Przejdź do głównej zawartości

Feature comparison

This page compares the four most common self-hosted, open-source identity providers feature by feature. Each row was checked against the projects' own documentation in October 2026 (Casdoor v4.17, Keycloak 26.8, ZITADEL v4, authentik 2026.x); the sources are listed at the end. Projects ship new features often, so check the other project's documentation for anything that decides your choice, and tell us if a row is out of date.

Overview​

CasdoorKeycloakZITADELauthentik
LanguageGo, React UIJava (Quarkus)Go, TypeScript login UIPython and Go
LicenseApache-2.0Apache-2.0AGPL-3.0MIT core, enterprise features under a commercial license
DatabasesMySQL, MariaDB, PostgreSQL, SQL Server, Oracle, SQLite, TiDB, CockroachDBPostgreSQL, MySQL, MariaDB, SQL Server, OraclePostgreSQLPostgreSQL
Multi-tenancyOrganizations, each with its own users, applications, providers, and rolesRealms, plus Organizations inside a realmInstances, and organizations inside an instanceBrands for separate branding; separate tenants are an alpha enterprise feature

Protocols​

CasdoorKeycloakZITADELauthentik
OAuth 2.0 / OIDC providerYesYesYesYes
SAML 2.0 identity providerYesYesYesYes
Sign in through external SAML / OIDC providersYesYesYesYes
CAS serverBuilt inCommunity extensionNoNo
LDAP server (applications bind to the IdP)Built inNoNoLDAP outpost
RADIUS serverBuilt inCommunity extensionNoRADIUS outpost
MCP server and OAuth 2.1 for MCPBuilt inNo built-in MCP serverNo built-in MCP serverNo built-in MCP server

Users and directories​

CasdoorKeycloakZITADELauthentik
LDAP / Active Directory as user sourceSync users, check passwords against LDAPUser federation, live lookupsLDAP identity provider, users created on first loginLDAP source, sync and password checks
SCIM 2.0 server (receive users from Entra ID, Okta, ...)Users and groupsUsers and groups, supported since 26.8Users, previewUsers and groups (SCIM source)
SCIM client (push users to other applications)No; the SCIM syncer pulls users from a SCIM serverNoNoYes (SCIM provider)
Import from other systemsSyncers for Keycloak, Okta, Entra ID, Active Directory, Google Workspace, AWS IAM, DingTalk, WeCom, Lark, any SQL databaseRealm import, LDAP federationImport API, LDAPSources for LDAP, SCIM, and social logins

Applications without their own login​

CasdoorKeycloakZITADELauthentik
Forward auth for reverse proxiescasdoor-forward-auth for Traefik, Caddy, and NginxNo; use OAuth2 ProxyNo; use OAuth2 ProxyProxy provider for Traefik, Caddy, Nginx, and Envoy
Groups and roles passed to the applicationX-Forwarded-Groups, X-Forwarded-Roles headersThrough OAuth2 ProxyThrough OAuth2 ProxyHeaders set by the outpost
Works with OAuth2 ProxyYes, including group and role checksYesYesYes

Sign-in experience​

CasdoorKeycloakZITADELauthentik
Login page customizationPer application in the admin console: fields, providers, layout, CSS, and HTML (UI customization)Themes (FreeMarker or React) deployed to the serverBranding settings, or your own login UI built on its APIsFlows and stages edited in the admin interface
Custom sign-in logicWebhooks and the REST APIAuthentication flows, Java SPIsActions (scripts and webhooks)Flows, stages, and Python expression policies
Built-in social and enterprise providers70+, including WeChat, DingTalk, Lark, and AlipayAbout a dozen, plus generic OIDC and SAMLTemplates for common providers, plus generic OIDC, OAuth, SAML, and LDAPApple, Discord, GitHub, Google, Twitch, and others, plus generic OIDC, OAuth, and SAML

Of the four, authentik has the most flexible sign-in flow engine, and Keycloak the most extension points for Java developers. Casdoor keeps the login page in configuration rather than code, and moves custom logic into your own services through webhooks and the API.

Operations​

CasdoorKeycloakZITADELauthentik
KubernetesHelm chartOperatorHelm chartHelm chart
Horizontal scalingMultiple replicas, with Redis for sessionsClustering with Infinispan, multi-siteStateless replicasMultiple server and worker replicas
Infrastructure as codeTerraform providerTerraform providerTerraform providerTerraform provider
Declarative config fileInit data (JSON or YAML, also as Helm values), applied again when it changesRealm import (JSON) at startupSetup steps for the first instance onlyBlueprints (YAML), applied again when they change
Audit logRecords of every API call, with retention settings and webhooksLogin and admin eventsEvent-sourced: every change is stored as an eventEvents, with notification rules

Sources​