Overview
Kanidm is an identity management server written in Rust that acts as a single source of truth for accounts, authentication and authorisation. Its goal is to be a complete identity provider: the project says you should not need other components such as Keycloak when you use it. It relies on strict defaults, simple configuration and self-healing components, and targets everything from home labs and families to larger organisations.
On the web side it is an OAuth2/OIDC provider with passkey (WebAuthn) login, an application portal and user self-service in a web UI. Beyond the web it integrates with Linux and UNIX hosts, including offline authentication, distributes SSH keys, provides RADIUS for network and VPN login, and exposes a read-only LDAPS gateway for older software. Administration is done with complete CLI tooling.
Its security model gives each device its own scoped credentials (SSH keys, application passwords, RADIUS passwords), so a compromised device or service can be revoked on its own. Kanidm is free and self-hosted, uses its own database with replication rather than an external SQL server, and does not target customer sign-up flows for public apps.
Pricing and plans
checked 28 Sept 2026Free tier · no card
Free and open source; self-hosted with no paid tiers or user limits
| Plan | Price | What you get |
|---|---|---|
| Kanidm | Free | Self-hosted, open source |
What it does
- OIDC provider and portal
- OAuth2/OIDC web SSO with an application portal listing linked apps.
- Passkeys
- WebAuthn passkeys for cryptographic authentication, including attested passkeys.
- UNIX integration
- Linux/UNIX login with offline authentication and SSH key distribution.
- RADIUS
- Network, Wi-Fi and VPN authentication backed by Kanidm accounts.
- LDAPS gateway
- Read-only LDAPS interface for legacy systems.
- Replication
- Built-in database replication for high availability, without an external SQL server.
Strengths and limitations
Strengths
- One server for web SSO, SSH, RADIUS and LDAP
- Written in Rust with secure defaults
- No external database needed
- Free with no user limits
Limitations
- LDAP gateway is read-only
- No SAML listed among features
- Self-hosted only with community support
- Not aimed at consumer sign-up or B2B multi-tenancy
Who it suits
Good for
- Homelabs and families wanting one login for web apps and machines
- Small organisations managing Linux hosts, SSH and VPN
- Self-hosters who want replication for availability
Look elsewhere if
- Public apps needing customer registration flows
- Enterprises that require SAML federation
Alternatives to Kanidm
| Tool | From | Free option | Stages |
|---|---|---|---|
| Amazon Cognito Cloud user directory and auth service | Usage-based | Free tier | |
| Asgardeo Hosted CIAM (with open-source self-hosted option) | $20/mo | Free tier | |
| Auth0 Hosted customer identity (CIAM) | $35/mo | Free tier | |
| authentik Open-source self-hosted identity provider | Usage-based | Free tier | |
| Authgear Open-source CIAM (cloud, VPC or one-time self-host licence) | $50/mo | Free tier | |
| Better Auth Open-source TypeScript auth library | $20/mo | Free tier |
Questions
Is Kanidm free?
Yes. Kanidm is open source and self-hosted with no paid tiers.
Does Kanidm support OpenID Connect?
Yes. It is an OAuth2/OIDC authentication provider for web SSO.
Can Kanidm replace LDAP?
It provides a read-only LDAPS gateway for legacy systems plus native UNIX, SSH and RADIUS integration.
Kanidm vs Pocket ID?
Pocket ID is a minimal passkey-only OIDC provider; Kanidm also covers UNIX login, SSH keys, RADIUS, LDAPS and replication.
Sources read for this page