What is Logto? A Complete Guide to the Open-Source Identity Platform
Logto is a modern, open-source identity and access management (IAM) infrastructure that provides a complete OIDC/OAuth 2.1/SAML stack with multi-tenancy, enterprise SSO, and type-safe SDKs for SaaS and AI applications.
Logto is an open-source authentication platform maintained by the logto-io organization that bundles backend authentication services, customizable frontend sign-in flows, and extensible identity connectors into a single, self-hostable solution. Designed to replace commercial identity providers like Auth0 or Cognito, Logto offers modular architecture built on a PNPM monorepo structure, enabling developers to implement secure authentication with minimal boilerplate while maintaining full control over user data.
Core Architecture and Multi-Tenancy
The Logto platform centers on a robust multi-tenant architecture implemented in the @logto/core package, where each tenant operates as an isolated environment with dedicated database connections and signing keys.
The Core Backend (@logto/core)
The heart of Logto resides in packages/core/src, implementing the OIDC provider, token handling, and sophisticated libraries for password policies, MFA, adaptive MFA, captcha, and quota management. This package exposes the primary authentication logic that handles everything from credential validation to session management, all while maintaining strict tenant isolation.
Tenant Isolation Model
Each tenant is represented by the Tenant class defined in packages/core/src/tenants/Tenant.ts. This class encapsulates tenant-specific resources including database connections, cryptographic signing keys, and configuration settings. The architecture uses TenantContext and Queries abstractions to ensure all database queries are automatically scoped to the requesting tenant, allowing multiple tenants to safely share a single PostgreSQL instance without data leakage risks.
Developer Experience and Management API
Logto prioritizes developer experience through type-safe APIs and automated tooling that reduces integration complexity.
Type-Safe Management API Client
The platform provides a generated, type-safe Management API client through the @logto/api package. The createManagementApi helper function in packages/api/src/management.ts constructs a client that automatically handles machine-to-machine authentication, including access token acquisition and refresh cycles.
import { createManagementApi } from '@logto/api/management';
const { apiClient, clientCredentials } = createManagementApi('default', {
clientId: 'my-client-id',
clientSecret: 'my-client-secret',
baseUrl: 'https://my-logto-instance.com',
apiIndicator: 'https://default.logto.app/api',
});
const response = await apiClient.GET('/api/users');
The createManagementApi utility automatically injects the Authorization header and manages token lifecycle for every request.
Sign-In Experience and Frontend Components
Logto delivers a complete authentication user interface through the @logto/experience package, offering customizable, plug-and-play sign-in flows.
Customizable Authentication Flows
The experience layer supports passwordless passkeys (WebAuthn), social identity providers, and multi-factor authentication (MFA). Built with LitElement components under packages/elements, the UI provides deep customization options while maintaining security best practices.
import { SignIn } from '@logto/react';
function App() {
return (
<SignIn
endpoint="https://my-tenant.logto.app"
theme={{ primaryColor: '#4A90E2' }}
/>
);
}
The <SignIn> component manages the complete OIDC flow, rendering Logto's hosted sign-in page and handling token exchange automatically.
Extensible Connectors and Protocols
Logto ships with an extensible connector system defined in packages/connectors, allowing integration with external identity providers without modifying core authentication logic. Each connector follows a common interface supporting protocols including OAuth 2.1, OIDC, SAML, and custom SMS/Email verification providers. The connector architecture enables developers to add new identity sources—such as the OIDC connector implementation detailed in packages/connectors/connector-oidc/README.md—through a standardized plugin system.
Deployment Options
Logto supports flexible deployment strategies optimized for both development and production environments.
Docker Compose Quick Start
For local development, Logto provides a complete Docker Compose configuration that orchestrates PostgreSQL, the Core service, and the React-based admin console. The following command pulls the official configuration and launches the entire stack:
curl -fsSL https://raw.githubusercontent.com/logto-io/logto/HEAD/docker-compose.yml | \
docker compose -p logto -f - up
This deployment exposes PostgreSQL on port 5432, the Core API on ports 3001/3002, and the admin console on port 5002.
Summary
- Logto is a comprehensive, open-source IAM platform providing OIDC/OAuth 2.1/SAML authentication with enterprise-grade multi-tenancy.
- The Tenant class in
packages/core/src/tenants/Tenant.tsensures strict data isolation while allowing efficient resource sharing across tenants. - Management API operations are streamlined through the type-safe
createManagementApiclient inpackages/api/src/management.ts. - Frontend integration is accelerated through React components and LitElement-based UI elements that handle complex OIDC flows automatically.
- The connector system in
packages/connectorsenables protocol extensibility without core code modifications. - Full self-hosting is supported via Docker Compose with minimal configuration requirements.
Frequently Asked Questions
What protocols does Logto support?
Logto implements a complete authentication protocol stack including OIDC (OpenID Connect), OAuth 2.1, and SAML 2.0. The core implementation in packages/core/src handles token issuance, validation, and session management according to these standards, while the connector system in packages/connectors allows integration with external providers using these same protocols.
How does Logto handle multi-tenancy?
Logto implements architectural isolation through the Tenant class in packages/core/src/tenants/Tenant.ts. Each tenant receives dedicated database connections, signing keys, and configuration scopes via the TenantContext abstraction. This design allows multiple tenants to share a single PostgreSQL instance while maintaining complete data separation at the query level.
Can I self-host Logto?
Yes, Logto is designed for self-hosting as an open-source alternative to managed identity providers. The repository provides a docker-compose.yml file that orchestrates PostgreSQL, the Core service, and the admin console. You can launch a complete instance using the Docker Compose one-liner or through the npm init @logto quick-start script for local development.
How do I manage users programmatically?
User management is performed through the Management API using the type-safe client generated from OpenAPI specifications. The createManagementApi function in packages/api/src/management.ts creates a client that automatically handles machine-to-machine authentication, allowing you to list, create, update, or delete users, applications, and connectors via standard REST operations.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →