P10 · Host · Rendered from source

top repos

Identity, settings and navigation host

36 lines27,722 bytessha256 6172ede7488e
Keycloakrecord 1
{
  "id": "P10-R-001",
  "evidence_class": "observed",
  "source": "https://github.com/keycloak/keycloak",
  "observed": "2026-08-27",
  "name": "Keycloak",
  "category": "self-hosted IdP",
  "license": "Apache-2.0",
  "license_verified": "badge",
  "claim": "Full IAM server: OIDC/SAML, user federation, strong auth, fine-grained authz. 36.4k stars, Java, server distribution (not a library).",
  "host_concern": "identity",
  "hosted_embeddable": "conditional",
  "limitations": "Heavyweight JVM server; deploys as a separate process, not embeddable in-host. Admin console is its own UI, so its settings model is not reusable as a host settings registry.",
  "disposition": "top10"
}
ZITADELrecord 2
{
  "id": "P10-R-002",
  "evidence_class": "observed",
  "source": "https://github.com/zitadel/zitadel",
  "observed": "2026-08-27",
  "name": "ZITADEL",
  "category": "self-hosted IdP",
  "license": "AGPL-3.0 (core), with Apache-2.0/MIT exceptions for specific directories per LICENSING.md",
  "license_verified": "badge",
  "claim": "Identity infrastructure with SSO, MFA, passkeys, OIDC, SAML, SCIM and first-class multi-tenancy. 14.9k stars, Go.",
  "host_concern": "tenancy",
  "hosted_embeddable": "conditional",
  "limitations": "AGPL-3.0 network copyleft on the core — FLAG. Serving a modified ZITADEL over a network triggers source-provision duties. Directory-level Apache/MIT carve-outs exist but were not read at file level in this run.",
  "disposition": "register"
}
Ory Kratosrecord 3
{
  "id": "P10-R-003",
  "evidence_class": "observed",
  "source": "https://github.com/ory/kratos",
  "observed": "2026-08-27",
  "name": "Ory Kratos",
  "category": "self-hosted IdP",
  "license": "Apache-2.0",
  "license_verified": "badge",
  "claim": "Headless, API-first identity and user management in Go; no UI of its own, so the host owns all identity screens. 13.8k stars.",
  "host_concern": "identity",
  "hosted_embeddable": "yes",
  "limitations": "Headless by design means the host must build every identity flow UI. SCIM, SAML, org SSO and CVE-fix SLAs are Ory Enterprise License only, not in the OSS build.",
  "disposition": "top10"
}
authentikrecord 4
{
  "id": "P10-R-004",
  "evidence_class": "observed",
  "source": "https://github.com/goauthentik/authentik",
  "observed": "2026-08-27",
  "name": "authentik",
  "category": "self-hosted IdP",
  "license": "MIT core; separate authentik EE License covers authentik/enterprise/; docs CC BY-SA 4.0",
  "license_verified": "badge",
  "claim": "Self-hosted IdP for SSO across SAML, OAuth2/OIDC, LDAP and RADIUS. 25.2k stars, mixed Python/Go/TS.",
  "host_concern": "identity",
  "hosted_embeddable": "conditional",
  "limitations": "Mixed licensing — the enterprise/ subtree is NOT MIT. Any absorption must exclude that directory or trigger EE terms.",
  "disposition": "register"
}
Ory Hydrarecord 5
{
  "id": "P10-R-005",
  "evidence_class": "observed",
  "source": "https://github.com/ory/hydra",
  "observed": "2026-08-27",
  "name": "Ory Hydra",
  "category": "self-hosted IdP",
  "license": "Apache-2.0",
  "license_verified": "badge",
  "claim": "OpenID-certified OAuth2/OIDC server that delegates user management to an external IdP. 17.5k stars, Go.",
  "host_concern": "session",
  "hosted_embeddable": "yes",
  "limitations": "Token server only — no user store, so it must be paired with Kratos or equivalent. Security releases with SLA and multi-tenancy scaling support are Ory Enterprise License features.",
  "disposition": "register"
}
Ory Ketorecord 6
{
  "id": "P10-R-006",
  "evidence_class": "observed",
  "source": "https://github.com/ory/keto",
  "observed": "2026-08-27",
  "name": "Ory Keto",
  "category": "authorization engine",
  "license": "Apache-2.0",
  "license_verified": "badge",
  "claim": "Zanzibar-model permission server with relation tuples, ACL/RBAC/ReBAC and the Ory Permission Language. 5.4k stars, Go.",
  "host_concern": "authorization",
  "hosted_embeddable": "yes",
