README.md

February 25, 2026 ยท View on GitHub

ZITADEL Logo ZITADEL Logo

GitHub Workflow Status (with event) GitHub contributors

The Identity Infrastructure for Developers

ZITADEL is an open-source identity and access management platform built for teams that need more than basic auth. Whether you're securing a SaaS product, building a B2B platform, or self-hosting a production IAM stack โ€” ZITADEL gives you everything out of the box: SSO, MFA, Passkeys, OIDC, SAML, SCIM, and a battle-tested multi-tenancy model.

No vendor lock-in. No compromise on control. Just a robust, API-first identity platform you can own.


๐Ÿก Website ย |ย  ๐Ÿ’ฌ Chat ย |ย  ๐Ÿ“‹ Docs ย |ย  ๐Ÿง‘โ€๐Ÿ’ป Blog ย |ย  ๐Ÿ“ž Contact


Why ZITADEL

We built ZITADEL to handle the hardest IAM challenges at scale โ€” starting with multi-tenancy.

ZITADELFusionAuthKeycloakAuth0/Okta
Open-sourceโœ…โŒโœ…โŒ
Self-hostableโœ…โœ…โœ…โŒ
Infrastructure-level tenantsโœ… Instances (High scale)โœ… Tenants๐ŸŸก Realms (Scaling limits)โŒ (Multi-tenant = multi-account)
B2B Organizationsโœ… Native & Unlimited๐ŸŸก via Entity Managementโœ… (Recent addition)๐ŸŸก (Plan/Account dependent)
Full audit trailโœ… Comprehensive Event Stream*๐ŸŸก Audit logs๐ŸŸก Audit logs๐ŸŸก Audit logs
Passkeys (FIDO2)โœ…โœ…โœ…โœ…
Actions / webhooksโœ…โœ…๐ŸŸก via SPIโœ…
API-first (gRPC + REST)โœ…๐ŸŸก REST only๐ŸŸก REST only๐ŸŸก REST only
SaaS + self-host parityโœ…โœ…โž– N/Aโž– N/A

ZITADEL Cloud and self-hosted ZITADEL run the same codebase.

Key differentiators for architects:

  • Relational core, event-driven soul โ€” every mutation is written as an immutable event for a complete, API-accessible audit trail. Unlike systems that log only select activities, ZITADEL provides a comprehensive event stream that can be audited or streamed to external systems via Webhooks.
  • Strict multi-tenant hierarchy โ€” Identity System โ†’ Organizations โ†’ Projects, with isolated data and policy scoping at multiple levels
  • API-first design โ€” every resource and action is available via connectRPC, gRPC, and HTTP/JSON APIs
  • Zero-downtime updates and horizontal scalability without external session stores

Get Started in 3 Minutes

๐Ÿ‘‰ Quick Start Guide

ZITADEL Self-Hosted

# Docker Compose โ€” up and running in under 3 minutes
curl -LO https://raw.githubusercontent.com/zitadel/zitadel/main/deploy/compose/docker-compose.yml \
  && curl -LO https://raw.githubusercontent.com/zitadel/zitadel/main/deploy/compose/.env.example \
  && cp .env.example .env \
  && docker compose up -d --wait

Full deployment guides:

Need professional support for your self-hosted deployment? Contact us.

ZITADEL Cloud (SaaS)

Start for free at zitadel.com โ€” no credit card required. Available in US ยท EU ยท AU ยท CH. Pay-as-you-go pricing.


Integrate with the V2 API

ZITADEL exposes every capability over a typed API. Here's how to create a user with the V2 REST API:

curl -X POST https://$ZITADEL_DOMAIN/v2/users/human \
  -H "Authorization: Bearer $ACCESS_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "username": "alice@example.com",
    "profile": { "givenName": "Alice", "familyName": "Smith" },
    "email": { "email": "alice@example.com", "sendCode": {} }
  }'

Explore the full API reference โ€” including connectRPC and gRPC transports โ€” or jump straight to quickstart examples.


Features

Authentication

Multi-Tenancy

Integration

Self-Service & Admin

Deployment

Track upcoming features on our roadmap and follow our changelog for recent updates.


Showcase

Login V2

Our new, fully customizable login experience โ€” documentation


Adopters & Ecosystem

Used in production by organizations worldwide. See the full Adopters list โ€” and add yours by submitting a pull request.


How To Contribute

ZITADEL is built in the open and welcoming to contributions of all kinds.

Contributors

Made with contrib.rocks.


Security

Security policy: SECURITY.md

Vulnerability Disclosure Policy โ€” how to responsibly report security issues.

Technical Advisories are published for major issues that could impact security or stability in production.

License

AGPL-3.0 โ€” see LICENSING.md for the full licensing policy, including Apache 2.0 and MIT exceptions for specific directories.