Harden infrastructure security.

ZITADEL

Manage identities, SSO and permissions self-hosted, ready in 5 minutes.

256 MB minimum (< 100 MB at idle without load) RAM 1 vCPU In validation

In validation

Automatic installation for this solution is ready and currently going through our tests on a real server. Ordering will open as soon as validation is complete.

ZITADEL is an open-source IAM (Identity and Access Management) platform written in Go, designed for teams that want enterprise-grade authentication without the complexity of Keycloak. It supports OIDC, OAuth 2.0, SAML 2.0, passkeys and LDAP, with native multi-tenancy (organizations, projects, roles) suited to ISVs and B2B SaaS. Under 100 MB of RAM at idle, deployable in two containers (ZITADEL + PostgreSQL), and operational behind your reverse proxy in under 5 minutes.

Key features

Certified OIDC, OAuth 2.0 and SAML 2.0: integrate any application in minutes.
Native passkeys and WebAuthn: passwordless authentication out of the box.
Native multi-tenancy: organizations, projects and hierarchical roles, ideal for B2B SaaS.
Full web admin console: manage users, apps and security policies.
Complete gRPC and REST APIs: manage everything via code or Terraform.
Under 100 MB of RAM at idle: deployable on the smallest VPS.

When to use this solution?

1

SSO for your internal applications

Centralise authentication for all your apps (Gitea, n8n, Grafana, Nextcloud…) behind ZITADEL via OIDC. One account, one password policy.

2

Authentication for your B2B SaaS

ZITADEL's native multi-tenant model gives each of your SaaS customers their own organisation with isolated users, roles and applications.

3

Replace your cloud IdP

Migrate from Auth0, Okta or Cognito to self-hosted ZITADEL: keep your OIDC/OAuth 2.0 flows without changing your clients, and keep identity data on your own infrastructure.

Deploy ZITADEL on your VPS

Guide optimized for ServOrbit Cloud VPS.

01

Create the VPS and configure the domain

ZITADEL locks its domain at first boot — the chosen subdomain cannot change afterwards. Point your DNS (your subdomain or the free ServOrbit VPS subdomain) to the VPS IP before installing.

02

Install ZITADEL from the Marketplace

From your client area, select ZITADEL, enter your domain and click Install. The script deploys PostgreSQL 16 and ZITADEL via Docker Compose, generates secrets automatically and configures nginx as an HTTPS reverse proxy.

03

Log in to the admin console

Go to https://<your-domain>/ui/console. Sign in with the admin account and the password shown in your installation details. Start by creating your first OIDC application.

04

Create your first OIDC application

In the console, go to Projects → Create, then Add Application. Select the type (Web, Native, API) and ZITADEL automatically generates the Client ID and Client Secret for your integration.

05

Invite your first users

In Users → Create, add accounts by providing the email. ZITADEL sends an invitation and can force a password reset on first login.

Frequently asked questions

Authelia is an authentication proxy (forward-auth for nginx) without its own user management. Authentik is a full-stack IdP with many features. ZITADEL is tailored for dev teams needing enterprise-grade IAM (multi-tenant, complete APIs, Terraform provider) with a very small memory footprint.

Harden infrastructure security.

ZITADEL isn't orderable yet.

Automatic installation for this solution is ready and currently going through our tests on a real server. Ordering will open as soon as validation is complete.

Need help?

Browse our help center and FAQ, or reach our team — callback, WhatsApp or email. Support in French, English and Arabic.

Message us on WhatsAppopens in a new tab