{"repo":"Shrpp/ovlt","free":true,"listed":false,"github":"https://github.com/Shrpp/ovlt","clone":"git clone https://github.com/Shrpp/ovlt.git","description":"Lightweight OIDC Authorization Server in Rust. Authorization Code + PKCE, RS256, multi-tenant RLS, AES-256-GCM zero-knowledge encryption. < 50 MB RAM.","language":"Rust","stars":51,"topics":["authentication","authorization-server","axum","multi-tenant","oauth2","oidc","rust","self-hosted","zero-knowledge"],"license":"MIT","category":"auth-billing-email","readme_excerpt":"Self-hosted OIDC auth in a single Rust binary. OAuth2 + OIDC · Multi-tenant via Postgres RLS · --- ⚠ Alpha build. Not production ready. APIs and configuration may change. Stable beta target: Q3 2026. See Roadmap and Security for current state and known gaps. OVLT is a self-hosted OIDC authorization server in Rust, designed for indie hackers and small teams who want OIDC without the operational overhead of Keycloak or the per-seat cost of hosted alternatives. Single binary, Postgres-only, no sidecars. Built with Rust + Axum + PostgreSQL RLS . Powered by hefesto. --- Quick Start Secrets ( JWT SECRET , MASTER ENCRYPTION KEY , TENANT WRAP KEY ) are auto-generated on first run and printed to logs. Save them somewhere safe before restarting the container. Once running, see Getting Started to create your first tenant and integrate a client application. --- Features --- --- 🔐 OIDC Authorization Server Authorization Code + PKCE, client credentials (M2M), RS256 id tokens, JWKS endpoint, OpenID discovery 🏢 Multi-tenant isolation PostgreSQL Row-Level Security — tenant boundaries enforced at the database layer, not the application layer 🔒 Encryption at rest AES-256-GCM envelope encryption for sensitive fields (TOTP secrets, SMTP credentials, IdP secrets) via hefesto 📱 MFA TOTP (RFC 6238) + WebAuthn/Passkeys (FIDO2 Level 2) — manage via TUI or API 🌐 Social login Google and GitHub OAuth2 — per-tenant IdP config, stored encrypted, manageable via TUI 📧 Per-tenant SMTP Encrypted credenti","default_branch":null,"files":null,"tree":[],"storefront":"/r/Shrpp","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Shrpp/ovlt/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}