  "limitations": "Smallest community of the Zanzibar options (5.4k stars vs SpiceDB 7.0k). Last-commit recency not confirmed from the repo page in this run.",
  "disposition": "register"
}
Autheliarecord 7
{
  "id": "P10-R-007",
  "evidence_class": "observed",
  "source": "https://github.com/authelia/authelia",
  "observed": "2026-08-27",
  "name": "Authelia",
  "category": "self-hosted IdP",
  "license": "Apache-2.0",
  "license_verified": "badge",
  "claim": "SSO and MFA portal designed as a forward-auth companion to reverse proxies (nginx, Traefik, Caddy, Envoy), now also OpenID-certified. 28.7k stars, Go.",
  "host_concern": "session",
  "hosted_embeddable": "conditional",
  "limitations": "Architecture assumes a reverse proxy performs the auth interception; its OIDC provider role is described as still effectively beta on the roadmap.",
  "disposition": "register"
}
Casdoorrecord 8
{
  "id": "P10-R-008",
  "evidence_class": "observed",
  "source": "https://github.com/casdoor/casdoor",
  "observed": "2026-08-27",
  "name": "Casdoor",
  "category": "self-hosted IdP",
  "license": "Apache-2.0",
  "license_verified": "badge",
  "claim": "Self-hosted IAM with an explicit multi-tenancy model: independent organizations each owning users, applications, providers and branding. 14.3k stars, Go + React.",
  "host_concern": "tenancy",
  "hosted_embeddable": "yes",
  "limitations": "Organization is a first-class login field, which shapes the UX. Beego-framework backend is a less common Go stack.",
  "disposition": "register"
}
Better Authrecord 9
{
  "id": "P10-R-009",
  "evidence_class": "observed",
  "source": "https://github.com/better-auth/better-auth",
  "observed": "2026-08-27",
  "name": "Better Auth",
  "category": "auth library",
  "license": "MIT",
  "license_verified": "badge",
  "claim": "Framework-agnostic TypeScript auth framework with a plugin ecosystem covering 2FA, SSO and multi-tenancy. 29.7k stars. Auth.js has joined Better Auth and now points new projects here.",
  "host_concern": "identity",
  "hosted_embeddable": "yes",
  "limitations": "Library, not a server — the host owns deployment and storage. High open-PR count (385) observed. Specific organization-plugin API not read at source level in this run.",
  "disposition": "top10"
}
Auth.js (NextAuth.js)record 10
{
  "id": "P10-R-010",
  "evidence_class": "observed",
  "source": "https://github.com/nextauthjs/next-auth",
  "observed": "2026-08-27",
  "name": "Auth.js (NextAuth.js)",
  "category": "auth library",
  "license": "ISC",
  "license_verified": "badge",
  "claim": "Web-standards auth for Next.js, Nuxt, SvelteKit, SolidJS and Remix; works with or without a database. 28.3k stars, TypeScript.",
  "host_concern": "identity",
  "hosted_embeddable": "yes",
  "limitations": "README states Auth.js has joined Better Auth and recommends new projects start with Better Auth unless they need stateless database-free sessions — a maintenance/transition posture, not active feature development. Treat as legacy for greenfield.",
  "disposition": "register"
}
Luciarecord 11
{
  "id": "P10-R-011",
  "evidence_class": "observed",
  "source": "https://github.com/lucia-auth/lucia",
  "observed": "2026-08-27",
  "name": "Lucia",
  "category": "auth library",
  "license": "MIT",
  "license_verified": "badge",
  "claim": "README states verbatim that Lucia was deprecated on March 2025; repositioned as a learning resource pointing at a single-file session implementation plus the maintainer's Auth Book. 10.5k stars.",
  "host_concern": "session",
  "hosted_embeddable": "no",
  "limitations": "DEPRECATED — do not adopt as a dependency. Value is purely educational: the single-file auth_session.ts is a readable reference for hand-rolling session handling.",
  "disposition": "rejected"
}
Open Policy Agentrecord 12
{
  "id": "P10-R-012",
  "evidence_class": "observed",
  "source": "https://github.com/open-policy-agent/opa",
  "observed": "2026-08-27",
  "name": "Open Policy Agent",
  "category": "authorization engine",
  "license": "Apache-2.0",
  "license_verified": "badge",
  "claim": "CNCF-graduated (Feb 2021) general-purpose policy engine. Embeddable as a Go library, runnable as a sidecar/daemon, or compiled to WASM. 12.2k stars.",
  "host_concern": "authorization",
