head to head · open source
Sa-Token vs tinyauth
Sa-Token has 19,055 GitHub stars, 2,913 forks, 111 open issues and last shipped 4 days ago. tinyauth has 8,271 stars, 272 forks, 41 open issues and last shipped yesterday. Sa-Token leads on adoption by 130% (19,055 vs 8,271 stars). Sa-Token is written in Java under Apache-2.0; tinyauth is written in Go under AGPL-3.0. Sa-Token has attracted 15% as many forks as stars, tinyauth 3%. tinyauth was the more recently maintained of the two, and both are self-hostable with no licence fee. The two share 1 topic tag (sso), so they are genuine substitutes rather than adjacent tools.
Two open source projects, one decision. Both are free and self-hostable — the differences are community size, license terms, language stack and release pace.
← all 20902 open source comparisons
Side by side
| Sa-Token | tinyauth | |
|---|---|---|
| GitHub stars | ★ 19K | ★ 8.3K |
| License | Apache-2.0 | AGPL-3.0 |
| Written in | Java | Go |
| Last push | 2026-09-18 | 2026-09-21 |
| Forks | ⑂ 2.9K | ⑂ 272 |
| Self-hosting | Yes | Yes |
| Data ownership | Your server | Your server |
pick Sa-Token if
- You weight community size — 19K stars and counting
- You want the Apache-2.0 license terms
- Your stack matches Java
- You value the larger contributor base for long-term maintenance
pick tinyauth if
- You want the tinyauth feature set and don't need the biggest community
- You prefer the AGPL-3.0 license terms
- Your stack matches Go
- You evaluated both and tinyauth fits your workflow better
About Sa-Token
Sa Token is a free, open source, one stop Java authentication and authorization framework, licensed under Apache 2.0, that gives Java and Spring Boot developers login authentication, permission checks, distributed sessions, single sign on, OAuth2.0, gateway authentication, JWT integration, API key authorization and API parameter signing from a single dependency.
read the full Sa-Token overview →
About tinyauth
Tinyauth is a small Go authentication and authorization server that runs either as authentication middleware in front of self hosted applications or as a standalone authentication server, and it is aimed at self hosters and homelab operators who want OpenID Certified™ single sign on without deploying a large identity platform.
read the full tinyauth overview →
More in Security & Privacy
Related comparisons
More Identity & Access Management (IAM) projects
Compare either of these against the rest of the Identity & Access Management (IAM) field.
Frequently asked questions
Is Sa-Token or tinyauth more popular?
Sa-Token has 19,055 GitHub stars and tinyauth has 8,271. Sa-Token has the larger community by that measure.
Are Sa-Token and tinyauth free?
Both are open source. Sa-Token is licensed under Apache-2.0 and tinyauth under AGPL-3.0. Neither carries a licence fee.
What is the difference between Sa-Token and tinyauth?
Sa-Token is written in Java and tinyauth in Go. The practical differences are community size, licence terms, language stack and release cadence — all compared in the table above.
Which should I choose, Sa-Token or tinyauth?
Choose Sa-Token if you want the larger community (19,055 stars) or its Apache-2.0 licence terms. Choose tinyauth if its feature set, stack or AGPL-3.0 licence fits better. Both are self-hostable.