head to head · open source
tinyauth vs caddy-security
tinyauth has 8,290 GitHub stars, 273 forks, 41 open issues and last shipped yesterday. caddy-security has 2,239 stars, 102 forks, 8 open issues and last shipped today. tinyauth leads on adoption by 270% (8,290 vs 2,239 stars). tinyauth is written in Go under AGPL-3.0; caddy-security is written in Go under Apache-2.0. tinyauth has attracted 3% as many forks as stars, caddy-security 5%. caddy-security was the more recently maintained of the two, and both are self-hostable with no licence fee. The two share 2 topic tags (authentication, sso), so they are genuine substitutes rather than adjacent tools.
Two open source projects, one decision. Both are free and self-hostable — the differences are community size, license terms, language stack and release pace.
← all 20902 open source comparisons
Side by side
| tinyauth | caddy-security | |
|---|---|---|
| GitHub stars | ★ 8.3K | ★ 2.2K |
| License | AGPL-3.0 | Apache-2.0 |
| Written in | Go | Go |
| Last push | 2026-09-26 | 2026-09-27 |
| Forks | ⑂ 273 | ⑂ 102 |
| Self-hosting | Yes | Yes |
| Data ownership | Your server | Your server |
pick tinyauth if
- You weight community size — 8.3K stars and counting
- You want the AGPL-3.0 license terms
- Your stack matches Go
- You value the larger contributor base for long-term maintenance
pick caddy-security if
- You want the caddy-security feature set and don't need the biggest community
- You prefer the Apache-2.0 license terms
- Your stack matches Go
- You evaluated both and caddy-security fits your workflow better
About tinyauth
Tinyauth is a small Go authentication and authorization server that runs either as authentication middleware in front of self hosted applications or as a standalone authentication server, and it is aimed at self hosters and homelab operators who want OpenID Certified™ single sign on without deploying a large identity platform.
read the full tinyauth overview →
About caddy-security
caddy security is an authentication, authorization, and accounting (AAA) app and plugin for Caddy v2 that implements form based, basic, local, LDAP, OpenID Connect, OAuth 2.0 and SAML sign in together with JWT and PASETO request authorization, and it is aimed at operators and security teams who terminate HTTP traffic with Caddy and want identity enforcement to happen inside the web server itself.
read the full caddy-security overview →
More in Security & Privacy
Related comparisons
More Identity & Access Management (IAM) projects
Compare either of these against the rest of the Identity & Access Management (IAM) field.
Frequently asked questions
Is tinyauth or caddy-security more popular?
tinyauth has 8,290 GitHub stars and caddy-security has 2,239. tinyauth has the larger community by that measure.
Are tinyauth and caddy-security free?
Both are open source. tinyauth is licensed under AGPL-3.0 and caddy-security under Apache-2.0. Neither carries a licence fee.
What is the difference between tinyauth and caddy-security?
tinyauth is written in Go and caddy-security in Go. The practical differences are community size, licence terms, language stack and release cadence — all compared in the table above.
Which should I choose, tinyauth or caddy-security?
Choose tinyauth if you want the larger community (8,290 stars) or its AGPL-3.0 licence terms. Choose caddy-security if its feature set, stack or Apache-2.0 licence fits better. Both are self-hostable.