  "hosted_embeddable": "yes",
  "limitations": "Rego is a distinct policy language with a real learning curve. General-purpose rather than identity-shaped — no built-in relationship model.",
  "disposition": "top10"
}
Cerbosrecord 13
{
  "id": "P10-R-013",
  "evidence_class": "observed",
  "source": "https://github.com/cerbos/cerbos",
  "observed": "2026-08-27",
  "name": "Cerbos",
  "category": "authorization engine",
  "license": "Apache-2.0",
  "license_verified": "body (README states 'Cerbos is licensed under the Apache License 2.0')",
  "claim": "Stateless authorization PDP with YAML policy files; deploys as a Kubernetes service, sidecar, systemd unit or Lambda. 4.6k stars, Go.",
  "host_concern": "authorization",
  "hosted_embeddable": "yes",
  "limitations": "Open-core: the self-hosted PDP is Apache-2.0, but policy CI/CD, fleet distribution and the Embedded PDP for browser/edge live in commercial Cerbos Hub.",
  "disposition": "register"
}
SpiceDBrecord 14
{
  "id": "P10-R-014",
  "evidence_class": "observed",
  "source": "https://github.com/authzed/spicedb",
  "observed": "2026-08-27",
  "name": "SpiceDB",
  "category": "authorization engine",
  "license": "Apache-2.0",
  "license_verified": "badge",
  "claim": "Most mature OSS Zanzibar implementation; adds caveated relationships combining ABAC with ReBAC. 7.0k stars, Go. Explicitly verified NOT BSL/source-available.",
  "host_concern": "authorization",
  "hosted_embeddable": "yes",
  "limitations": "Requires running a dedicated datastore-backed service; relationship modelling is a genuine design commitment, not a drop-in.",
  "disposition": "top10"
}
OpenFGArecord 15
{
  "id": "P10-R-015",
  "evidence_class": "observed",
  "source": "https://github.com/openfga/openfga",
  "observed": "2026-08-27",
  "name": "OpenFGA",
  "category": "authorization engine",
  "license": "Apache-2.0",
  "license_verified": "badge",
  "claim": "CNCF project (community Slack under cncf), Zanzibar-inspired, in production behind Auth0 FGA since Dec 2021. Embeddable as a Go library or run as a service. 5.7k stars.",
  "host_concern": "authorization",
  "hosted_embeddable": "yes",
  "limitations": "Formal CNCF tier not spelled out on the repo page (inferred from the cncf Slack reference). Okta relationship not stated on the page.",
  "disposition": "register"
}
Casbinrecord 16
{
  "id": "P10-R-016",
  "evidence_class": "observed",
  "source": "https://github.com/casbin/casbin",
  "observed": "2026-08-27",
  "name": "Casbin",
  "category": "authorization engine",
  "license": "Apache-2.0",
  "license_verified": "badge",
  "claim": "Embedded authorization library (not a server) built on the PERM metamodel — Policy, Effect, Request, Matchers — so swapping ACL/RBAC/ABAC is a config change, not a code change. Includes RBAC with domains/tenants. 20.4k stars.",
  "host_concern": "authorization",
  "hosted_embeddable": "yes",
  "limitations": "In-process library: no central policy distribution or audit plane. Deliberately excludes authentication and user management.",
  "disposition": "register"
}
single-sparecord 17
{
  "id": "P10-R-017",
  "evidence_class": "observed",
  "source": "https://github.com/single-spa/single-spa",
  "observed": "2026-08-27",
  "name": "single-spa",
  "category": "microfrontend shell",
  "license": "MIT",
  "license_verified": "body (raw LICENSE fetched: 'License (MIT)', Copyright (c) 2020 single-spa)",
  "claim": "Top-level router for microfrontends. Apps register via registerApplication(name, loadFn, activeWhen) and export bootstrap/mount/unmount lifecycle promises; the router mounts and unmounts on route change. 13.9k stars.",
  "host_concern": "navigation",
  "hosted_embeddable": "yes",
  "limitations": "Registration API confirmed from general knowledge, not quoted from the repo page — the page did not document the API. Routes to apps but carries no notion of a nav item, label, icon or permission.",
  "disposition": "top10"
}
Module Federation 2.0record 18
{
  "id": "P10-R-018",
  "evidence_class": "observed",
  "source": "https://github.com/module-federation/core",
  "observed": "2026-08-27",
  "name": "Module Federation 2.0",
