[{"data":1,"prerenderedAt":103},["ShallowReactive",2],{"seo-verification":3,"marketplace-app-en-zitadel":6},{"google":4,"bing":5},"EycwPY2XMyTkVzas3n1ygeNJFGAH513qrMjfDljzsMQ","",{"key":7,"data":8},"marketplace-app-en-zitadel",{"slug":9,"slugs":10,"categorySlugs":11,"name":16,"description":17,"phase":18,"unavailableReason":19,"docsUrl":20,"logo":21,"github":21,"tagline":22,"longDescription":23,"features":24,"useCases":31,"steps":41,"faq":57,"specs":73,"compatibleOs":79,"relatedApps":80,"relatedPosts":99,"category":100},"zitadel",{"fr":9,"en":9,"ar":9,"es":9},{"fr":12,"en":13,"ar":14,"es":15},"cybersecurity","cybersecurity-bastion","الأمن-السيبراني-والحصن","ciberseguridad-bastion","ZITADEL","Open-source developer-first IAM platform: identity management, SSO OIDC\u002FOAuth 2.0, passkeys, and native multi-tenancy. A lightweight alternative to Keycloak for dev teams.",2,"awaiting_qa","https:\u002F\u002Fservorbit.com\u002Fblog\u002Fself-host-zitadel-vps-open-source-iam-developers",null,"Manage identities, SSO and permissions self-hosted, ready in 5 minutes.","ZITADEL is an open-source IAM (Identity and Access Management) platform written in Go, designed for teams that want enterprise-grade authentication without the complexity of Keycloak. It supports OIDC, OAuth 2.0, SAML 2.0, passkeys and LDAP, with native multi-tenancy (organizations, projects, roles) suited to ISVs and B2B SaaS. Under 100 MB of RAM at idle, deployable in two containers (ZITADEL + PostgreSQL), and operational behind your reverse proxy in under 5 minutes.",[25,26,27,28,29,30],"Certified OIDC, OAuth 2.0 and SAML 2.0: integrate any application in minutes.","Native passkeys and WebAuthn: passwordless authentication out of the box.","Native multi-tenancy: organizations, projects and hierarchical roles, ideal for B2B SaaS.","Full web admin console: manage users, apps and security policies.","Complete gRPC and REST APIs: manage everything via code or Terraform.","Under 100 MB of RAM at idle: deployable on the smallest VPS.",[32,35,38],{"title":33,"body":34},"SSO for your internal applications","Centralise authentication for all your apps (Gitea, n8n, Grafana, Nextcloud…) behind ZITADEL via OIDC. One account, one password policy.",{"title":36,"body":37},"Authentication for your B2B SaaS","ZITADEL's native multi-tenant model gives each of your SaaS customers their own organisation with isolated users, roles and applications.",{"title":39,"body":40},"Replace your cloud IdP","Migrate from Auth0, Okta or Cognito to self-hosted ZITADEL: keep your OIDC\u002FOAuth 2.0 flows without changing your clients, and keep identity data on your own infrastructure.",[42,45,48,51,54],{"title":43,"body":44},"Create the VPS and configure the domain","ZITADEL locks its domain at first boot — the chosen subdomain cannot change afterwards. Point your DNS (your subdomain or the free ServOrbit VPS subdomain) to the VPS IP before installing.",{"title":46,"body":47},"Install ZITADEL from the Marketplace","From your client area, select ZITADEL, enter your domain and click Install. The script deploys PostgreSQL 16 and ZITADEL via Docker Compose, generates secrets automatically and configures nginx as an HTTPS reverse proxy.",{"title":49,"body":50},"Log in to the admin console","Go to `https:\u002F\u002F\u003Cyour-domain>\u002Fui\u002Fconsole`. Sign in with the `admin` account and the password shown in your installation details. Start by creating your first OIDC application.",{"title":52,"body":53},"Create your first OIDC application","In the console, go to Projects → Create, then Add Application. Select the type (Web, Native, API) and ZITADEL automatically generates the Client ID and Client Secret for your integration.",{"title":55,"body":56},"Invite your first users","In Users → Create, add accounts by providing the email. ZITADEL sends an invitation and can force a password reset on first login.",[58,61,64,67,70],{"q":59,"a":60},"What is the difference between ZITADEL, Authelia and Authentik?","Authelia is an authentication proxy (forward-auth for nginx) without its own user management. Authentik is a full-stack IdP with many features. ZITADEL is tailored for dev teams needing enterprise-grade IAM (multi-tenant, complete APIs, Terraform provider) with a very small memory footprint.",{"q":62,"a":63},"Does ZITADEL require a domain?","Yes, ZITADEL requires an HTTPS domain from the first boot because the OIDC issuer is anchored to the public URL. You can use a subdomain of one of your domain names, or the free ServOrbit VPS subdomain (`{app}.{slug}.servorbit-dns.com`).",{"q":65,"a":66},"Can I change the domain after installation?","No. ZITADEL's OIDC issuer is locked at first boot. If you need a different domain, you will need to reinstall (issued tokens will be invalidated). Choose your final domain before installing.",{"q":68,"a":69},"Does ZITADEL support passkeys?","Yes, ZITADEL supports passkeys (WebAuthn\u002FFIDO2) natively, with no additional configuration. Users can authenticate without a password from any compatible device.",{"q":71,"a":72},"How do I integrate ZITADEL with an existing application?","Create an application in the ZITADEL console (Projects → Add Application), select the OIDC Web type, and retrieve the Client ID and Client Secret. Then configure your application to point to `https:\u002F\u002F\u003Cyour-domain>` as the OIDC discovery endpoint.",{"license":74,"ram":75,"cpu":76,"disk":77,"version":78},"AGPL-3.0","256 MB minimum (\u003C 100 MB at idle without load)","1 vCPU","5 GB minimum","stable",[],[81,89,94],{"name":82,"slug":83,"categorySlug":13,"categoryName":84,"categoryColor":85,"logo":86,"tagline":87,"description":88},"Authelia","authelia","Cybersecurity & Bastion","text-red-400 bg-red-500\u002F10","https:\u002F\u002Fcdn.simpleicons.org\u002Fauthelia","Add MFA, SSO and fine-grained access control in front of any app — no code changes required.","Open-source authentication and authorization gateway — add MFA, SSO and fine-grained access control in front of any app without touching its code.",{"name":90,"slug":91,"categorySlug":13,"categoryName":84,"categoryColor":85,"logo":21,"tagline":92,"description":93},"Authentik","authentik","Self-hosted Auth0 alternative — full IdP with OIDC, SAML, LDAP, passkeys and a visual flow editor.","Open-source self-hosted identity platform: manage users, SSO, OIDC\u002FSAML, passkeys and custom authentication flows — an Auth0 and Okta alternative on your VPS.",{"name":95,"slug":96,"categorySlug":13,"categoryName":84,"categoryColor":85,"logo":21,"tagline":97,"description":98},"Logto","logto","Self-hosted Auth0 alternative — user authentication in minutes. OIDC, social login, MFA, user management, SDKs for 20+ frameworks. One compose, no vendor lock-in.","Self-hosted open-source authentication platform: add login, sign-up, MFA, and user management to your apps with a few lines of code — Auth0\u002FClerk alternative, MPL-2.0, ~14 k stars.",[],{"key":101,"slug":13,"name":84,"objective":102,"icon":101,"color":85},"security","Harden infrastructure security.",1789570210368]