head to head · open source
Sa-Token vs caddy-security
Sa-Token has 19,065 GitHub stars, 2,914 forks, 111 open issues and last shipped 3 days ago. caddy-security has 2,239 stars, 102 forks, 8 open issues and last shipped today. Sa-Token leads on adoption by 751% (19,065 vs 2,239 stars). Sa-Token is written in Java under Apache-2.0; caddy-security is written in Go under Apache-2.0. Sa-Token has attracted 15% as many forks as stars, caddy-security 5%. caddy-security was the more recently maintained of the two, and both are self-hostable with no licence fee. The two share 2 topic tags (authorization, sso), so they are genuine substitutes rather than adjacent tools.
Two open source projects, one decision. Both are free and self-hostable — the differences are community size, license terms, language stack and release pace.
← all 20902 open source comparisons
Side by side
| Sa-Token | caddy-security | |
|---|---|---|
| GitHub stars | ★ 19K | ★ 2.2K |
| License | Apache-2.0 | Apache-2.0 |
| Written in | Java | Go |
| Last push | 2026-09-24 | 2026-09-27 |
| Forks | ⑂ 2.9K | ⑂ 102 |
| Self-hosting | Yes | Yes |
| Data ownership | Your server | Your server |
pick Sa-Token if
- You weight community size — 19K stars and counting
- You want the Apache-2.0 license terms
- Your stack matches Java
- You value the larger contributor base for long-term maintenance
pick caddy-security if
- You want the caddy-security feature set and don't need the biggest community
- You prefer the Apache-2.0 license terms
- Your stack matches Go
- You evaluated both and caddy-security fits your workflow better
About Sa-Token
Sa Token is a free, open source, one stop Java authentication and authorization framework, licensed under Apache 2.0, that gives Java and Spring Boot developers login authentication, permission checks, distributed sessions, single sign on, OAuth2.0, gateway authentication, JWT integration, API key authorization and API parameter signing from a single dependency.
read the full Sa-Token overview →
About caddy-security
caddy security is an authentication, authorization, and accounting (AAA) app and plugin for Caddy v2 that implements form based, basic, local, LDAP, OpenID Connect, OAuth 2.0 and SAML sign in together with JWT and PASETO request authorization, and it is aimed at operators and security teams who terminate HTTP traffic with Caddy and want identity enforcement to happen inside the web server itself.
read the full caddy-security overview →
More in Security & Privacy
Related comparisons
More Identity & Access Management (IAM) projects
Compare either of these against the rest of the Identity & Access Management (IAM) field.
Frequently asked questions
Is Sa-Token or caddy-security more popular?
Sa-Token has 19,065 GitHub stars and caddy-security has 2,239. Sa-Token has the larger community by that measure.
Are Sa-Token and caddy-security free?
Both are open source. Sa-Token is licensed under Apache-2.0 and caddy-security under Apache-2.0. Neither carries a licence fee.
What is the difference between Sa-Token and caddy-security?
Sa-Token is written in Java and caddy-security in Go. The practical differences are community size, licence terms, language stack and release cadence — all compared in the table above.
Which should I choose, Sa-Token or caddy-security?
Choose Sa-Token if you want the larger community (19,065 stars) or its Apache-2.0 licence terms. Choose caddy-security if its feature set, stack or Apache-2.0 licence fits better. Both are self-hostable.