Pocket ID: Passkey-Only Single Sign-On for Your Self-Hosted Apps
Pocket ID is an OpenID Connect (OIDC) identity provider that lets you log in to your self-hosted apps with passkeys, and only passkeys. There are no passwords to set, forget, phish, or leak.
It comes from the developer of Pingvin Share, who archived that project in 2025 to focus on Pocket ID.
Why passkeys only
A passkey is a key pair: the private key stays on your phone, laptop, or hardware security key like a YubiKey, and the server only holds the public key. There is nothing on the server worth stealing and nothing a phishing site can capture. Removing passwords entirely also removes the whole reset, reuse, and brute-force problem.
Features
- OpenID Connect Certified and OAuth 2.0 compliant, so it works with any app that supports OIDC
- Passkey-only login, including hardware security keys
- A deliberately simple interface compared with Keycloak or Authentik
- User and group management, with groups passed to apps as claims
What it works with
Anything with OIDC login: Immich, Jellyfin (via plugin), Grafana, Forgejo, Nextcloud, Paperless-ngx, Proxmox, and many more. For apps without any SSO support, pair it with a forward-auth proxy such as Tinyauth, which can use Pocket ID as its login provider.
Deployment
Pocket ID is a small Go backend with a web frontend, deployed with Docker Compose. It must be served over HTTPS on a real domain name, because browsers only allow passkeys on secure origins. Put it behind a reverse proxy with a TLS certificate.
Plan recovery before you depend on it: register at least two passkeys per admin account, such as a phone and a hardware key, so losing one device does not lock you out of every app.
How it compares
| Pocket ID | Authelia | Authentik / Keycloak | |
|---|---|---|---|
| Complexity | Very low | Low | High |
| Passwords | None | Yes, plus 2FA | Yes, plus many flows |
| OIDC provider | Yes | Yes | Yes |
| Forward auth | Via Tinyauth | Built in | Built in |
| LDAP, SAML, flows | No | Limited | Extensive |
License
BSD-2-Clause.