Authgear, an open source authentication server and identity provider that adds sign in, passkeys, multi factor authentication and single sign on to your apps from one place.
Authgear is an open source authentication server and identity provider that lets you add secure sign in to web and mobile applications without building it yourself. It implements the OpenID Connect and OAuth 2 standards, so applications delegate authentication to Authgear and receive standard tokens back. Out of the box it supports passwords, passwordless email and SMS one time codes, passkeys and biometric login, social and enterprise sign in, and multi factor authentication with authenticator apps, so you can offer modern, phishing resistant login without stitching together separate services.
Beyond login it manages the whole identity lifecycle: user directories, sessions and device management, sign in and sign up flows, roles and groups, and single sign on across every application that trusts it. An admin portal gives operators a place to configure providers, inspect users and sessions and tune security policy, while first party SDKs and a GraphQL admin API let developers integrate and automate. It suits teams who want to own their identity layer, consolidate logins behind one provider, and meet security and compliance needs with modern authentication.
cloudimg delivers Authgear as a complete, secure by default appliance: the pinned upstream authentication server and admin portal run the moment the instance boots, backed by a self contained local PostgreSQL database and Redis, with no container registry to reach or compose file to assemble. It is secure by default: on the first boot of every instance unique database and Redis passwords, a unique admin API key and fresh cryptographic signing keys are generated and written to a root only file, so no two instances ever share a secret and no default credential is ever shipped. The server learns its own public address on every boot so the endpoints and portal work without hand editing, the datastore is captured empty and re provisioned per instance, the base is fully patched with unattended security upgrades enabled, and every deployment comes with a paired deploy guide and 24/7 cloudimg support.
Real screenshots taken while testing this image against its deployment guide.