  "category": "microfrontend shell",
  "license": "MIT",
  "license_verified": "badge",
  "claim": "Runtime code-sharing across JS applications. 2.0 adds a standalone Federation Runtime, a runtime plugin system, a Manifest describing federated modules, dynamic TypeScript type hinting and a Chrome devtool. Webpack and Rspack. 2.6k stars.",
  "host_concern": "shell",
  "hosted_embeddable": "yes",
  "limitations": "Build/runtime module plumbing only — no navigation, identity or settings semantics. The Manifest is the interesting seam: metadata about remotes that a host could read.",
  "disposition": "top10"
}
Piralrecord 19
{
  "id": "P10-R-019",
  "evidence_class": "observed",
  "source": "https://github.com/smapiot/piral",
  "observed": "2026-08-27",
  "name": "Piral",
  "category": "microfrontend shell",
  "license": "MIT",
  "license_verified": "badge",
  "claim": "App-shell framework where 'pilets' are runtime-loaded modules that extend other pilets or expose extension slots, can be rolled out or disabled dynamically, and are transferrable between host applications. 1.9k stars, TypeScript.",
  "host_concern": "shell",
  "hosted_embeddable": "conditional",
  "limitations": "Small community (1.9k stars). A hosted pilet feed service is implied by a status.piral.io badge but its commercial terms were not stated on the page — the feed is how pilets reach the shell, so this needs verification before adoption.",
  "disposition": "register"
}
qiankunrecord 20
{
  "id": "P10-R-020",
  "evidence_class": "observed",
  "source": "https://github.com/umijs/qiankun",
  "observed": "2026-08-27",
  "name": "qiankun",
  "category": "microfrontend shell",
  "license": "MIT",
  "license_verified": "badge",
  "claim": "Microfrontend solution with a Proxy-membrane JS sandbox isolating window/document/timers/listeners per app, opt-in CSS @scope style isolation, and native ESM support. @qiankunjs/sandbox is publishable standalone to contain any third-party script. 16.7k stars.",
  "host_concern": "shell",
  "hosted_embeddable": "yes",
  "limitations": "v3 is under active development and ships on the npm rc tag while latest remains 2.x — adopting v3 means tracking a pre-release. 411 open issues.",
  "disposition": "register"
}
Luigi (SAP)record 21
{
  "id": "P10-R-021",
  "evidence_class": "observed",
  "source": "https://github.com/SAP/luigi",
  "observed": "2026-08-27",
  "name": "Luigi (SAP)",
  "category": "microfrontend shell",
  "license": "Apache-2.0",
  "license_verified": "badge",
  "claim": "SAP's micro-frontend framework for admin UIs, split into Luigi Core (host, owns routing/navigation/authorization config) and Luigi Client (embedded in each MF), communicating over postMessage. 923 stars.",
  "host_concern": "navigation",
  "hosted_embeddable": "yes",
  "limitations": "Iframe-based mounting with explicit sandbox and origin-allowlist rules — strong isolation, weaker UX integration. Whether navigation is a declarative node tree was NOT confirmed from the repo page; it requires docs.luigi-project.io. Only 923 stars.",
  "disposition": "register"
}
FrintJSrecord 22
{
  "id": "P10-R-022",
  "evidence_class": "observed",
  "source": "https://github.com/frintjs/frint",
  "observed": "2026-08-27",
  "name": "FrintJS",
  "category": "microfrontend shell",
  "license": "MIT",
  "license_verified": "badge",
  "claim": "Modular reactive JS framework for scalable apps. 757 stars.",
  "host_concern": "shell",
  "hosted_embeddable": "no",
  "limitations": "Dormant. No archive banner or formal deprecation, but Travis CI, Greenkeeper, NSP and Gitter badges indicate years without maintenance; frint-model is individually marked deprecated. Last-commit date could not be confirmed (GitHub API blocked in this environment).",
  "disposition": "rejected"
}
Backstagerecord 23
{
  "id": "P10-R-023",
  "evidence_class": "observed",
  "source": "https://github.com/backstage/backstage",
  "observed": "2026-08-27",
  "name": "Backstage",
  "category": "portal/workspace shell",
  "license": "Apache-2.0",
  "license_verified": "body (README states 'Licensed under the Apache License, Version 2.0')",
