Account Settings
A user's own passkey-secured account, managed without a traditional password.
Passkey-only OIDC provider for single sign-on across self-hosted apps.
A user's own passkey-secured account, managed without a traditional password.
OIDC/OAuth2 client applications configured for single sign-on.
Admin view of every user provisioned in this Pocket ID instance.
A full record of sign-ins and authorization events across every user.
Server-wide branding and behaviour settings for the Pocket ID instance.
Pocket ID is a lightweight OpenID Connect and OAuth 2.0 provider built around passkeys instead of passwords. It syncs users and groups from an LDAP source, restricts which user groups can authenticate to a given OIDC client, and keeps audit logs of sign-in activity with optional email alerts for logins from unrecognised devices. People who choose Pocket ID over full-featured identity platforms consistently point to how little setup and maintenance it demands. In a Hacker News discussion comparing self-hosted OIDC providers, several users independently said the more established options looked too heavy or complex for what they needed, and praised Pocket ID for doing one thing well as a single-container deployment. Every feature, including LDAP sync and audit logging, is available self-hosted at no cost.
v2.12.0 (about 20 hours ago*)
about 6 hours ago*
GitHub
pocket-id/pocket-id8.6k stars
282 forks
Funding
Technology stack
BSD-2-CLAUSE
BSD 2-Clause "Simplified" License
A permissive license that comes in two variants, the <a href="/licenses/bsd-2-clause/">BSD 2-Clause</a> and <a href="/licenses/bsd-3-clause/">BSD 3-Clause</a>. Both have very minute differences to the MIT license.
Bitflake is not affiliated with or the creator of this project. App names, logos, and trademarks are property of their respective owners. Data shown (including GitHub stats) is updated once per day and may be inaccurate or out of date. Spotted an issue? Let us know at contact@bitflake.com.