head to head · open source
oauth2-proxy vs caddy-security
oauth2-proxy has 15,013 GitHub stars, 2,200 forks, 285 open issues and last shipped 2 days ago. caddy-security has 2,239 stars, 102 forks, 8 open issues and last shipped today. oauth2-proxy leads on adoption by 571% (15,013 vs 2,239 stars). oauth2-proxy is written in Go under MIT; caddy-security is written in Go under Apache-2.0. oauth2-proxy has attracted 15% as many forks as stars, caddy-security 5%. caddy-security was the more recently maintained of the two, and both are self-hostable with no licence fee. The two share 2 topic tags (oauth2, sso), so they are genuine substitutes rather than adjacent tools.
Two open source projects, one decision. Both are free and self-hostable — the differences are community size, license terms, language stack and release pace.
← all 20902 open source comparisons
Side by side
| oauth2-proxy | caddy-security | |
|---|---|---|
| GitHub stars | ★ 15K | ★ 2.2K |
| License | MIT | Apache-2.0 |
| Written in | Go | Go |
| Last push | 2026-09-25 | 2026-09-27 |
| Forks | ⑂ 2.2K | ⑂ 102 |
| Self-hosting | Yes | Yes |
| Data ownership | Your server | Your server |
pick oauth2-proxy if
- You weight community size — 15K stars and counting
- You want the MIT license terms
- Your stack matches Go
- You value the larger contributor base for long-term maintenance
pick caddy-security if
- You want the caddy-security feature set and don't need the biggest community
- You prefer the Apache-2.0 license terms
- Your stack matches Go
- You evaluated both and caddy-security fits your workflow better
About oauth2-proxy
OAuth2 Proxy is an open source, MIT licensed reverse proxy and middleware written in Go that puts OAuth2 and OpenID Connect authentication in front of web applications, aimed at operators and platform teams who need single sign on without adding auth code to every app.
read the full oauth2-proxy overview →
About caddy-security
caddy security is an authentication, authorization, and accounting (AAA) app and plugin for Caddy v2 that implements form based, basic, local, LDAP, OpenID Connect, OAuth 2.0 and SAML sign in together with JWT and PASETO request authorization, and it is aimed at operators and security teams who terminate HTTP traffic with Caddy and want identity enforcement to happen inside the web server itself.
read the full caddy-security overview →
More in Security & Privacy
Related comparisons
More Identity & Access Management (IAM) projects
Compare either of these against the rest of the Identity & Access Management (IAM) field.
Frequently asked questions
Is oauth2-proxy or caddy-security more popular?
oauth2-proxy has 15,013 GitHub stars and caddy-security has 2,239. oauth2-proxy has the larger community by that measure.
Are oauth2-proxy and caddy-security free?
Both are open source. oauth2-proxy is licensed under MIT and caddy-security under Apache-2.0. Neither carries a licence fee.
What is the difference between oauth2-proxy and caddy-security?
oauth2-proxy is written in Go and caddy-security in Go. The practical differences are community size, licence terms, language stack and release cadence — all compared in the table above.
Which should I choose, oauth2-proxy or caddy-security?
Choose oauth2-proxy if you want the larger community (15,013 stars) or its MIT licence terms. Choose caddy-security if its feature set, stack or Apache-2.0 licence fits better. Both are self-hostable.