~/tools/pocket-id
Pocket ID
tool

Pocket ID

Pocket ID is an open source, self-hosted OpenID Connect (OIDC) identity provider built around passkeys — an Auth0 and Okta alternative that gives every app you run one passwordless login, with no per-user cloud pricing.

What is Pocket ID?

Pocket ID is an open source identity provider that lets users sign in to your applications with passkeys instead of passwords. It’s a certified OpenID Connect (OIDC) and OAuth 2.0 server you self-host, so every app you connect gets one consistent, passwordless login backed by WebAuthn.

What is Pocket ID best for?

Homelabs, small teams, and developers who want modern single sign-on across their self-hosted apps without running a heavy identity platform. It fits people who have already adopted passkeys and want one clean login for their tools, dashboards, and APIs — not enterprises that need SAML or complex authorization policies.

What can Pocket ID do?

  • Sign users in with passkeys (WebAuthn), including hardware keys like a YubiKey — no passwords stored anywhere
  • Act as a certified OpenID Connect and OAuth 2.0 provider, so any OIDC-compatible app can use it for single sign-on
  • Sync users and groups from LDAP, and restrict access to each app by user group
  • Onboard people flexibly: create accounts manually, share one-time signup links, or allow open registration
  • Issue one-time login codes so users can sign in from a device that doesn’t have their passkey
  • Give you a REST API, global and per-user audit logs, and email alerts when an unknown device signs in
  • Run as a single Docker container or binary with a built-in SQLite database (PostgreSQL optional)

Where does Pocket ID fall short?

  • It’s passkey-only by design. There’s no password or TOTP login — the one-time code is an escape hatch, not a fallback method — so it’s the wrong fit if your users can’t or won’t use passkeys yet.
  • It’s deliberately minimal. Pocket ID is an OIDC/OAuth 2.0 provider without SAML or a fine-grained policy engine, so complex enterprise access rules outgrow it — that’s where heavier tools like Keycloak or Authentik fit.
  • Passkeys require HTTPS on a real domain to work at all, so a TLS reverse proxy is mandatory — you can’t run it on plain http://localhost for real use the way you might trial other apps.

Is Pocket ID free?

Yes — Pocket ID is fully free and open source under the BSD-2-Clause license, with no paid tier and no managed cloud to upsell. You only pay for the server it runs on, and because it ships with an embedded SQLite database, there’s no separate database bill either.

What does Pocket ID replace?

Pocket ID is a self-hosted alternative to hosted identity platforms like Auth0 and Okta. It covers the core job — being the login provider your apps trust — without per-active-user pricing or sending your directory to someone else’s cloud. Among open source options, it’s a lighter, passkey-first counterpart to Authelia and Authentik.

FAQ

Is Pocket ID open source? Yes. It’s released under the BSD-2-Clause license, an OSI-approved open source license, and the full backend (Go) and frontend (SvelteKit) are public on GitHub.

Can I self-host Pocket ID for free? Yes. Self-hosting is free and there’s no paid edition. It runs as one Docker container with a built-in SQLite database, so you only need a small server — it’s light enough for a modest VPS.

Is Pocket ID a good Auth0 or Okta alternative? For self-hosted, passkey-based single sign-on across your own apps, yes — you get an OIDC provider you control with no per-user fees. If you need SAML, enterprise directory integrations, or complex authorization policies, a heavier platform is the better fit.

What do I need to run Pocket ID? A server with Docker and a reverse proxy that serves it over HTTPS on a real domain, since WebAuthn (passkeys) requires a secure origin. SQLite is built in; PostgreSQL is optional if you’d rather use it.