Logto
Logto is an open source authentication and identity platform you can self-host — an Auth0, Okta, and Clerk alternative that gives you OIDC, OAuth 2.1, SAML, passwordless, social login, MFA, and multi-tenant organizations behind developer-friendly SDKs.
What is Logto?
Logto is an open source authentication and identity platform that handles sign-in, single sign-on, and user management for your apps and APIs. Built in TypeScript with a PostgreSQL backend, it gives you standards-based OIDC, OAuth 2.1, and SAML, prebuilt sign-in UIs, and SDKs for 30+ frameworks — as a service you self-host or run on Logto Cloud.
What is Logto best for?
Logto is best for developers and startups building SaaS, B2B, or AI products who want a modern auth stack — passwordless, social login, MFA, and multi-tenant organizations — without wiring it together from scratch or paying per active user. Its prebuilt sign-in flows and broad SDK coverage make it a fast drop-in for teams that would otherwise reach for a hosted identity provider.
What can Logto do?
- Standards-based auth — OIDC, OAuth 2.1, and SAML, so it works as an identity provider for third-party apps too.
- Passwordless and social sign-in — email and SMS verification codes, Google One Tap, plus Google, Apple, Discord, and other social connectors.
- Multi-factor auth — WebAuthn/passkeys, authenticator-app TOTP, and backup codes.
- Multi-tenancy via Organizations — organization-level RBAC, member invites, and just-in-time provisioning for B2B apps.
- Enterprise SSO — connect Okta, Microsoft Entra, and generic SAML/OIDC identity providers.
- Machine-to-machine auth — service credentials and access tokens for APIs and microservices.
- Prebuilt, customizable UI — hosted sign-up, sign-in, and account center flows, plus SDKs for React, Next.js, Vue, Angular, Go, Python, Swift, and more.
Where does Logto fall short?
- It’s younger and smaller than the incumbents, so the ecosystem of third-party guides, community extensions, and battle-tested edge-case integrations is thinner than Auth0’s or Keycloak’s.
- Deep customization of the sign-in experience runs through Logto’s configuration and APIs rather than a pluggable extension model, so highly bespoke auth logic can be harder to graft on than with Keycloak’s SPI system.
- On Logto Cloud, features like MFA, enterprise SSO, and Organizations are paid add-ons rather than being included in the base plan — a real cost consideration if you don’t self-host.
Is Logto free?
Yes — self-hosting Logto is free and open source under MPL-2.0, and the self-hosted build includes the full feature set (MFA, SSO, Organizations, and M2M) with no per-feature gating; you pay only for your own server. Logto Cloud, the managed option, has a free tier (up to 50,000 monthly active users), a Pro plan from $24/month with usage-based token pricing, and custom Enterprise pricing — with several advanced features billed as add-ons.
What does Logto replace?
Logto is a self-hostable stand-in for hosted identity providers — an Auth0 alternative, an Okta alternative, a Clerk alternative, and a Firebase Authentication alternative. It covers the same core ground — sign-in flows, social and enterprise login, MFA, and user management — while keeping your identity data and deployment under your control. Among open source options it competes most directly with Zitadel, Keycloak, and SuperTokens.
FAQ
Is Logto open source? Yes. The core platform is on GitHub under the MPL-2.0 license, which is OSI-approved and permissive enough to self-host and use commercially.
Can I self-host Logto for free? Yes. Self-hosting is free under MPL-2.0 and includes the full feature set. You provide the infrastructure — Logto plus a PostgreSQL database, via Docker Compose or Node.js — and pay only for hosting.
Is Logto a good Auth0 alternative? For teams that want modern passwordless flows, multi-tenant organizations, and no per-active-user pricing, yes. Auth0 still leads on breadth of prebuilt integrations, marketplace extensions, and enterprise track record.
What do I need to run Logto? A PostgreSQL database and either Docker (Docker Compose) or Node.js. The stack is lightweight, and the same open-source build powers both local development and production.