Tinyauth: A Tiny Login Screen for Any App Behind Your Reverse Proxy

Tinyauth: A Tiny Login Screen for Any App Behind Your Reverse Proxy

Tinyauth puts a login screen in front of any web app, even one with no authentication of its own. It works as forward-auth middleware: your reverse proxy asks Tinyauth whether each request is allowed before passing it to the app.

Why forward auth

Plenty of useful self-hosted tools have weak or no login: dashboards, file browsers, admin panels, the *arr apps. Putting each one behind a single sign-on gate means one login, one place to enforce two-factor authentication, and no app-specific password databases.

Authelia and Authentik do this too. Tinyauth’s appeal is how little it takes: a small Go service and a few labels.

Features

  • Forward auth for Traefik, Caddy, and Nginx
  • Login with local users, OAuth providers (Google, GitHub, or your own OIDC server such as Pocket ID), or LDAP (such as lldap)
  • TOTP two-factor authentication
  • Access controls per app: which users or groups may reach which service
  • It can also act as an OpenID Connect provider itself, and is OpenID certified

How it looks with Traefik

A typical setup adds middleware labels to each protected container:

labels:
  traefik.http.routers.whoami.middlewares: tinyauth

With the tinyauth middleware defined once, pointing Traefik’s forwardAuth at Tinyauth’s verification endpoint. Caddy (forward_auth) and Nginx (auth_request) work the same way. The documentation has complete examples for each proxy.

When to choose something else

Tinyauth is ideal for a homelab with a handful of users. If you need complex policies, SAML, user self-service, or many identity flows, Authentik or Keycloak are built for that.

License

AGPL-3.0.