{"repo":"puzed/darkauth","free":true,"listed":false,"github":"https://github.com/puzed/darkauth","clone":"git clone https://github.com/puzed/darkauth.git","description":"A zero-knowledge authentication system with OIDC compatibility","language":"TypeScript","stars":11,"topics":["oauth","oidc","opaque","zero-knowledge","rfc-9380"],"license":null,"category":"auth-billing-email","readme_excerpt":"DarkAuth A zero-knowledge authentication system with OIDC compatibility. DarkAuth implements OPAQUE (RFC 9380) for password authentication where the server never learns the password, and provides optional zero-knowledge delivery of Data Root Keys (DRK) to trusted clients. DarkAuth is open source and self-hosted. There is no paid plan, subscription, or cloud service. A ready-to-run Docker image is available at ghcr.io/puzed/darkauth:latest . For local OIDC development without a real identity database, use the app-agnostic ghcr.io/puzed/darkauth-mock:latest image with a mounted YAML identity configuration. Features - Zero-Knowledge Password Auth : OPAQUE protocol ensures passwords never reach the server - OIDC Compatible : Standard OAuth 2.0/OpenID Connect for universal compatibility - Zero-Knowledge DRK Delivery : Optional fragment-based JWE delivery for trusted clients - TOTP MFA : Time-based one-time passwords for users and admins with backup codes, rate limits, and per-organization enforcement - Email Password Reset : SMTP-gated self-service reset links with hashed one-time tokens and session invalidation - Database-Backed Configuration : Most settings stored in PostgreSQL; minimal config.yaml for bootstrap - Two-Port Architecture : Separate ports for user (9080) and admin (9081). First-run installer is served on the admin port until setup completes. - Secure Key Storage : Optional encryption of private keys at rest using Argon2id-derived KEK - RBAC Support : Fine-grained p","default_branch":null,"files":null,"tree":[],"storefront":"/r/puzed","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/puzed/darkauth/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}