  "claim": "CNCF Incubation-level developer-portal framework from Spotify, 34.3k stars. Plugin-first: every feature including the catalog is a plugin. Plugins export routable extensions bound via route refs so they link to each other without hardcoded paths.",
  "host_concern": "navigation",
  "hosted_embeddable": "yes",
  "limitations": "Two frontend systems coexist: in the classic one the app author manually edits App.tsx routes and adds SidebarItem entries; the new frontend system lets plugins declare nav items and routes as auto-discovered extensions. That new-system detail is general knowledge, not quoted from the repo page — verify against backstage.io architecture docs before relying on it.",
  "disposition": "top10"
}
Appsmithrecord 24
{
  "id": "P10-R-024",
  "evidence_class": "observed",
  "source": "https://github.com/appsmithorg/appsmith",
  "observed": "2026-08-27",
  "name": "Appsmith",
  "category": "portal/workspace shell",
  "license": "Apache-2.0",
  "license_verified": "body (raw LICENSE fetched and read end-to-end: unmodified Apache 2.0, no Commons Clause, no appended exceptions)",
  "claim": "Platform for admin panels, internal tools and dashboards, integrating 25+ databases and any API. 40.8k stars.",
  "host_concern": "shell",
  "hosted_embeddable": "conditional",
  "limitations": "Docker image is tagged appsmith-ce, implying a separate commercial edition, though the page does not state the split explicitly. The OSS repo LICENSE itself is clean Apache-2.0 — verified against the body, not the badge.",
  "disposition": "register"
}
ToolJetrecord 25
{
  "id": "P10-R-025",
  "evidence_class": "observed",
  "source": "https://github.com/ToolJet/ToolJet",
  "observed": "2026-08-27",
  "name": "ToolJet",
  "category": "portal/workspace shell",
  "license": "AGPL-3.0",
  "license_verified": "body (README footer: 'ToolJet © 2023, ToolJet Solutions Inc - Released under the GNU Affero General Public License v3.0')",
  "claim": "Low-code platform for internal tools, dashboards, workflows and AI agents. 40.8k stars, JS/TS.",
  "host_concern": "shell",
  "hosted_embeddable": "conditional",
  "limitations": "AGPL-3.0 network copyleft — FLAG. Confirmed not GPL and not ELv2. Hosting a modified ToolJet for users triggers source-provision duties.",
  "disposition": "register"
}
Budibaserecord 26
{
  "id": "P10-R-026",
  "evidence_class": "observed",
  "source": "https://github.com/Budibase/budibase",
  "observed": "2026-08-27",
  "name": "Budibase",
  "category": "portal/workspace shell",
  "license": "GPL-3.0 core; client and component libraries MPL-2.0; paid pro package under Business Source License",
  "license_verified": "body (README licensing statement)",
  "claim": "Low-code platform for internal apps, automations and agents. 28.2k stars, Svelte builder + Koa server.",
  "host_concern": "shell",
  "hosted_embeddable": "conditional",
  "limitations": "Three-way license split — FLAG. GPL-3.0 core is strong copyleft; the pro package is BSL (source-available, not open source). Absorption requires per-directory care.",
  "disposition": "rejected"
}
NocoBaserecord 27
{
  "id": "P10-R-027",
  "evidence_class": "observed",
  "source": "https://github.com/nocobase/nocobase",
  "observed": "2026-08-27",
  "name": "NocoBase",
  "category": "portal/workspace shell",
  "license": "Custom 'NocoBase License Agreement' (NOCOBASE PTE. LTD.), updated 2026-02-24 — source-available, NOT Apache-2.0",
  "license_verified": "body (LICENSE.txt fetched and read; GitHub badge says Apache-2.0 and is MISLEADING)",
  "claim": "Microkernel no-code platform where everything is a plugin. 23.9k stars.",
  "host_concern": "shell",
  "hosted_embeddable": "no",
  "limitations": "CRITICAL LICENSE FINDING — the GitHub sidebar badge reads Apache-2.0 because LICENSE-APACHE.txt sits alongside LICENSE.txt, but the actual agreement incorporates Apache-2.0 only by reference and states its supplementary terms prevail on any inconsistency. It prohibits offering the software as a public no-code/low-code/AI SaaS or PaaS product and restricts selling upper-layer applications below the Professional tier. Not OSI open source. Plugin UI/menu registration mechanism not documented on the repo page.",
  "disposition": "rejected"
}
