> /v1/collections/hold-your-own-keys
Hold Your Own Keys
Identity is the one vendor you cannot switch on a bad Tuesday, which is why Okta, Auth0 and their pricing pages are so confident. Keycloak, Authentik, Better Auth and Zitadel handle login and SSO; Vault, Infisical, Bitwarden and KeePassXC handle secrets; Tailscale, Netbird and Firezone handle the perimeter. Own all three and the lock-in disappears.
14 tools replaced · 17 open source projects · 385.1k combined GitHub stars
Replace Okta
ALL OKTA ALTERNATIVES →Okta provides cloud identity and access management with single sign-on, multi-factor authentication and user provisioning.
Open Source Identity and Access Management For Modern Applications and Services
Java · Apache-2.0
The authentication framework for TypeScript
TypeScript · MIT
The authentication glue you need
Python · NOASSERTION
OpenID Certified™ OpenID Connect and OAuth Provider written in Go
Go · Apache-2.0
// TAKE · Keycloak is the closest like-for-like, with SAML, OIDC, federation and an admin console enterprises already recognise, at the cost of heavy JVM operations. Zitadel and Authentik reach a similar feature set with far less overhead, Authentik especially for internal app SSO, while Better Auth is a framework you build login into and Ory Hydra expects you to supply the user management around it.
Replace Auth0
ALL AUTH0 ALTERNATIVES →Auth0 provides hosted authentication and authorization: social and enterprise SSO, MFA, user management and OAuth/OIDC tokens.
Open Source Identity and Access Management For Modern Applications and Services
Java · Apache-2.0
The authentication framework for TypeScript
TypeScript · MIT
The authentication glue you need
Python · NOASSERTION
OpenID Certified™ OpenID Connect and OAuth Provider written in Go
Go · Apache-2.0
// TAKE · Keycloak is the closest feature-for-feature replacement and the safest bet for enterprise SSO, SAML and fine-grained realms, but it is heavy and its admin model takes real time to learn. Zitadel and Logto give you a far better developer experience with multi-tenancy built in, while Better Auth is a library rather than an identity server, so choose it only if you want auth living inside your own app.
Replace AWS Cognito
ALL AWS COGNITO ALTERNATIVES →AWS Cognito provides managed user pools, federated identity and OAuth token issuance for signing users into AWS-hosted applications.
Open Source Identity and Access Management For Modern Applications and Services
Java · Apache-2.0
The authentication framework for TypeScript
TypeScript · MIT
The authentication glue you need
Python · NOASSERTION
OpenID Certified™ OpenID Connect and OAuth Provider written in Go
Go · Apache-2.0
// TAKE · SuperTokens aims squarely at this migration and is the least painful landing spot if you mostly used Cognito user pools with a hosted login page. Keycloak is the stronger choice once you need SAML federation, group-based access and long-term stability, while Zitadel sits between them with per-tenant isolation and an API that will feel familiar after Cognito's.
Replace Clerk
ALL CLERK ALTERNATIVES →Clerk provides drop-in authentication and user management with prebuilt UI components, sessions, MFA and organisations.
The authentication framework for TypeScript
TypeScript · MIT
The authentication glue you need
Python · NOASSERTION
OpenID Certified™ OpenID Connect and OAuth Provider written in Go
Go · Apache-2.0
Open source alternative to Auth0 / AWS Cognito / Firebase Auth
Java · NOASSERTION
// TAKE · Better Auth is the closest on developer experience for TypeScript apps, though you assemble the login UI that Clerk hands you ready-made. Zitadel and Logto are better when you want a full identity server with organisations, multi-tenancy and hosted login pages, while Ory Hydra is only the OAuth and OIDC piece.
Replace WorkOS
ALL WORKOS ALTERNATIVES →WorkOS provides enterprise auth building blocks such as SSO, SCIM directory sync, audit logs and RBAC behind a single developer API.
