Kanidm
An open-source identity management server offering OAuth2, LDAP and passkey login from one place.
These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.
About Kanidm
Kanidm is an identity management platform written in Rust that keeps accounts and groups in one server and lets applications authenticate against it using OAuth2 and LDAP, with passkey support for user logins.
The project includes Unix integration so Linux machines can use Kanidm accounts, RADIUS modules, a Python client and command-line tools, with documentation maintained as a book in the repository. It suits self-hosters and organisations looking for a single, modern identity service.
Strengths
- OAuth2, LDAP and passkeys in a single server
- Unix integration for Linux logins
- RADIUS support through included modules
Limitations
- Smaller ecosystem than long-established directory servers
- Requires running and securing your own server
Details
- Pricing
- FreeFree and open source.
- License
- Open source, license not stated
- Developer
- The Kanidm contributors
- Platforms
- Linux, Self-hosted, Command line
- How it runs
- Self-hosted
- Account
- Not required
- Best suited for
- Self-hosters and teams wanting one identity server with passkey support
- Categories
- IT administration
- Last verified
- Added
- Provenance
- Facts checked against the developer's own pages and store listings, 1 sources on file.
Alternatives to Kanidm
Compare allSoftware that can replace Kanidm for an important use case, and what changes if you switch.
Keycloak
A self-hosted identity and access management server that adds single sign-on and login to applications.
Keycloak is an Apache-licensed self-hosted SSO server with OpenID Connect and SAML brokering that connects to existing LDAP or Active Directory rather than serving LDAP itself.
FreeIPA
Open-source identity management for Linux users and hosts, combining LDAP, Kerberos, DNS and certificates.
FreeIPA combines LDAP, Kerberos, DNS and certificates for Linux hosts with Active Directory trusts, but its many components make it heavier to deploy.
Zitadel
An open-source identity and access management platform with SSO, MFA and a hosted login page.
Zitadel is an open-source, self-hostable identity platform aimed at developers, with multi-tenancy, SDKs and a customisable hosted login page instead of Unix login integration.
Casdoor
A self-hosted identity and access management server with single sign-on, MFA and a web interface.
Casdoor is an Apache-licensed self-hosted IAM server supporting OAuth, OIDC, SAML, CAS, LDAP and SCIM with a web UI, though its wide scope adds complexity.
Univention Corporate Server
A Linux-based server system providing open-source identity and access management for on-premises networks.
Univention Corporate Server is a full Linux server OS for on-premises identity and access management, so it needs a dedicated machine or VM rather than one service.
Microsoft Entra ID
Microsoft's cloud identity and access management service, formerly Azure Active Directory, with single sign-on support.
Microsoft Entra ID is a paid cloud-only directory with single sign-on, tied to Microsoft's platform, replacing a self-hosted server you run yourself.
JumpCloud
A cloud directory platform for managing user identities, access and devices across several operating systems.
JumpCloud is a hosted paid cloud directory adding device management across Windows, Apple, Linux and Android, with SSO, MFA and RADIUS built in.
LLDAP
A lightweight LDAP server for managing users and groups through a simple web interface.
LLDAP is a lightweight LDAP server with a web interface for users and groups, but it needs a separate identity provider for OAuth2 or SSO.
Kanidm as an alternative
Listings that name Kanidm as an alternative.
389 Directory Server
An open-source LDAP directory server for Linux with multi-supplier replication.
Kanidm combines LDAP with OAuth2 and passkey login in one open-source server, though its ecosystem is smaller than long-established directory servers.
FusionAuth
An identity and user management server with SSO, MFA and OAuth2 that can be self-hosted.
Kanidm is an open-source identity server with OAuth2, LDAP and passkeys plus Linux login integration, aimed more at self-hosters than app developers.
OpenLDAP
Open-source implementation of LDAP, with a directory server, a load balancer, client libraries and tools.
Kanidm offers LDAP alongside OAuth2 and passkeys in one server with Unix login integration, but has a smaller ecosystem than long-established directory servers.
privacyIDEA
Open-source, self-hosted multi-factor authentication server that manages OTP and other token types.
Kanidm provides passkey login, RADIUS support and LDAP in one open-source server rather than managing many OTP token types.
Similar software
Related functionality, not necessarily a direct replacement.
Pomerium
An identity-aware reverse proxy that gives secure access to internal applications without a VPN.
phpLDAPadmin
A web-based LDAP administration tool for browsing and editing directory entries from a browser.
Samba
Open-source SMB file and print server that can also run as an Active Directory domain controller.