Alternatives to FusionAuth

An identity and user management server with SSO, MFA and OAuth2 that can be self-hosted. The listings below can replace it for an important use case. Each note says what changes if you switch.

The original

Replacements

Listings that take over the same core job as FusionAuth.

  • Keycloak

    A self-hosted identity and access management server that adds single sign-on and login to applications.

    Keycloak is fully open source under Apache-2.0, offering SSO with OpenID Connect and SAML brokering plus LDAP and Active Directory connections.

  • Zitadel

    An open-source identity and access management platform with SSO, MFA and a hosted login page.

    Zitadel is open source and self-hostable, with multi-tenancy, passwordless login, SDKs and a customisable hosted login page for app developers.

  • Casdoor

    A self-hosted identity and access management server with single sign-on, MFA and a web interface.

    Casdoor is open source under Apache-2.0 and supports OAuth, OIDC, SAML, CAS, LDAP and SCIM with a web UI, but its broad scope adds complexity.

  • Kanidm

    An open-source identity management server offering OAuth2, LDAP and passkey login from one place.

    Kanidm is an open-source identity server with OAuth2, LDAP and passkeys plus Linux login integration, aimed more at self-hosters than app developers.

  • Microsoft Entra ID

    Microsoft's cloud identity and access management service, formerly Azure Active Directory, with single sign-on support.

    PaidProprietaryWeb

    Microsoft Entra ID moves identity into Microsoft's paid cloud with SSO, focused on staff accounts rather than self-hosted app login.

Similar software

Related functionality, not a direct replacement.