openvpn-auth-oauth2 is a free, open source identity & access management (iam) project written in Go and released under MIT. It has 516 GitHub stars, 64 forks and 1 open issues, and was last pushed 36 hours ago. On this registry it ranks #66 of 67 tracked projects in Identity & Access Management (IAM), with 5 head-to-head comparisons available.

What is openvpn-auth-oauth2?

openvpn-auth-oauth2 is an OpenVPN management client and plugin that lets VPN users sign in through any OIDC-compatible identity provider, aimed at administrators who want single sign-on for their OpenVPN server.

What it is

openvpn-auth-oauth2 is a Go project, released under the MIT License, that handles single sign-on authentication for an OpenVPN server by talking to the server's management interface (or connecting as a stable plugin on supported platforms) and completing the sign-in against an OIDC provider. It works with Microsoft Entra ID (Azure AD), GitHub, Okta, Google Workspace, Authentik, Zitadel, DigitalOcean, Keycloak, and any other OIDC-compatible authentication server. The project is documented through a wiki organized by task, covering OpenVPN requirements, installation, configuration, and deployment.

The concrete problem it solves is that OpenVPN's native authentication does not provide a browser-based, OIDC-driven login flow against a corporate or third-party identity provider. OpenVPN administrators who want users to authenticate with their existing accounts — rather than with separately provisioned VPN credentials — need a bridge between the OpenVPN server and an OIDC IdP, which is exactly the gap this project fills.

Key capabilities

  • Integrates with OpenVPN through two supported paths: the stable plugin on Linux AMD64, Linux ARM64, and FreeBSD AMD64, or directly via the OpenVPN management interface.
  • Supports OIDC single sign-on against Microsoft Entra ID (Azure AD), GitHub, Okta, Google Workspace, Authentik, Zitadel, DigitalOcean, and Keycloak.
  • Works with any other OIDC-compatible authentication server, as documented in the wiki's Providers page.
  • Ships as downstream packages across multiple distributions, tracked by its Repology packaging badge.
  • Provides a Docker Compose demo for trying the project locally before deploying.
  • Offers a Getting Started guide that compares the plugin and management-interface integration options so administrators can choose between them.
  • Runs in production environments: the repository maintains an ADOPTERS.md listing real users and success stories contributed by organizations.

Who uses it and how

  • Teams whose users already authenticate through Microsoft Entra ID, Okta, Google Workspace, or Keycloak and who want those same accounts to open a VPN session.
  • Organizations self-hosting their identity provider with Authentik, Zitadel, or Keycloak and fronting an OpenVPN server with it.
  • Administrators running OpenVPN on Linux AMD64, Linux ARM64, or FreeBSD AMD64, where the stable plugin integration is available.
  • Operators who evaluate the setup first with the Docker Compose demo, then follow the task-organized wiki to deploy.
  • Production users who document their deployment in ADOPTERS.md via pull request.

Getting started

Follow the Getting Started guide in the project wiki for a first deployment, using the Installation Guide for package and source-build options, or run the Docker Compose demo to try it locally.

How it compares

Among similar tools, the README names openvpn-auth-aad (CyberNinjas), openvpn-oidc (vitaliy-sn), and the same author's earlier openvpn-auth-azure-ad; openvpn-auth-oauth2 differs by targeting any OIDC-compatible provider rather than a single identity backend. Its MIT licence and downstream packaging across distributions also make it straightforward to evaluate against those narrower alternatives.

When to use it — and when not

You need to operate the OpenVPN server, its management interface or plugin configuration, and a working OIDC provider, and the plugin path is limited to Linux AMD64, Linux ARM64, and FreeBSD AMD64 — other platforms must use the management interface. The licence is clear (MIT) and only one issue is open, but the project is a bridge rather than a full IAM solution: teams without an OIDC provider, or those needing authentication mechanisms beyond OIDC, should look elsewhere.

project readme (upstream, from github) — read inline

CI GitHub license Current Release GitHub Repo stars GitHub all releases codecov

openvpn-auth-oauth2 logo

openvpn-auth-oauth2

⭐ Don't forget to star this repository! ⭐

Adopters and Users

Are you using openvpn-auth-oauth2 in production or as part of your infrastructure?

Share your experience and help others understand how openvpn-auth-oauth2 is used in real-world environments.

You can find existing users and success stories in ADOPTERS.md.

If you are using openvpn-auth-oauth2, feel free to add your organization or a short success story through a pull request.

About

openvpn-auth-oauth2 is a management client for OpenVPN that handles the single sign-on (SSO) authentication against various OIDC providers. This project aims to simplify the process of integrating OpenVPN with OIDC providers such as

Getting Started

The complete wiki is organized by task and remains available from the documentation home.

OpenVPN can connect through the stable plugin on Linux AMD64, Linux ARM64, and FreeBSD AMD64, or directly through its management interface. The Getting Started guide compares both supported options.

Installation

For package and source-build options, see the Installation Guide.

Downstream Packages

Packaging status

Configuration

For information on how to configure openvpn-auth-oauth2, please refer to the Configuration Guide.

OpenVPN Version Requirements

For information on the OpenVPN version requirements, please refer to the OpenVPN Guide.

Related Projects

Contributing

See the contributing guide to propose and submit changes.

License

This project is licensed under the MIT License.

Open Source Sponsors

Thanks to all sponsors!

Acknowledgements

Thanks to JetBrains IDEs and Sparklabs for their support.

Frequently asked questions

Is openvpn-auth-oauth2 free to use?

openvpn-auth-oauth2 is open source under the MIT licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does openvpn-auth-oauth2 do?

openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows

What is openvpn-auth-oauth2 written in?

openvpn-auth-oauth2 is primarily written in Go. Its source is publicly available at https://github.com/jkroepke/openvpn-auth-oauth2, and it has 516 GitHub stars.