Open Source Identity and Access Management For Modern Applications and Services
Java · Apache-2.0
The authentication framework for TypeScript
TypeScript · MIT
The authentication glue you need
Python · NOASSERTION
OpenID Certified™ OpenID Connect and OAuth Provider written in Go
Go · Apache-2.0
// TAKE · Zitadel is the closest match to WorkOS's B2B model, with first-class organisations, SAML and OIDC, audit trails and an API-first design, while Keycloak covers the same enterprise protocols with far more deployment history but a heavier Java stack and a clunkier admin console. Better Auth is a different shape entirely, a TypeScript library you embed rather than a service you operate, which is the right trade only if you need login for one app and not directory sync.
Replace Stytch
ALL STYTCH ALTERNATIVES →Stytch provides authentication APIs for passwordless login, passkeys, OAuth, MFA and fraud prevention.
Open Source Identity and Access Management For Modern Applications and Services
Java · Apache-2.0
The authentication framework for TypeScript
TypeScript · MIT
The authentication glue you need
Python · NOASSERTION
OpenID Certified™ OpenID Connect and OAuth Provider written in Go
Go · Apache-2.0
// TAKE · Better Auth is the closest fit for developers who want Stytch's API-first feel inside a TypeScript codebase, with passkeys and MFA available as plugins. Hanko is the sharpest passwordless option on its own, while Keycloak, Authentik and Logto are full identity servers that hand you far more than Stytch does but expect you to run and tune them.
Replace LastPass
ALL LASTPASS ALTERNATIVES →LastPass stores and autofills passwords across browsers and devices, with sharing, generation and encrypted vault sync.
A tool for secrets management, encryption as a service, and privileged access management
Go · NOASSERTION
KeePassXC is a cross-platform community-driven port of the Windows application “KeePass Password Safe”.
C++ · NOASSERTION
Bitwarden infrastructure/backend (API, database, Docker, etc).
C# · NOASSERTION
Passbolt Community Edition (CE) API. The JSON API for the open source password manager for teams!
PHP · AGPL-3.0
// TAKE · Bitwarden is the obvious swap, with the same browser and mobile autofill, shared vaults and a server you can host yourself. KeePassXC is more secure by construction but leaves sync entirely to you, and Passbolt is built for teams sharing credentials rather than individuals.
Replace Dashlane
ALL DASHLANE ALTERNATIVES →Dashlane is a password manager with an encrypted vault, browser autofill, credential sharing and admin controls for teams.
A tool for secrets management, encryption as a service, and privileged access management
Go · NOASSERTION
KeePassXC is a cross-platform community-driven port of the Windows application “KeePass Password Safe”.
C++ · NOASSERTION
Bitwarden infrastructure/backend (API, database, Docker, etc).
C# · NOASSERTION
Passbolt Community Edition (CE) API. The JSON API for the open source password manager for teams!
PHP · AGPL-3.0
// TAKE · Bitwarden is the direct replacement, with browser and mobile clients, sharing and an admin console that map almost one for one onto Dashlane's team plan. KeePassXC is stronger if you want no server at all, just a local encrypted file you sync yourself, and Passbolt is built specifically around team credential sharing with per-user keys, whereas Vault solves a different problem and belongs in your infrastructure rather than your browser.
Replace Keeper
ALL KEEPER ALTERNATIVES →Keeper is an encrypted password manager and secrets vault for teams, with sharing, role-based access, SSO and audit reporting.
A tool for secrets management, encryption as a service, and privileged access management
Go · NOASSERTION
KeePassXC is a cross-platform community-driven port of the Windows application “KeePass Password Safe”.
C++ · NOASSERTION
Open-source secret management platform
TypeScript · NOASSERTION
Bitwarden infrastructure/backend (API, database, Docker, etc).
C# · NOASSERTION
// TAKE · Bitwarden is the closest replacement for the human side of Keeper, with a comparable organisation and collection sharing model plus solid clients on every platform. Passbolt suits teams that want granular per-password permissions and a self-hosted-first design, KeePassXC really fits individuals happy to sync a file themselves, and Vault or Infisical solve machine secrets rather than team passwords.
Replace Doppler
ALL DOPPLER ALTERNATIVES →Doppler provides centralised secrets and environment variable management, syncing config into apps, environments and CI pipelines.
