openvpn-auth-oauth2 is an OpenVPN management client and plugin that lets VPN users sign in through any OIDC-compatible identity provider, aimed at administrators who want single sign-on for their OpenVPN server.
What it is
openvpn-auth-oauth2 is a Go project, released under the MIT License, that handles single sign-on authentication for an OpenVPN server by talking to the server's management interface (or connecting as a stable plugin on supported platforms) and completing the sign-in against an OIDC provider. It works with Microsoft Entra ID (Azure AD), GitHub, Okta, Google Workspace, Authentik, Zitadel, DigitalOcean, Keycloak, and any other OIDC-compatible authentication server. The project is documented through a wiki organized by task, covering OpenVPN requirements, installation, configuration, and deployment.
The concrete problem it solves is that OpenVPN's native authentication does not provide a browser-based, OIDC-driven login flow against a corporate or third-party identity provider. OpenVPN administrators who want users to authenticate with their existing accounts — rather than with separately provisioned VPN credentials — need a bridge between the OpenVPN server and an OIDC IdP, which is exactly the gap this project fills.
Key capabilities
- Integrates with OpenVPN through two supported paths: the stable plugin on Linux AMD64, Linux ARM64, and FreeBSD AMD64, or directly via the OpenVPN management interface.
- Supports OIDC single sign-on against Microsoft Entra ID (Azure AD), GitHub, Okta, Google Workspace, Authentik, Zitadel, DigitalOcean, and Keycloak.
- Works with any other OIDC-compatible authentication server, as documented in the wiki's Providers page.
- Ships as downstream packages across multiple distributions, tracked by its Repology packaging badge.
- Provides a Docker Compose demo for trying the project locally before deploying.
- Offers a Getting Started guide that compares the plugin and management-interface integration options so administrators can choose between them.
- Runs in production environments: the repository maintains an ADOPTERS.md listing real users and success stories contributed by organizations.
Who uses it and how
- Teams whose users already authenticate through Microsoft Entra ID, Okta, Google Workspace, or Keycloak and who want those same accounts to open a VPN session.
- Organizations self-hosting their identity provider with Authentik, Zitadel, or Keycloak and fronting an OpenVPN server with it.
- Administrators running OpenVPN on Linux AMD64, Linux ARM64, or FreeBSD AMD64, where the stable plugin integration is available.
- Operators who evaluate the setup first with the Docker Compose demo, then follow the task-organized wiki to deploy.
- Production users who document their deployment in ADOPTERS.md via pull request.
Getting started
Follow the Getting Started guide in the project wiki for a first deployment, using the Installation Guide for package and source-build options, or run the Docker Compose demo to try it locally.
How it compares
Among similar tools, the README names openvpn-auth-aad (CyberNinjas), openvpn-oidc (vitaliy-sn), and the same author's earlier openvpn-auth-azure-ad; openvpn-auth-oauth2 differs by targeting any OIDC-compatible provider rather than a single identity backend. Its MIT licence and downstream packaging across distributions also make it straightforward to evaluate against those narrower alternatives.
When to use it — and when not
You need to operate the OpenVPN server, its management interface or plugin configuration, and a working OIDC provider, and the plugin path is limited to Linux AMD64, Linux ARM64, and FreeBSD AMD64 — other platforms must use the management interface. The licence is clear (MIT) and only one issue is open, but the project is a bridge rather than a full IAM solution: teams without an OIDC provider, or those needing authentication mechanisms beyond OIDC, should look elsewhere.
project readme (upstream, from github) — read inline

openvpn-auth-oauth2
⭐ Don't forget to star this repository! ⭐
Adopters and Users
Are you using openvpn-auth-oauth2 in production or as part of your infrastructure?
Share your experience and help others understand how openvpn-auth-oauth2 is used in real-world environments.
You can find existing users and success stories in ADOPTERS.md.
If you are using openvpn-auth-oauth2, feel free to add your organization or a short success story through a pull request.
About
openvpn-auth-oauth2 is a management client for OpenVPN that handles
the single sign-on (SSO) authentication against various OIDC providers. This project aims to simplify the process of
integrating OpenVPN with OIDC providers such as
Getting Started
The complete wiki is organized by task and remains available from the
documentation home.
OpenVPN can connect through the stable plugin on Linux AMD64, Linux ARM64, and
FreeBSD AMD64, or directly through its management interface. The
Getting Started guide
compares both supported options.
Installation
For package and source-build options, see the
Installation Guide.
Downstream Packages

Configuration
For information on how to configure openvpn-auth-oauth2, please refer to the Configuration Guide.
OpenVPN Version Requirements
For information on the OpenVPN version requirements, please refer to the OpenVPN Guide.
Related Projects
Contributing
See the contributing guide to propose and submit changes.
License
This project is licensed under the MIT License.
Open Source Sponsors
Thanks to all sponsors!
Acknowledgements
Thanks to JetBrains IDEs and Sparklabs for their support.