<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>single-sign-on</title>
    <link rel="self" type="application/atom+xml" href="https://links.biapy.com/guest/tags/472/feed"/>
    <updated>2026-09-21T03:06:42+00:00</updated>
    <id>https://links.biapy.com/guest/tags/472/feed</id>
            <entry>
            <id>https://links.biapy.com/links/298</id>
            <title type="text"><![CDATA[VoidAuth]]></title>
            <link rel="alternate" href="https://voidauth.app/#/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/298"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The Single Sign-On Provider that makes securing your applications and resources easy. 
 An Easy to Use and Self-Host Single Sign-On Provider 🐈‍⬛🔒 

VoidAuth is an open-source authentication platform designed to simplify user management and securing access to your self-hosted applications and resources.

- [VoidAuth @ GitHub](https://github.com/voidauth/voidauth).]]>
            </summary>
            <updated>2025-11-05T15:45:20+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1163</id>
            <title type="text"><![CDATA[opkssh (OpenPubkey SSH)]]></title>
            <link rel="alternate" href="https://github.com/openpubkey/opkssh/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1163"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[opkssh is a tool which enables ssh to be used with OpenID Connect allowing SSH access management via identities like alice@example.com instead of long-lived SSH keys. It does not replace ssh, but rather generates ssh public keys that contain PK Tokens and configures sshd to verify the PK Token in the ssh public key. These PK Tokens contain standard OpenID Connect ID Tokens. This protocol builds on the OpenPubkey which adds user public keys to OpenID Connect without breaking compatibility with existing OpenID Provider.

Related contents:

- [Open-sourcing OpenPubkey SSH (OPKSSH): integrating single sign-on with SSH @ The Cloudflare Blog](https://blog.cloudflare.com/open-sourcing-openpubkey-ssh-opkssh-integrating-single-sign-on-with-ssh/).]]>
            </summary>
            <updated>2025-08-28T19:10:55+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1355</id>
            <title type="text"><![CDATA[Pocket ID]]></title>
            <link rel="alternate" href="https://pocket-id.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1355"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A simple and easy-to-use OIDC provider that allows users to authenticate with their passkeys to your services. 

- [Pocket ID @ GitHub](https://github.com/pocket-id/pocket-id).

Related contents:

- [DITCH PASSWORDS: Self-Host PassKeys with Pocket ID @ Techdox&amp;#039;s YouTube](https://www.youtube.com/watch?v=GKyMXguNcos).
- [Episode 650: This Old Network @ Linux Unplugged](https://linuxunplugged.com/650).
- [Pocket ID - L&amp;#039;auth par passkey pour votre homelab @ Korben :fr:](https://korben.info/pocket-id-auth-oidc-passkey.html).
- [Protect your MCP Server with OAuth 2.1 in just 5 minutes with Pocket ID @ Pocket ID&amp;#039;s YouTube](https://www.youtube.com/watch?v=JjoXz2u5r3Y).]]>
            </summary>
            <updated>2026-08-21T12:41:53+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3760</id>
            <title type="text"><![CDATA[Pocket ID]]></title>
            <link rel="alternate" href="https://github.com/stonith404/pocket-id" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3760"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A simple OIDC provider that allows users to authenticate with their passkeys to your services.]]>
            </summary>
            <updated>2025-08-29T02:23:29+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3766</id>
            <title type="text"><![CDATA[django-allauth]]></title>
            <link rel="alternate" href="https://allauth.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3766"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Integrated set of Django applications addressing authentication, registration, account management as well as 3rd party (social) account authentication. 
   
A free, secure, well integrated, reusable authentication solution for the Django framework, covering all functionality related to local and social user accounts, multi-factor authentication, in various configurations, with flows that just work.

