/apps, plus SCIM for provisioning-tool sync.
  • Platform tenant-provisioning API — a separate, platform-scoped credential lets an external system create whole new tenants server-to-server (POST /api/v1/tenants) — useful when embedding LoginLink as another product's identity layer.
  • Admin console — tenants, apps, users, audit log, webhooks, rate limiting, platform admins.
  • Webhooks, audit logging, rate limiting — built in, not bolted on.

⁠Tags

TagWhat it is
latestMost recent build off main
1.0Latest build in the 1.0 series
1.0.NA specific, reproducible build
An exact X.Y.ZBuilt from a pushed vX.Y.Z git tag

⁠License

Source-available; see the repository for current license status.

Tag summary

Content type

Image

Digest

sha256:8656a14ef…

Size

118.1 MB

Last updated

1 day ago

docker pull websvcin/loginlink