Use only what you need
- ✓Just gate one page behind a PIN?
— a shared PIN or passphrase, no user account required. - ✓Forward-auth in front of other apps, like TinyAuth?
— yes, via/auth/forwardor a ready-made OIDC gateway. - ✓Want an admin panel?
— built in. Prefer it inside your own? — use just the JSON API. - ✓From “a password is enough” to “OIDC → password → TOTP”?
— it grows with you; every piece optional, on/off by config. - ✓Your own look & language?
— the whole front end is replaceable (set_template), texts in English or German.
Ways to sign in
And more
login_identifierInstall
[all] pulls every optional dependency. Take only what you need:
[argon2]stronger hashing[oidc]OIDC login[saml]SAML 2.0[ldap]LDAP/AD[passkey]WebAuthn[qr]TOTP QR code[redis]rate limit across workers[gateway]forward-auth gateway (OIDC + server)
Combine them: [oidc,argon2]. Without any extra you still get password + TOTP (stdlib scrypt).
Use
Want just SSO in front of existing apps? Run it as an OIDC forward-auth gateway.
