Pocket ID

Passwordless Authentication Made Easy

Pocket ID is the most user-friendly OpenID Connect Certified™ and OAuth 2.0 provider that lets users sign in to your applications with passkeys.

OpenID Connect Certified™

active instances
active instances
Docker pulls
Docker pulls
GitHub stars
GitHub stars
contributors
contributors

What the community says

I have been using Pocket ID since 2025 and it has been an excellent experience. It was incredibly easy to set up uses very few resources, and does exactly what I need without any unnecessary complexity.
Hu/huzzyzon r/selfhosted
Amazing. Favorite self hosted service by far!
Mu/mamwybejaneon r/selfhosted
The only Auth application I could install and not even think about it later. You did an amazing job with this application.
Au/Asfalotson r/selfhosted
Love PocketID, used for a while now, very nice design and stability, works so well with cloudflare tunnels.
Hu/hometechgeekon r/selfhosted
I put Pocket ID on a VPS (it's so light) and I've never looked back. Thank you, it's amazing!
Pu/ProletariatPaton r/selfhosted
All praise for pocket ID is warranted. This is a freakin awesome project
Du/dakoellison r/selfhosted
It's so stinking simple to integrate and use and I can spend my time working on the subject matter pieces of my application.
Ru/RedditNotFreeSpeechon r/selfhosted
Love pocket id, its so simple to setup and visually pleasing!
Uu/unlevelson r/selfhosted
I've really appreciated how easy pocket-id has been to setup and administer in my homelab.
Fu/Funny-Satisfaction-1on r/selfhosted
I just installed Pocket ID on Wednesday and was very impressed at how simple it was. Two hours from when I started it was running and all of my apps that support oidc were configured.
Mu/mydarbon r/selfhosted

Features

Pocket ID handles sign-in and leaves out what a self-hosted setup rarely needs, so it stays small and easy to maintain.

Passkeys instead of passwords

Pocket ID has no passwords. Users sign in with passkeys from their device, password manager or security key, and can add as many as they like.

Login codes

Send new users a one-time login code or link, so they can add their first passkey.

The login code dialog with a code and QR codeThe login code dialog with a code and QR code

Access by group

Limit a client to selected user groups, and users outside them can't sign in to it.

The allowed user groups of a clientThe allowed user groups of a client

App dashboard

The My Apps page lists the apps that a user has access to.

The My Apps dashboardThe My Apps dashboard

LDAP sync

Import users and groups from LDAP or Active Directory and keep them in sync.

The LDAP settingsThe LDAP settings

Access tokens for your APIs

Define an API with its permissions, and clients get tokens limited to what they were granted.

An API with its permissionsAn API with its permissions

Audit log

Every sign-in is logged with its device, IP address and approximate location, per user and for the whole instance.

The audit log with sign-in eventsThe audit log with sign-in events

OAuth for MCP servers

Pocket ID can be the OAuth authorization server for remote MCP servers and other AI tools. Users approve access with their passkey, and each client gets a token limited to the scopes it was granted.

Ready to get started?

Pocket ID runs as a single Docker container or binary. The docs walk you through the installation and connecting your first app.