- [django-allauth @ GitHub](https://github.com/pennersr/django-allauth).]]>
            </summary>
            <updated>2025-08-29T02:25:31+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3788</id>
            <title type="text"><![CDATA[NetBird]]></title>
            <link rel="alternate" href="https://netbird.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3788"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Connect and Secure Your IT Infrastructure in Minutes.
Connect your devices into a secure WireGuard®-based overlay network with SSO, MFA and granular access controls. 
NetBird combines a configuration-free peer-to-peer private network and a centralized access control system in a single open-source platform, making it easy to create secure private networks for your organization or home.

- [NetBird @ GitHub](https://github.com/netbirdio/netbird).

Related contents:

- [Episode 575: Brent&amp;#039;s Busted Builds @ Linux Unplugged](https://linuxunplugged.com/575).
- [Ep 13: Cyberdeck Cyberwhat Selfhosted VPN networks and is Wireguard Hard @ Linux Prepper](https://podcast.james.network/@linuxprepper/episodes/cyberdeck-cyberwhat)
  ([Episode 13 Shownotes - Cyberdeck Cyberwhat and is Wireguard Hard @ Learning Together](https://discuss.james.network/public/d/69-episode-13-shownotes-cyberdeck-cyberwhat-and-is-wireguard-hard)).
- [NetBird : VPN mesh WireGuard auto-hébergé et souverain @ DevSecOps :fr:](https://blog.stephane-robert.info/docs/securiser/acces/netbird/).
- [How I Use NetBird to Connect My Entire Network @ Techdox&amp;#039;s  YouTube](https://www.youtube.com/watch?v=7PY3qOyRREo).]]>
            </summary>
            <updated>2026-09-01T17:43:33+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3961</id>
            <title type="text"><![CDATA[Vouch Proxy]]></title>
            <link rel="alternate" href="https://github.com/vouch/vouch-proxy" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3961"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[an SSO and OAuth / OIDC login solution for Nginx using the auth_request module.

An SSO solution for Nginx using the auth_request module. Vouch Proxy can protect all of your websites at once.

Vouch Proxy supports many OAuth and OIDC login providers and can enforce authentication]]>
            </summary>
            <updated>2025-08-29T02:57:50+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4530</id>
            <title type="text"><![CDATA[OpenPubkey]]></title>
            <link rel="alternate" href="https://www.bastionzero.com/openpubkey" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4530"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[OpenPubkey is an open source project that binds public keys and workload identities using standard SSO and OpenID Connect.

Use OpenPubkey today to SSH to machines on your network without SSH keys.

- [OpenPubkey @ GitHub](https://github.com/openpubkey/openpubkey).
- [OpenPubkey: Augmenting OpenID Connect with User held Signing Keys @ Cryptology ePrint Archive](https://eprint.iacr.org/2023/296).
- [How to Use OpenPubkey to Solve Key Management via SSO @ Docker Blog](https://www.docker.com/blog/how-to-use-openpubkey-to-solve-key-management-via-sso/).]]>
            </summary>
            <updated>2025-08-29T04:31:38+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4920</id>
            <title type="text"><![CDATA[FreeIPA]]></title>
            <link rel="alternate" href="https://www.freeipa.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4920"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Identity, Policy, Audit.

Manage Linux users and client hosts in your realm from one central location with CLI, Web UI or RPC access. Enable Single Sign On authentication for all your systems, services and applications.

- [FreeIPA @ Pagure](https://pagure.io/freeipa).

Related contents:

- [Installation le gestionnaire d&amp;#039;identité FreeIPA @ DevSecOps :fr:](https://blog.stephane-robert.info/post/gitlab-secure-server-freeipa/).]]>
            </summary>
            <updated>2025-12-09T09:09:05+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5042</id>
            <title type="text"><![CDATA[glpi-singlesignon]]></title>
            <link rel="alternate" href="https://github.com/edgardmessias/glpi-singlesignon" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5042"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Single sign-on (SSO) is a property of access control of multiple related, yet independent, software systems. With this property, a user logs in with a single ID and password to gain access to any of several related systems.]]>
            </summary>
            <updated>2025-08-29T05:57:20+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5778</id>
            <title type="text"><![CDATA[Traefik Forward Auth]]></title>
            <link rel="alternate" href="https://github.com/thomseddon/traefik-forward-auth" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5778"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Minimal forward authentication service that provides Google/OpenID oauth based login and authentication for the traefik reverse proxy.

