Open source oauth projects

Every project in the registry tagged oauth, ranked by real GitHub adoption.

projects 9 combined stars ★ 123K refresh nightly
01 Tailscale ★ 37K

Zero-config VPN with WireGuard for secure networking

last push6 hours ago languageGo licenseBSD-3-Clause
02 Better Auth ★ 30K

Framework-agnostic authentication for TypeScript applications

last push11 hours ago languageTypeScript licenseMIT
03 SuperTokens ★ 15K

Secure, customizable authentication for your applications

last push4 days ago languageJava license
04 Nango ★ 12K

Build product integrations with 500+ APIs in hours

last push6 hours ago languageTypeScript license
05 hanko ★ 9.0K

last push6 hours ago languageGo license
06 Hexclave ★ 6.9K

Modular auth, payments, emails, and analytics for your product

last push8 hours ago languageTypeScript license
07 open-connector ★ 5.8K

Open-source auth gateway connecting 1500+ SaaS providers to AI agents through SDK, CLI, MCP, HTTP, and OpenAPI.

last push16 hours ago languageTypeScript licenseApache-2.0
08 praw ★ 4.3K

PRAW, an acronym for "Python Reddit API Wrapper", is a python package that allows for simple access to Reddit's API.

last push3 days ago languagePython licenseBSD-2-Clause
09 Defguard ★ 2.8K

Zero-Trust VPN with built-in 2FA/MFA and SSO capabilities

last push12 hours ago languageRust license

Related tags

← all tags

Frequently asked questions

How many open source oauth projects are there?

This registry tracks 9 projects tagged oauth, with 122,871 GitHub stars between them. The most-adopted is Tailscale at 36,587 stars.

Are these oauth projects free to use?

Yes — 4 of the 9 carry an explicit open-source licence across 4 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.

Which oauth project should I choose?

The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.

Are these oauth projects still maintained?

9 of the 9 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.