Frappe Frameworkrecord 28
{
  "id": "P10-R-028",
  "evidence_class": "observed",
  "source": "https://github.com/frappe/frappe",
  "observed": "2026-08-27",
  "name": "Frappe Framework",
  "category": "portal/workspace shell",
  "license": "MIT",
  "license_verified": "badge",
  "claim": "Low-code full-stack framework (Python/MariaDB server, integrated client library) underlying ERPNext, with a built-in admin interface, role-based permissions, auto-generated REST API and customizable forms/views. 10.6k stars.",
  "host_concern": "settings",
  "hosted_embeddable": "conditional",
  "limitations": "Desk UI, the DocType metadata model and workspace/menu registration are NOT described on the repo page — the framework's most relevant ideas for a host settings/navigation registry are unverified here and need docs.frappe.io. Python/MariaDB stack may not match the host.",
  "disposition": "register"
}
GrowthBookrecord 29
{
  "id": "P10-R-029",
  "evidence_class": "observed",
  "source": "https://github.com/growthbook/growthbook",
  "observed": "2026-08-27",
  "name": "GrowthBook",
  "category": "settings/flags",
  "license": "MIT for the bulk of the code; certain directories under a separate commercial GrowthBook Enterprise License",
  "license_verified": "body (README open-core statement)",
  "claim": "Feature flags with advanced targeting, gradual rollouts and experiments, warehouse-native, 24 SDKs plus REST API and webhooks. 8.2k stars.",
  "host_concern": "settings",
  "hosted_embeddable": "conditional",
  "limitations": "Open core — enterprise directories are not MIT and must be excluded from any absorption. Detailed targeting-rule schema not shown on the repo page.",
  "disposition": "register"
}
Unleashrecord 30
{
  "id": "P10-R-030",
  "evidence_class": "observed",
  "source": "https://github.com/Unleash/unleash",
  "observed": "2026-08-27",
  "name": "Unleash",
  "category": "settings/flags",
  "license": "AGPL-3.0-or-later",
  "license_verified": "badge (AGPL-3.0-or-later badge plus resources listing; explicitly NOT Apache-2.0 as commonly assumed)",
  "claim": "Open-source feature management platform. 13.8k stars, TypeScript/Node.",
  "host_concern": "settings",
  "hosted_embeddable": "conditional",
  "limitations": "LICENSE FINDING — widely believed to be Apache-2.0; the repo is AGPL-3.0-or-later. FLAG for network copyleft. No enterprise carve-out directory visible in the file listing, though docker-compose-enterprise.yml exists.",
  "disposition": "register"
}
Flagsmithrecord 31
{
  "id": "P10-R-031",
  "evidence_class": "observed",
  "source": "https://github.com/Flagsmith/flagsmith",
  "observed": "2026-08-27",
  "name": "Flagsmith",
  "category": "settings/flags",
  "license": "BSD-3-Clause for the majority of the platform; enterprise features require a paid Flagsmith Enterprise license; some sibling repos MIT",
  "license_verified": "body (README licensing statement)",
  "claim": "Open-source feature flagging and remote config service. 6.5k stars, Django/Python API + React frontend.",
  "host_concern": "settings",
  "hosted_embeddable": "yes",
  "limitations": "Most permissive license of the three flag platforms surveyed. 'Remote config' is the closest OSS analogue to a hosted settings tree, but it is flat key-value per environment rather than a hierarchical settings schema.",
  "disposition": "top10"
}
SuperTokensrecord 32
{
  "id": "P10-R-032",
  "evidence_class": "observed",
  "source": "https://github.com/supertokens/supertokens-core",
  "observed": "2026-08-27",
  "name": "SuperTokens",
  "category": "self-hosted IdP",
  "license": "Apache-2.0 for content outside ee/; the ee/ directory is under a proprietary SuperTokens Enterprise License requiring a paid subscription for production use",
  "license_verified": "body (raw LICENSE.md fetched from master and read; it opens 'Portions of this software are licensed as follows' and carves out ee/. ee/LICENSE.md fetched separately and read: production use requires agreement to the SuperTokens Subscription Terms and a valid Enterprise licence for the correct number of user seats, and it states it is 'forbidden to copy, merge, publish, distribute, sublicense, and/or sell the Software'. GitHub API reports spdx_id NOASSERTION, confirming the badge alone was insufficient)",
