UserFront: Auth Without Complexity
userfront.com
userfront.com
Mind you, data residence and provenance may be more important in the use cases/applications I'm familiar with.
Then again, it is good to see a healthy standards based Authn/z ecosystem - good luck to all.
EDIT: After reviewing the site closer I'm not seeing anything about standards compliance.
If you only have a single web application (yes, that still exists) you don't need any of this. Use your backend framework's "native" auth package and you're good to go.
Plus they have robot detection, mfa, captcha, etc out if the box.
Thanks! We'll make a section to highlight them. We use the JWT standard (not sure if that is what you mean?), Oauth 2.0, SAML, etc... there are lots of standards in this space
EDIT: for example: https://auth0.com/security. SOC 2 is a big one.
This is exactly what we're rolling out in the next few weeks. We already have it trivial to rotate API keys [1], and we have a JWKS endpoint [2], so rotating the primary JWT private key is next on the list.
[1] https://userfront.com/docs/api.html#api-keys
[2] https://userfront.com/docs/api.html#json-web-key-set-jwks
We started doing auth because our dev customers kept telling us how much of a pain it was with the first-gen companies (Auth0 et al). With Userfront, you don't have to learn all the standards/protocols or deal with browser quirks, and things like testing, access control, and multi-tenancy are first-class features instead of things you spend lots of time on.
Currently I am self-hosting several web applications for the same userbase and just want them to have the same username and password for each app (SSO not required).
After much pain and confusion, I have an OpenLDAP instance functioning basically how I want, but it just feels like there must be a better way!
It will also provide you with SAML and OIDC web authentication, and can support WebAuthN, U2F, certificate auth, and so on for your apps, as well as integrate Google Authenticator compatible MFA (out of the box) or link with privacyIdea for more complex authentication setup. It can even link kerberos with HTTP, if you need it :)
Pretty much everything that supports custom OIDC (or SAML) will work with Keycloak out of the box.
Some confusion how additional roles are created (didn't dive into API, just exploring the panel) - guess this is tenancy?
Yes you can do multi-tenancy natively, with each tenant having the same power as its parent in terms of roles, separate login pages, etc. Our architecture is "tenants all the way down".
As you may know, HN never fails to complain about having to create a new user account to try a service out. Sometimes when you can try a service out before signing up, it's a better experience.