Alternatives to Kanidm

An open-source identity management server offering OAuth2, LDAP and passkey login from one place. The listings below can replace it for an important use case. Each note says what changes if you switch.

The original

Replacements

Listings that take over the same core job as Kanidm.

  • Keycloak

    A self-hosted identity and access management server that adds single sign-on and login to applications.

    Keycloak is an Apache-licensed self-hosted SSO server with OpenID Connect and SAML brokering that connects to existing LDAP or Active Directory rather than serving LDAP itself.

  • FreeIPA

    Open-source identity management for Linux users and hosts, combining LDAP, Kerberos, DNS and certificates.

    FreeIPA combines LDAP, Kerberos, DNS and certificates for Linux hosts with Active Directory trusts, but its many components make it heavier to deploy.

  • Zitadel

    An open-source identity and access management platform with SSO, MFA and a hosted login page.

    Zitadel is an open-source, self-hostable identity platform aimed at developers, with multi-tenancy, SDKs and a customisable hosted login page instead of Unix login integration.

  • Casdoor

    A self-hosted identity and access management server with single sign-on, MFA and a web interface.

    Casdoor is an Apache-licensed self-hosted IAM server supporting OAuth, OIDC, SAML, CAS, LDAP and SCIM with a web UI, though its wide scope adds complexity.

  • Univention Corporate Server

    A Linux-based server system providing open-source identity and access management for on-premises networks.

    Univention Corporate Server is a full Linux server OS for on-premises identity and access management, so it needs a dedicated machine or VM rather than one service.

  • Microsoft Entra ID

    Microsoft's cloud identity and access management service, formerly Azure Active Directory, with single sign-on support.

    PaidProprietaryWeb

    Microsoft Entra ID is a paid cloud-only directory with single sign-on, tied to Microsoft's platform, replacing a self-hosted server you run yourself.

  • JumpCloud

    A cloud directory platform for managing user identities, access and devices across several operating systems.

    JumpCloud is a hosted paid cloud directory adding device management across Windows, Apple, Linux and Android, with SSO, MFA and RADIUS built in.

  • LLDAP

    A lightweight LDAP server for managing users and groups through a simple web interface.

    LLDAP is a lightweight LDAP server with a web interface for users and groups, but it needs a separate identity provider for OAuth2 or SSO.

Also worth comparing

These listings name Kanidm as their own alternative, so the relationship runs both ways.

  • 389 Directory Server

    An open-source LDAP directory server for Linux with multi-supplier replication.

    Kanidm combines LDAP with OAuth2 and passkey login in one open-source server, though its ecosystem is smaller than long-established directory servers.

  • FusionAuth

    An identity and user management server with SSO, MFA and OAuth2 that can be self-hosted.

    Kanidm is an open-source identity server with OAuth2, LDAP and passkeys plus Linux login integration, aimed more at self-hosters than app developers.

  • OpenLDAP

    Open-source implementation of LDAP, with a directory server, a load balancer, client libraries and tools.

    Kanidm offers LDAP alongside OAuth2 and passkeys in one server with Unix login integration, but has a smaller ecosystem than long-established directory servers.

  • privacyIDEA

    Open-source, self-hosted multi-factor authentication server that manages OTP and other token types.

    Kanidm provides passkey login, RADIUS support and LDAP in one open-source server rather than managing many OTP token types.

Similar software

Related functionality, not a direct replacement.