A minimal forward authentication service that provides OAuth/SSO login and authentication for the traefik reverse proxy/load balancer.]]>
            </summary>
            <updated>2025-08-29T08:00:31+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6779</id>
            <title type="text"><![CDATA[Keycloak]]></title>
            <link rel="alternate" href="https://www.keycloak.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6779"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Open Source Identity and Access Management.
Add authentication to applications and secure services with minimum effort.
No need to deal with storing users or authenticating users.
Keycloak provides user federation, strong authentication, user management, fine-grained authorization, and more. 

- [Keycloak @ GitHub](https://github.com/keycloak/keycloak).

Related contents:

- [Deploy Keycloak Single Sign-On With Ansible @ DZone](https://dzone.com/articles/deploy-keycloak-single-sign-on-with-ansible).
- [Building trust with OpenID Federation trust chain on Keycloak @ Cloud Native Computing Foundation](https://www.cncf.io/blog/2025/04/25/building-trust-with-openid-federation-trust-chain-on-keycloak/).
- [Keycloak vs Ory @ Cerbos](https://www.cerbos.dev/blog/keycloak-vs-ory).]]>
            </summary>
            <updated>2026-09-14T05:52:36+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6780</id>
            <title type="text"><![CDATA[authentik]]></title>
            <link rel="alternate" href="https://goauthentik.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6780"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Making authentication simple.

authentik is an open-source Identity Provider focused on flexibility and versatility.
It can be seamlessly integrated into existing environments to support new protocols.
authentik is also a great solution for implementing sign-up, recovery,
and other similar features in your application, saving you the hassle of dealing with them.

- [authentik @ GitHub](https://github.com/goauthentik/authentik).

Sources:

- [GoAuthentik de A à Y @ Une tasse de café :fr:](https://une-tasse-de.cafe/blog/goauthentik/).
- [La veille des Ours n°31 @ Bearstech&amp;#039;s LinkedIn :fr:](https://www.linkedin.com/pulse/la-veille-des-ours-n31-bearstech-gbmgf/).
- [Ultimate Authentik Docker Compose Guide with Traefik 2025 @ SmartHomeBeginner](https://www.smarthomebeginner.com/authentik-docker-compose-guide-2025/).
- [Improving Security with Hardware Keys - Authentik &amp;amp; Pocket-ID @ Jim&amp;#039;s Garage&amp;#039;s YouTube](https://www.youtube.com/watch?v=QC5IUmu7cgw).
- [Secure Jellyfin with Authentik (SSO + LDAP + 2FA/MFA Tutorial) @ IBRACORP&amp;#039;s YouTube](https://www.youtube.com/watch?v=WvXXKNyB0ig).
- [Manage Authentik Resources in Terraform @ Christian Lempa&amp;#039;s YouTube](https://www.youtube.com/watch?v=R6koN4ZmbOY).
- [Highly Available Authentication - Set It Up NOW! @ Jim&amp;#039;s Garage&amp;#039;s YouTube](https://www.youtube.com/watch?v=-6zTZAKR_nk).]]>
            </summary>
            <updated>2026-08-07T12:49:51+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/7125</id>
            <title type="text"><![CDATA[Authelia]]></title>
            <link rel="alternate" href="https://www.authelia.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/7125"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Authentication server providing two-factor and SSO.
Protect your applications with Single Sign-On and 2 Factor.
Authelia is an open-source full-featured authentication server available on Github .

- [Authelia @ GitHub](https://github.com/authelia/authelia).