  "claim": "Self-hostable auth service positioned as an open-source alternative to Auth0/Firebase Auth/Cognito, with prebuilt and custom UI recipes for email-password, passwordless, social and session management. 15,285 stars, Java core.",
  "host_concern": "identity",
  "hosted_embeddable": "conditional",
  "limitations": "Split licence — FLAG. The Apache-2.0 grant stops at ee/, and the enterprise terms are seat-based and forbid redistribution, so multi-tenancy and other ee/ features cannot be absorbed. Core is a standalone Java service plus per-language SDKs, so it deploys as a separate process rather than embedding in the host.",
  "disposition": "register"
}
Logtorecord 33
{
  "id": "P10-R-033",
  "evidence_class": "observed",
  "source": "https://github.com/logto-io/logto",
  "observed": "2026-08-27",
  "name": "Logto",
  "category": "self-hosted IdP",
  "license": "MPL-2.0 (Mozilla Public License Version 2.0)",
  "license_verified": "body (raw LICENSE fetched from master and read: the text opens 'Mozilla Public License Version 2.0' and terminates in the standard Exhibit A / Exhibit B notices, with no appended exceptions, Commons Clause, or enterprise carve-out. Root directory listing shows a single LICENSE file and no ee/ or enterprise/ directory. GitHub API spdx_id MPL-2.0 agrees with the body)",
  "claim": "Auth infrastructure for SaaS and AI apps built on OIDC and OAuth 2.1, with first-class multi-tenancy, prebuilt sign-in experience and a management API. 14,469 stars, TypeScript.",
  "host_concern": "tenancy",
  "hosted_embeddable": "conditional",
  "limitations": "MPL-2.0 is weak file-level copyleft — meaningfully lighter than ZITADEL's AGPL since it carries no network-service source-provision duty, but modified Logto files must still be published under MPL. FLAG-LITE rather than FLAG. Logto is commonly assumed permissive; it is not. Cloud tier gates some features, not read at file level in this run.",
  "disposition": "top10"
}
oauth2-proxyrecord 34
{
  "id": "P10-R-034",
  "evidence_class": "observed",
  "source": "https://github.com/oauth2-proxy/oauth2-proxy",
  "observed": "2026-08-27",
  "name": "oauth2-proxy",
  "category": "auth library",
  "license": "MIT",
  "license_verified": "body (raw LICENSE fetched from master and read end-to-end: verbatim MIT permission grant and warranty disclaimer, no added conditions. Note the file omits a copyright attribution line, which is a minor attribution gap rather than a licence-scope issue. GitHub API spdx_id MIT agrees)",
  "claim": "Reverse proxy that terminates authentication in front of an upstream app against Google, Azure, GitHub, generic OIDC and many other providers, injecting identity headers downstream. 14,878 stars, Go.",
  "host_concern": "session",
  "hosted_embeddable": "yes",
  "limitations": "Sits at the network edge rather than in the application, so it authenticates a request but contributes nothing to in-app settings or navigation. Header-injection trust model requires the upstream to be unreachable except through the proxy. Cleanest licence in the identity set.",
  "disposition": "register"
}
jose (panva)record 35
{
  "id": "P10-R-035",
  "evidence_class": "observed",
  "source": "https://github.com/panva/jose",
  "observed": "2026-08-27",
  "name": "jose (panva)",
  "category": "auth library",
  "license": "MIT",
  "license_verified": "body (raw LICENSE.md fetched from master and read end-to-end: 'The MIT License (MIT)', Copyright (c) 2018 Filip Skokan, verbatim grant with no added conditions. GitHub API spdx_id MIT agrees)",
  "claim": "Zero-dependency implementation of JWA, JWS, JWE, JWT, JWK and JWKS running on Node.js, browsers, Cloudflare Workers, Deno and Bun. 7,768 stars, TypeScript.",
  "host_concern": "session",
  "hosted_embeddable": "yes",
  "limitations": "A cryptographic primitive library, not a system — it verifies and mints tokens but owns no user store, session lifecycle, settings or navigation. Correct building block for host-side token verification; contributes nothing to the registry gaps.",
  "disposition": "register"
}