ZITADEL
A cloud-native, API-first identity platform with a generous self-hosted core.
82
sovereigntyZITADEL is a modern identity and access management platform built API-first for cloud-native and multi-tenant SaaS use cases. It supports OIDC, SAML, passkeys/WebAuthn, and fine-grained actions/hooks for customizing the auth flow in code, and offers both a managed cloud and a self-hostable core.
OPEN SOURCEAGPL-3.0SELF-HOSTLOCAL-FIRST
LicenseAGPL-3.0
PricingFree / self-host under AGPL-3.0; ZITADEL Cloud offers a managed free tier plus paid usage-based plans for teams that don't want to run the server themselves.
Open sourceYes
Self-hostableYes
Local-first dataYes
What it does well
- +Strong native support for passkeys/WebAuthn and modern passwordless flows out of the box
- +API-first design and 'Actions' hooks make custom auth logic (e.g. custom claims, external calls during login) straightforward without forking the codebase
- +Built for multi-tenancy (organizations/projects) from the ground up, closer to Auth0's B2B model than most self-hosted options
- +Active development with frequent releases and a responsive open-source community
Where it falls short
- −AGPL-3.0 requires that any modified version offered as a network service also be released under AGPL — a real legal consideration for SaaS companies embedding it
- −Younger project than Keycloak with a smaller track record at very large scale
- −Some advanced features are positioned toward the paid ZITADEL Cloud tier rather than the self-hosted core
ZITADEL as an alternative to
Where ZITADEL shows up in our comparisons, and how it ranked.
ZITADEL head-to-head
Straight comparisons against the tools people weigh it against.