# What is Logto? A Complete Guide to the Open-Source Identity Platform

> Discover Logto, the open-source identity platform offering a full OIDC/OAuth 2.1/SAML stack with multi-tenancy and type-safe SDKs. Secure your SaaS and AI apps today.

- Repository: [Logto/logto](https://github.com/logto-io/logto)
- Tags: getting-started
- Published: 2026-07-02

---

**Logto is a modern, open-source identity and access management (IAM) infrastructure that provides a complete OIDC/OAuth 2.1/SAML stack with multi-tenancy, enterprise SSO, and type-safe SDKs for SaaS and AI applications.**

Logto is an open-source authentication platform maintained by the logto-io organization that bundles backend authentication services, customizable frontend sign-in flows, and extensible identity connectors into a single, self-hostable solution. Designed to replace commercial identity providers like Auth0 or Cognito, Logto offers modular architecture built on a PNPM monorepo structure, enabling developers to implement secure authentication with minimal boilerplate while maintaining full control over user data.

## Core Architecture and Multi-Tenancy

The Logto platform centers on a robust multi-tenant architecture implemented in the `@logto/core` package, where each tenant operates as an isolated environment with dedicated database connections and signing keys.

### The Core Backend (@logto/core)

The heart of Logto resides in `packages/core/src`, implementing the OIDC provider, token handling, and sophisticated libraries for password policies, MFA, adaptive MFA, captcha, and quota management. This package exposes the primary authentication logic that handles everything from credential validation to session management, all while maintaining strict tenant isolation.

### Tenant Isolation Model

Each tenant is represented by the `Tenant` class defined in [`packages/core/src/tenants/Tenant.ts`](https://github.com/logto-io/logto/blob/main/packages/core/src/tenants/Tenant.ts). This class encapsulates tenant-specific resources including database connections, cryptographic signing keys, and configuration settings. The architecture uses `TenantContext` and `Queries` abstractions to ensure all database queries are automatically scoped to the requesting tenant, allowing multiple tenants to safely share a single PostgreSQL instance without data leakage risks.

## Developer Experience and Management API

Logto prioritizes developer experience through type-safe APIs and automated tooling that reduces integration complexity.

### Type-Safe Management API Client

The platform provides a generated, type-safe Management API client through the `@logto/api` package. The `createManagementApi` helper function in [`packages/api/src/management.ts`](https://github.com/logto-io/logto/blob/main/packages/api/src/management.ts) constructs a client that automatically handles machine-to-machine authentication, including access token acquisition and refresh cycles.

```typescript
import { createManagementApi } from '@logto/api/management';

const { apiClient, clientCredentials } = createManagementApi('default', {
  clientId: 'my-client-id',
  clientSecret: 'my-client-secret',
  baseUrl: 'https://my-logto-instance.com',
  apiIndicator: 'https://default.logto.app/api',
});

const response = await apiClient.GET('/api/users');

```

*The `createManagementApi` utility automatically injects the `Authorization` header and manages token lifecycle for every request.*

## Sign-In Experience and Frontend Components

Logto delivers a complete authentication user interface through the `@logto/experience` package, offering customizable, plug-and-play sign-in flows.

### Customizable Authentication Flows

The experience layer supports passwordless passkeys (WebAuthn), social identity providers, and multi-factor authentication (MFA). Built with LitElement components under `packages/elements`, the UI provides deep customization options while maintaining security best practices.

```tsx
import { SignIn } from '@logto/react';

function App() {
  return (
    <SignIn
      endpoint="https://my-tenant.logto.app"
      theme={{ primaryColor: '#4A90E2' }}
    />
  );
}

```

*The `<SignIn>` component manages the complete OIDC flow, rendering Logto's hosted sign-in page and handling token exchange automatically.*

## Extensible Connectors and Protocols

Logto ships with an extensible connector system defined in `packages/connectors`, allowing integration with external identity providers without modifying core authentication logic. Each connector follows a common interface supporting protocols including OAuth 2.1, OIDC, SAML, and custom SMS/Email verification providers. The connector architecture enables developers to add new identity sources—such as the OIDC connector implementation detailed in [`packages/connectors/connector-oidc/README.md`](https://github.com/logto-io/logto/blob/main/packages/connectors/connector-oidc/README.md)—through a standardized plugin system.

## Deployment Options

Logto supports flexible deployment strategies optimized for both development and production environments.

### Docker Compose Quick Start

For local development, Logto provides a complete Docker Compose configuration that orchestrates PostgreSQL, the Core service, and the React-based admin console. The following command pulls the official configuration and launches the entire stack:

```bash
curl -fsSL https://raw.githubusercontent.com/logto-io/logto/HEAD/docker-compose.yml | \
docker compose -p logto -f - up

```

*This deployment exposes PostgreSQL on port 5432, the Core API on ports 3001/3002, and the admin console on port 5002.*

## Summary

- **Logto** is a comprehensive, open-source IAM platform providing OIDC/OAuth 2.1/SAML authentication with enterprise-grade multi-tenancy.
- The **Tenant class** in [`packages/core/src/tenants/Tenant.ts`](https://github.com/logto-io/logto/blob/main/packages/core/src/tenants/Tenant.ts) ensures strict data isolation while allowing efficient resource sharing across tenants.
- **Management API** operations are streamlined through the type-safe `createManagementApi` client in [`packages/api/src/management.ts`](https://github.com/logto-io/logto/blob/main/packages/api/src/management.ts).
- **Frontend integration** is accelerated through React components and LitElement-based UI elements that handle complex OIDC flows automatically.
- The **connector system** in `packages/connectors` enables protocol extensibility without core code modifications.
- Full **self-hosting** is supported via Docker Compose with minimal configuration requirements.

## Frequently Asked Questions

### What protocols does Logto support?

Logto implements a complete authentication protocol stack including OIDC (OpenID Connect), OAuth 2.1, and SAML 2.0. The core implementation in `packages/core/src` handles token issuance, validation, and session management according to these standards, while the connector system in `packages/connectors` allows integration with external providers using these same protocols.

### How does Logto handle multi-tenancy?

Logto implements architectural isolation through the `Tenant` class in [`packages/core/src/tenants/Tenant.ts`](https://github.com/logto-io/logto/blob/main/packages/core/src/tenants/Tenant.ts). Each tenant receives dedicated database connections, signing keys, and configuration scopes via the `TenantContext` abstraction. This design allows multiple tenants to share a single PostgreSQL instance while maintaining complete data separation at the query level.

### Can I self-host Logto?

Yes, Logto is designed for self-hosting as an open-source alternative to managed identity providers. The repository provides a [`docker-compose.yml`](https://github.com/logto-io/logto/blob/main/docker-compose.yml) file that orchestrates PostgreSQL, the Core service, and the admin console. You can launch a complete instance using the Docker Compose one-liner or through the `npm init @logto` quick-start script for local development.

### How do I manage users programmatically?

User management is performed through the Management API using the type-safe client generated from OpenAPI specifications. The `createManagementApi` function in [`packages/api/src/management.ts`](https://github.com/logto-io/logto/blob/main/packages/api/src/management.ts) creates a client that automatically handles machine-to-machine authentication, allowing you to list, create, update, or delete users, applications, and connectors via standard REST operations.