Repo of the Day
pocket-id/pocket-id: The most user-friendly OpenID Connect Certified™ and OAuth 2.0 provider that lets users sign in to your applications with passkeys.
Published: Oct 7, 2026
Open repository ↗The most user-friendly OpenID Connect Certified™ and OAuth 2.0 provider that lets users sign in to your applications with passkeys. - pocket-id/pocket-id
Summary
Pocket ID is a self-hosted OpenID Connect and OAuth 2.0 identity provider written in Go. Its defining feature is that it authenticates users exclusively with passkeys, so there is no password database to manage or protect. The README positions it as a simpler alternative to heavier self-hosted providers like Keycloak and ORY Hydra.
What it is useful for
Pocket ID is useful when an engineer wants to add single sign-on to a small set of self-hosted applications without standing up a full identity stack. Typical scenarios include protecting a homelab dashboard, a media server, a wiki, or an internal tool that already speaks OIDC. The passkey-only design also fits environments where hardware keys such as a Yubikey are the preferred authentication method, since the README explicitly mentions using a physical Yubikey to sign in to self-hosted services.
A few things to be aware of before adopting it:
- It only supports passkey authentication. Anyone who cannot or will not use a passkey cannot sign in, and there is no password or social-login fallback.
- The README compares it to Keycloak and ORY Hydra, which suggests it is aimed at simpler deployments rather than enterprise-scale identity scenarios with complex custom authentication flows.
- The repository is BSD-2-Clause licensed, which is permissive, but you should still review the terms for your own use.
How engineers can use it
The README recommends Docker as the easiest installation path and links to the official documentation at docs.pocket-id.org for the full setup guide. It does not include a copy-pasteable Docker command in the README itself, so the practical first step is to read the documentation, which covers environment variables, the database backend, and how to register an OIDC client for the application you want to protect.
A typical workflow is:
- Run Pocket ID in Docker and create an admin account using a passkey on your platform of choice.
- In the admin UI, create an OIDC client and note the client ID, client secret, and redirect URI.
- Point an OIDC-aware application at the Pocket ID discovery URL and complete a sign-in to confirm the flow works.
If you want to evaluate it without installing anything, the README points to a hosted demo at demo.pocket-id.org. Contributions follow the guide in CONTRIBUTING.md.