Feature comparison
This page compares the four most common self-hosted, open-source identity providers feature by feature. Each row was checked against the projects' own documentation in October 2026 (Casdoor v4.17, Keycloak 26.8, ZITADEL v4, authentik 2026.x); the sources are listed at the end. Projects ship new features often, so check the other project's documentation for anything that decides your choice, and tell us if a row is out of date.
Overview
| Casdoor | Keycloak | ZITADEL | authentik | |
|---|---|---|---|---|
| Language | Go, React UI | Java (Quarkus) | Go, TypeScript login UI | Python and Go |
| License | Apache-2.0 | Apache-2.0 | AGPL-3.0 | MIT core, enterprise features under a commercial license |
| Databases | MySQL, MariaDB, PostgreSQL, SQL Server, Oracle, SQLite, TiDB, CockroachDB | PostgreSQL, MySQL, MariaDB, SQL Server, Oracle | PostgreSQL | PostgreSQL |
| Multi-tenancy | Organizations, each with its own users, applications, providers, and roles | Realms, plus Organizations inside a realm | Instances, and organizations inside an instance | Brands for separate branding; separate tenants are an alpha enterprise feature |
Protocols
| Casdoor | Keycloak | ZITADEL | authentik | |
|---|---|---|---|---|
| OAuth 2.0 / OIDC provider | Yes | Yes | Yes | Yes |
| SAML 2.0 identity provider | Yes | Yes | Yes | Yes |
| Sign in through external SAML / OIDC providers | Yes | Yes | Yes | Yes |
| CAS server | Built in | Community extension | No | No |
| LDAP server (applications bind to the IdP) | Built in | No | No | LDAP outpost |
| RADIUS server | Built in | Community extension | No | RADIUS outpost |
| MCP server and OAuth 2.1 for MCP | Built in | No built-in MCP server | No built-in MCP server | No built-in MCP server |
Users and directories
| Casdoor | Keycloak | ZITADEL | authentik | |
|---|---|---|---|---|
| LDAP / Active Directory as user source | Sync users, check passwords against LDAP | User federation, live lookups | LDAP identity provider, users created on first login | LDAP source, sync and password checks |
| SCIM 2.0 server (receive users from Entra ID, Okta, ...) | Users and groups | Users and groups, supported since 26.8 | Users, preview | Users and groups (SCIM source) |
| SCIM client (push users to other applications) | No; the SCIM syncer pulls users from a SCIM server | No | No | Yes (SCIM provider) |
| Import from other systems | Syncers for Keycloak, Okta, Entra ID, Active Directory, Google Workspace, AWS IAM, DingTalk, WeCom, Lark, any SQL database | Realm import, LDAP federation | Import API, LDAP | Sources for LDAP, SCIM, and social logins |
Applications without their own login
| Casdoor | Keycloak | ZITADEL | authentik | |
|---|---|---|---|---|
| Forward auth for reverse proxies | casdoor-forward-auth for Traefik, Caddy, and Nginx | No; use OAuth2 Proxy | No; use OAuth2 Proxy | Proxy provider for Traefik, Caddy, Nginx, and Envoy |
| Groups and roles passed to the application | X-Forwarded-Groups, X-Forwarded-Roles headers | Through OAuth2 Proxy | Through OAuth2 Proxy | Headers set by the outpost |
| Works with OAuth2 Proxy | Yes, including group and role checks | Yes | Yes | Yes |
Sign-in experience
| Casdoor | Keycloak | ZITADEL | authentik | |
|---|---|---|---|---|
| Login page customization | Per application in the admin console: fields, providers, layout, CSS, and HTML (UI customization) | Themes (FreeMarker or React) deployed to the server | Branding settings, or your own login UI built on its APIs | Flows and stages edited in the admin interface |
| Custom sign-in logic | Webhooks and the REST API | Authentication flows, Java SPIs | Actions (scripts and webhooks) | Flows, stages, and Python expression policies |
| Built-in social and enterprise providers | 70+, including WeChat, DingTalk, Lark, and Alipay | About a dozen, plus generic OIDC and SAML | Templates for common providers, plus generic OIDC, OAuth, SAML, and LDAP | Apple, Discord, GitHub, Google, Twitch, and others, plus generic OIDC, OAuth, and SAML |
Of the four, authentik has the most flexible sign-in flow engine, and Keycloak the most extension points for Java developers. Casdoor keeps the login page in configuration rather than code, and moves custom logic into your own services through webhooks and the API.
Operations
| Casdoor | Keycloak | ZITADEL | authentik | |
|---|---|---|---|---|
| Kubernetes | Helm chart | Operator | Helm chart | Helm chart |
| Horizontal scaling | Multiple replicas, with Redis for sessions | Clustering with Infinispan, multi-site | Stateless replicas | Multiple server and worker replicas |
| Infrastructure as code | Terraform provider | Terraform provider | Terraform provider | Terraform provider |
| Declarative config file | Init data (JSON or YAML, also as Helm values), applied again when it changes | Realm import (JSON) at startup | Setup steps for the first instance only | Blueprints (YAML), applied again when they change |
| Audit log | Records of every API call, with retention settings and webhooks | Login and admin events | Event-sourced: every change is stored as an event | Events, with notification rules |
Sources
- Keycloak: Server administration guide, Organizations, SCIM support, Keycloak Operator, keycloak-protocol-cas, keycloak-radius-plugin, Terraform provider
- ZITADEL: License, SCIM v2.0, SAML endpoints, LDAP identity provider, OAuth2 Proxy guide, Kubernetes deployment, CockroachDB removal
- authentik: Proxy provider, Caddy forward auth, SCIM source, Tenancy, CAS