Tokens and sessions
JWT bearer tokens for users and Basic tokens for applications, refresh tokens that are single-use by default, revocation per session or for all devices, and scoped tokens limited to a subset of permissions.
ErtisAuth, delivers centralized, scalable, and secure identity and access management across your entire application ecosystem. From web and native applications to mobile apps and APIs, manage authentication, authorization, tokens, memberships, roles, granular & flexible permissions, dynamic user type management and OAuth integrations from a single platform.
One service, one database. No JVM, no separate admin server, no SQL migrations.
Memberships, users, roles, providers and hooks are managed through the same REST API that issues the tokens.
Each membership operates as a fully isolated environment, allowing you to securely manage multiple channels and product ecosystems under a single service—without compromising separation or security.
MIT licensed. No per-user pricing, no feature tiers, your data stays in your database.
Features
From the first sign-in to webhooks on every event, ErtisAuth covers the whole account lifecycle.
JWT bearer tokens for users and Basic tokens for applications, refresh tokens that are single-use by default, revocation per session or for all devices, and scoped tokens limited to a subset of permissions.
Isolated tenants, each with its own users, roles, applications, secret key, token lifetimes and mail settings.
Roles with permissions and forbidden rules, plus per-user and per-application overrides. The same model protects your own APIs.
Sign in with Google, Apple (web and native), Facebook and Microsoft. Provider tokens are validated on the server, never trusted from the client.
Define custom user fields with a JSON schema at runtime: validation, default values, unique fields and inheritance, without changing code.
A code flow for smart TVs, kiosks and CLI tools: the device shows a short code, a signed-in user approves it, the device gets a token.
Email activation, password reset with single-use tokens, one-time passwords, and freezing an account to revoke all of its tokens at once.
Argon2id and PBKDF2, chosen per membership. Legacy algorithms are still supported, so existing user databases can be imported.
Every operation is recorded as an event. Webhooks call your endpoints from a background queue, and mail hooks send templated emails.
OpenAPI reference with Scalar, Prometheus metrics, Application Insights, health checks and a Docker image that runs as a non-root user.
Permission model
A permission is an expression that names who may do what on which resource. Wildcards and shorter forms keep roles short, and the same expressions protect your own services.
A matching user or application permission decides first, whether it grants or forbids.
Otherwise the role decides, and a forbidden rule of the role always wins.
Users may still read and update their own record, unless the role forbids it.
A scoped token must also cover the request with its scopes.
Request
GET users/42
User: u-7 · Role: editor
Required permission
User permissions (u-7)
Role permissions (editor)
Security
An identity service is only as safe as its defaults. These protections are part of ErtisAuth and on from the start, with nothing to switch on.
TLS, rate limiting on public endpoints and network access to MongoDB belong to your gateway and infrastructure.
For .NET developers
ErtisAuth.Sdk is a typed client for the ErtisAuth API. ErtisAuth.Sdk.AspNetCore adds authentication and permission checks to your own ASP.NET Core services.
Declare the resource, action and object with attributes; placeholders read route values, query parameters, headers and environment variables.
A bundled Roslyn analyzer reports invalid permission attributes at compile time.
Not on .NET? Every feature is a REST endpoint, so services in any language can verify tokens and check permissions.
[Authorized]
[RbacResource("orders")]
[Route("orders")]
public class OrdersController : ControllerBase
{
[HttpGet("{id}")]
[RbacObject("{id}")]
[RbacAction(Rbac.CrudActions.Read)]
public IActionResult Get(string id)
{
// Reached only when the caller's token grants *.orders.read.{id}
...
}
}How it compares
ErtisAuth is a central, ready-to-run server like the big platforms, but small enough to run next to your own services.
A full-featured server, but a heavy Java application configured mostly through its admin console. ErtisAuth keeps the realm idea (memberships) in a small .NET service configured entirely through its API.
Managed for you, but paid per active user, and your user data lives on a third-party platform. ErtisAuth is self-hosted: the data stays in your MongoDB.
A framework to build your own server with, and most companies need a commercial license. ErtisAuth is a ready-to-run server under the MIT license.
A library embedded in each application. ErtisAuth is a central service: many applications, in any language, share the same users and permissions.
Get started
Start ErtisAuth and MongoDB with Docker Compose, create the first membership with the one-time setup endpoint, and sign in.
From the root of the repository. The API listens on port 9716, the API reference is at /docs.
$ git clone https://github.com/ertugrulozcan/ErtisAuth.git
$ cd ErtisAuth
$ docker compose up -d --buildInsert a setup token into the database, then call /setup once to create the first membership, role and administrator.
$ openssl rand -hex 32
$ docker compose exec mongo mongosh auth \
--eval 'db.setup.insertOne({ token: "<setup_token>" })'
$ curl -X POST http://localhost:9716/setup \
-H 'X-Setup-Token: <setup_token>' \
-H 'Content-Type: application/json' \
-d '{ "membership": { … }, "user": { … } }'Sign in with the administrator and use the access token on any endpoint.
$ curl -X POST http://localhost:9716/generate-token \
-H 'X-Ertis-Alias: <membership_id>' \
-H 'Content-Type: application/json' \
-d '{ "username": "admin", "password": "<password>" }'ErtisAuth is free and open source under the MIT license. Star the repository, read the docs, or open an issue.