opensourcestartups

> /v1/collections/hold-your-own-keys

Hold Your Own Keys

Identity is the one vendor you cannot switch on a bad Tuesday, which is why Okta, Auth0 and their pricing pages are so confident. Keycloak, Authentik, Better Auth and Zitadel handle login and SSO; Vault, Infisical, Bitwarden and KeePassXC handle secrets; Tailscale, Netbird and Firezone handle the perimeter. Own all three and the lock-in disappears.

14 tools replaced · 17 open source projects · 385.1k combined GitHub stars

Okta provides cloud identity and access management with single sign-on, multi-factor authentication and user provisioning.

// TAKE · Keycloak is the closest like-for-like, with SAML, OIDC, federation and an admin console enterprises already recognise, at the cost of heavy JVM operations. Zitadel and Authentik reach a similar feature set with far less overhead, Authentik especially for internal app SSO, while Better Auth is a framework you build login into and Ory Hydra expects you to supply the user management around it.

Auth0 provides hosted authentication and authorization: social and enterprise SSO, MFA, user management and OAuth/OIDC tokens.

// TAKE · Keycloak is the closest feature-for-feature replacement and the safest bet for enterprise SSO, SAML and fine-grained realms, but it is heavy and its admin model takes real time to learn. Zitadel and Logto give you a far better developer experience with multi-tenancy built in, while Better Auth is a library rather than an identity server, so choose it only if you want auth living inside your own app.

AWS Cognito provides managed user pools, federated identity and OAuth token issuance for signing users into AWS-hosted applications.

// TAKE · SuperTokens aims squarely at this migration and is the least painful landing spot if you mostly used Cognito user pools with a hosted login page. Keycloak is the stronger choice once you need SAML federation, group-based access and long-term stability, while Zitadel sits between them with per-tenant isolation and an API that will feel familiar after Cognito's.

Clerk provides drop-in authentication and user management with prebuilt UI components, sessions, MFA and organisations.

// TAKE · Better Auth is the closest on developer experience for TypeScript apps, though you assemble the login UI that Clerk hands you ready-made. Zitadel and Logto are better when you want a full identity server with organisations, multi-tenancy and hosted login pages, while Ory Hydra is only the OAuth and OIDC piece.

WorkOS provides enterprise auth building blocks such as SSO, SCIM directory sync, audit logs and RBAC behind a single developer API.

// TAKE · Zitadel is the closest match to WorkOS's B2B model, with first-class organisations, SAML and OIDC, audit trails and an API-first design, while Keycloak covers the same enterprise protocols with far more deployment history but a heavier Java stack and a clunkier admin console. Better Auth is a different shape entirely, a TypeScript library you embed rather than a service you operate, which is the right trade only if you need login for one app and not directory sync.

Stytch provides authentication APIs for passwordless login, passkeys, OAuth, MFA and fraud prevention.

// TAKE · Better Auth is the closest fit for developers who want Stytch's API-first feel inside a TypeScript codebase, with passkeys and MFA available as plugins. Hanko is the sharpest passwordless option on its own, while Keycloak, Authentik and Logto are full identity servers that hand you far more than Stytch does but expect you to run and tune them.

LastPass stores and autofills passwords across browsers and devices, with sharing, generation and encrypted vault sync.

// TAKE · Bitwarden is the obvious swap, with the same browser and mobile autofill, shared vaults and a server you can host yourself. KeePassXC is more secure by construction but leaves sync entirely to you, and Passbolt is built for teams sharing credentials rather than individuals.

Dashlane is a password manager with an encrypted vault, browser autofill, credential sharing and admin controls for teams.

// TAKE · Bitwarden is the direct replacement, with browser and mobile clients, sharing and an admin console that map almost one for one onto Dashlane's team plan. KeePassXC is stronger if you want no server at all, just a local encrypted file you sync yourself, and Passbolt is built specifically around team credential sharing with per-user keys, whereas Vault solves a different problem and belongs in your infrastructure rather than your browser.

Keeper is an encrypted password manager and secrets vault for teams, with sharing, role-based access, SSO and audit reporting.

// TAKE · Bitwarden is the closest replacement for the human side of Keeper, with a comparable organisation and collection sharing model plus solid clients on every platform. Passbolt suits teams that want granular per-password permissions and a self-hosted-first design, KeePassXC really fits individuals happy to sync a file themselves, and Vault or Infisical solve machine secrets rather than team passwords.

Doppler provides centralised secrets and environment variable management, syncing config into apps, environments and CI pipelines.

// TAKE · Infisical is the closest match to Doppler's workflow of syncing environment variables into apps and CI, with a comparable CLI, dashboard and integration list. Vault is far more capable with dynamic credentials, leasing and PKI, but it is an operations project in its own right, while Phase and Keyshade cover the basics with much smaller teams behind them.

Proton Pass is an end-to-end encrypted password manager with passkeys, two-factor codes and hide-my-email aliases.

// TAKE · Bitwarden is the practical replacement, with cross-platform apps, passkey support and sync you can either pay for or self-host. KeePassXC gives you the strongest local-only security model but you have to solve syncing yourself, and Passbolt is aimed at teams sharing credentials rather than individuals wanting alias-style privacy features.

Enpass is a cross-platform password manager that keeps an encrypted vault locally and syncs through your own cloud storage.

// TAKE · KeePassXC is the closest philosophical match, a local encrypted vault with no vendor account, though you supply your own sync and mobile access depends on third-party apps. Bitwarden is the pragmatic upgrade if you want polished clients and browser autofill and will run a server, and PearPass is the one to watch for peer-to-peer sync with no server at all.

Twingate provides zero trust remote access to private apps and networks without exposing a whole network over a traditional VPN.

// TAKE · Netbird is the closest, combining a WireGuard mesh with identity-provider login and per-resource access policies, and unlike Tailscale you can self-host the control plane as well as the clients. Firezone is the leaner choice if you mainly want policy-driven gateway access, and Pangolin is better suited to exposing self-hosted services through a tunnel than to managing a fleet of employee devices.

Zerotier builds encrypted peer-to-peer virtual networks so devices scattered across the internet behave as if they share one LAN.

// TAKE · Netbird is the closest true replacement: WireGuard overlay networking with a self-hostable control plane and access policies, which is exactly what people leave ZeroTier's hosted controller for. Tailscale's clients are open but its coordination server is not, so self-hosting means giving that piece up, and Firezone targets gateway-style access to specific resources rather than a flat peer-to-peer network.