A tool for secrets management, encryption as a service, and privileged access management
Go · NOASSERTION
Open-source secret management platform
TypeScript · NOASSERTION
Bitwarden infrastructure/backend (API, database, Docker, etc).
C# · NOASSERTION
Application secrets and configuration management for developers.
TypeScript · NOASSERTION
// TAKE · Infisical is the closest match to Doppler's workflow of syncing environment variables into apps and CI, with a comparable CLI, dashboard and integration list. Vault is far more capable with dynamic credentials, leasing and PKI, but it is an operations project in its own right, while Phase and Keyshade cover the basics with much smaller teams behind them.
Replace Proton Pass
ALL PROTON PASS ALTERNATIVES →Proton Pass is an end-to-end encrypted password manager with passkeys, two-factor codes and hide-my-email aliases.
KeePassXC is a cross-platform community-driven port of the Windows application “KeePass Password Safe”.
C++ · NOASSERTION
Bitwarden infrastructure/backend (API, database, Docker, etc).
C# · NOASSERTION
Passbolt Community Edition (CE) API. The JSON API for the open source password manager for teams!
PHP · AGPL-3.0
A modern, open source password manager for individuals and teams.
JavaScript · AGPL-3.0
// TAKE · Bitwarden is the practical replacement, with cross-platform apps, passkey support and sync you can either pay for or self-host. KeePassXC gives you the strongest local-only security model but you have to solve syncing yourself, and Passbolt is aimed at teams sharing credentials rather than individuals wanting alias-style privacy features.
Replace Enpass
ALL ENPASS ALTERNATIVES →Enpass is a cross-platform password manager that keeps an encrypted vault locally and syncs through your own cloud storage.
KeePassXC is a cross-platform community-driven port of the Windows application “KeePass Password Safe”.
C++ · NOASSERTION
Bitwarden infrastructure/backend (API, database, Docker, etc).
C# · NOASSERTION
Passbolt Community Edition (CE) API. The JSON API for the open source password manager for teams!
PHP · AGPL-3.0
A modern, open source password manager for individuals and teams.
JavaScript · AGPL-3.0
// TAKE · KeePassXC is the closest philosophical match, a local encrypted vault with no vendor account, though you supply your own sync and mobile access depends on third-party apps. Bitwarden is the pragmatic upgrade if you want polished clients and browser autofill and will run a server, and PearPass is the one to watch for peer-to-peer sync with no server at all.
Replace Twingate
ALL TWINGATE ALTERNATIVES →Twingate provides zero trust remote access to private apps and networks without exposing a whole network over a traditional VPN.
The easiest, most secure way to use WireGuard and 2FA.
Go · BSD-3-Clause
Connect your devices into a secure WireGuard -based overlay network with SSO, MFA and granular access controls.
Go · NOASSERTION
Identity-aware VPN and proxy for remote access to anything, anywhere.
TypeScript · NOASSERTION
OpenVPN is an open source VPN daemon
C · NOASSERTION
// TAKE · Netbird is the closest, combining a WireGuard mesh with identity-provider login and per-resource access policies, and unlike Tailscale you can self-host the control plane as well as the clients. Firezone is the leaner choice if you mainly want policy-driven gateway access, and Pangolin is better suited to exposing self-hosted services through a tunnel than to managing a fleet of employee devices.
Replace Zerotier
ALL ZEROTIER ALTERNATIVES →Zerotier builds encrypted peer-to-peer virtual networks so devices scattered across the internet behave as if they share one LAN.
The easiest, most secure way to use WireGuard and 2FA.
Go · BSD-3-Clause
Connect your devices into a secure WireGuard -based overlay network with SSO, MFA and granular access controls.
Go · NOASSERTION
Identity-aware VPN and proxy for remote access to anything, anywhere.
TypeScript · NOASSERTION
Easiest way to set up Zero Trust Access for your team
Elixir · Apache-2.0
// TAKE · Netbird is the closest true replacement: WireGuard overlay networking with a self-hostable control plane and access policies, which is exactly what people leave ZeroTier's hosted controller for. Tailscale's clients are open but its coordination server is not, so self-hosting means giving that piece up, and Firezone targets gateway-style access to specific resources rather than a flat peer-to-peer network.