Related contents:

- [Authelia — Self-hosted Single Sign-On (SSO) for your homelab services @ Akash Rajpurohit](https://akashrajpurohit.com/blog/setup-authelia-for-sso-authentication/).
- [Episode \#125: The state of homelab tech (2026) @ Changelog &amp;amp; Friends](https://changelog.com/friends/125).]]>
            </summary>
            <updated>2026-01-27T07:19:15+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/8759</id>
            <title type="text"><![CDATA[Shibboleth - Home]]></title>
            <link rel="alternate" href="http://shibboleth.net/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/8759"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Shibboleth is among the world&amp;#039;s most widely deployed federated identity solutions, connecting users to applications both within and between organizations. Every software component of the Shibboleth system is free and open source.]]>
            </summary>
            <updated>2025-08-29T16:17:56+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/8760</id>
            <title type="text"><![CDATA[cosign: web single sign-on]]></title>
            <link rel="alternate" href="http://weblogin.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/8760"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[An open source project originally designed to provide the University of Michigan with a secure single sign-on web authentication system. cosign is part of the National Science Foundation Middleware Initiative (NMI) EDIT software release.]]>
            </summary>
            <updated>2025-08-29T16:17:57+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/8762</id>
            <title type="text"><![CDATA[mod_auth_pubtkt: a pragmatic Web Single Sign-On (SSO) solution]]></title>
            <link rel="alternate" href="https://neon1.net/mod_auth_pubtkt" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/8762"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[mod_auth_pubtkt is an Apache module that authenticates a user based on a cookie with a ticket that has been issued by a central login server and digitally signed using either RSA or DSA. This means that only the trusted login server has the private key required to generate tickets, while web servers only need the corresponding public key to verify them.

Whenever mod_auth_pubtkt encounters a request without a valid ticket/cookie, it redirects the user to a pre-configured login URL, passing the originally requested URL as a GET parameter. The login server can then prompt the user for credentials, verify them using any authentication backend it chooses, and upon success, generate a login ticket (signed with its private key), return it in a cookie to the client, and finally redirect the user back to the originally requested URL.]]>
            </summary>
            <updated>2025-08-29T16:17:58+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/8763</id>
            <title type="text"><![CDATA[Open Fusion]]></title>
            <link rel="alternate" href="http://www.openfusion.com.au/labs/mod_auth_tkt" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/8763"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[mod_auth_tkt is a lightweight single-sign-on authentication module for apache, supporting versions 1.3.x, 2.0.x, and 2.2.x. It uses secure cookie-based tickets to implement a single-signon framework that works across multiple apache instances and servers.]]>
            </summary>
            <updated>2025-08-29T16:17:59+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/8814</id>
            <title type="text"><![CDATA[LemonLDAP::NG]]></title>
            <link rel="alternate" href="http://lemonldap-ng.org/welcome" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/8814"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Open Source Web Single Sign On]]>
            </summary>
            <updated>2025-08-29T16:27:01+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/9249</id>
            <title type="text"><![CDATA[Aper&amp;amp;#231;u - Authentic - Projets Entr&amp;#039;ouvert]]></title>
            <link rel="alternate" href="http://dev.entrouvert.org/projects/authentic" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/9249"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Authentic 2, a versatile identity management server]]>
            </summary>
            <updated>2025-08-29T17:39:39+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/9286</id>
            <title type="text"><![CDATA[Pubcookie Home Page]]></title>
            <link rel="alternate" href="http://www.pubcookie.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/9286"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Pubcookie consists of a standalone login server and modules for common web server platforms like Apache and Microsoft IIS. Together, these components can turn existing authentication services (like Kerberos, LDAP, or NIS) into a solution for single sign-on authentication to websites throughout an institution.]]>
            </summary>
            <updated>2025-08-29T17:45:47+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/9512</id>
            <title type="text"><![CDATA[Vulture webSSO]]></title>
            <link rel="alternate" href="http://www.vultureproject.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/9512"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Vulture est une solution Web-SSO basée sur une technologie de proxy inverse implémentée sur le socle Apache. Vulture implémente également des fonctionnalités de firewall applicatif.]]>
            </summary>
            <updated>2025-08-29T18:23:02+00:00</updated>
        </entry>
    </feed>
