head to head · open source
Sa-Token vs oauth2-proxy
Sa-Token has 19,051 GitHub stars, 2,914 forks, 111 open issues and last shipped 2 days ago. oauth2-proxy has 14,982 stars, 2,196 forks, 285 open issues and last shipped 2 days ago. Sa-Token leads on adoption by 27% (19,051 vs 14,982 stars). Sa-Token is written in Java under Apache-2.0; oauth2-proxy is written in Go under MIT. Sa-Token has attracted 15% as many forks as stars, oauth2-proxy 15%. oauth2-proxy was the more recently maintained of the two, and both are self-hostable with no licence fee. The two share 1 topic tag (sso), so they are genuine substitutes rather than adjacent tools.
Two open source projects, one decision. Both are free and self-hostable — the differences are community size, license terms, language stack and release pace.
← all 20902 open source comparisons
Side by side
| Sa-Token | oauth2-proxy | |
|---|---|---|
| GitHub stars | ★ 19K | ★ 15K |
| License | Apache-2.0 | MIT |
| Written in | Java | Go |
| Last push | 2026-09-18 | 2026-09-18 |
| Forks | ⑂ 2.9K | ⑂ 2.2K |
| Self-hosting | Yes | Yes |
| Data ownership | Your server | Your server |
pick Sa-Token if
- You weight community size — 19K stars and counting
- You want the Apache-2.0 license terms
- Your stack matches Java
- You value the larger contributor base for long-term maintenance
pick oauth2-proxy if
- You want the oauth2-proxy feature set and don't need the biggest community
- You prefer the MIT license terms
- Your stack matches Go
- You evaluated both and oauth2-proxy fits your workflow better
About Sa-Token
Sa Token is a free, open source, one stop Java authentication and authorization framework, licensed under Apache 2.0, that gives Java and Spring Boot developers login authentication, permission checks, distributed sessions, single sign on, OAuth2.0, gateway authentication, JWT integration, API key authorization and API parameter signing from a single dependency.
read the full Sa-Token overview →
About oauth2-proxy
OAuth2 Proxy is an open source, MIT licensed reverse proxy and middleware written in Go that puts OAuth2 and OpenID Connect authentication in front of web applications, aimed at operators and platform teams who need single sign on without adding auth code to every app.
read the full oauth2-proxy overview →
More in Security & Privacy
Related comparisons
More Identity & Access Management (IAM) projects
Compare either of these against the rest of the Identity & Access Management (IAM) field.
Frequently asked questions
Is Sa-Token or oauth2-proxy more popular?
Sa-Token has 19,051 GitHub stars and oauth2-proxy has 14,982. Sa-Token has the larger community by that measure.
Are Sa-Token and oauth2-proxy free?
Both are open source. Sa-Token is licensed under Apache-2.0 and oauth2-proxy under MIT. Neither carries a licence fee.
What is the difference between Sa-Token and oauth2-proxy?
Sa-Token is written in Java and oauth2-proxy in Go. The practical differences are community size, licence terms, language stack and release cadence — all compared in the table above.
Which should I choose, Sa-Token or oauth2-proxy?
Choose Sa-Token if you want the larger community (19,051 stars) or its Apache-2.0 licence terms. Choose oauth2-proxy if its feature set, stack or MIT licence fits better. Both are self-hostable.