Pocket ID: Passkey-Only Single Sign-On for Your Self-Hosted Apps

Pocket ID: Passkey-Only Single Sign-On for Your Self-Hosted Apps

Pocket ID is an OpenID Connect (OIDC) identity provider that lets you log in to your self-hosted apps with passkeys, and only passkeys. There are no passwords to set, forget, phish, or leak.

It comes from the developer of Pingvin Share, who archived that project in 2025 to focus on Pocket ID.

Why passkeys only

A passkey is a key pair: the private key stays on your phone, laptop, or hardware security key like a YubiKey, and the server only holds the public key. There is nothing on the server worth stealing and nothing a phishing site can capture. Removing passwords entirely also removes the whole reset, reuse, and brute-force problem.

Features

  • OpenID Connect Certified and OAuth 2.0 compliant, so it works with any app that supports OIDC
  • Passkey-only login, including hardware security keys
  • A deliberately simple interface compared with Keycloak or Authentik
  • User and group management, with groups passed to apps as claims

What it works with

Anything with OIDC login: Immich, Jellyfin (via plugin), Grafana, Forgejo, Nextcloud, Paperless-ngx, Proxmox, and many more. For apps without any SSO support, pair it with a forward-auth proxy such as Tinyauth, which can use Pocket ID as its login provider.

Deployment

Pocket ID is a small Go backend with a web frontend, deployed with Docker Compose. It must be served over HTTPS on a real domain name, because browsers only allow passkeys on secure origins. Put it behind a reverse proxy with a TLS certificate.

Plan recovery before you depend on it: register at least two passkeys per admin account, such as a phone and a hardware key, so losing one device does not lock you out of every app.

How it compares

Pocket IDAutheliaAuthentik / Keycloak
ComplexityVery lowLowHigh
PasswordsNoneYes, plus 2FAYes, plus many flows
OIDC providerYesYesYes
Forward authVia TinyauthBuilt inBuilt in
LDAP, SAML, flowsNoLimitedExtensive

License

BSD-2-Clause.