Skip to content
Goiabada logo

Goiabada

Sign-in, single sign-on and permissions for your apps, on a server you run yourself.

Goiabada signs your users in, so your apps don’t have to. It’s an OAuth2 and OpenID Connect server: your apps send users to it, and get back tokens that say who each user is and what they can do.

OAuth2 and OpenID Connect

The standards your languages and frameworks already have libraries for.

Single sign-on

Users sign in once and use all your apps.

Two-factor authentication

Codes from an authenticator app, required for the apps that need them.

Permissions

Decide who can do what in your APIs, by user, group or client.

Custom claims

Add groups and your own user and group attributes to ID tokens, access tokens or both.

Self-service accounts

Users manage their own profile, picture, email, phone, address, password and two-factor authentication, end their sessions and revoke consents.

Self-registration and password recovery

People create their own accounts, with or without email verification, and reset a forgotten password.

Dynamic client registration

Apps such as MCP clients register themselves, when you turn it on.

Admin API

Script everything the admin console does, with an OpenAPI reference and permissions as narrow as read-only.

Audit log

Sign-ins, failed passwords and every change an administrator makes, recorded and shown in the admin console.

Your choice of database

MySQL, PostgreSQL, SQL Server or SQLite.

Light to run

Two small Go servers, as Docker images for x86_64 and ARM64, or as native binaries.

Setup wizard

Answer a few questions and get a ready-to-run setup for Docker Compose, Kubernetes or native binaries, keys and passwords included.

Kubernetes friendly

Generated manifests with probes, graceful shutdown and disruption budgets, Prometheus metrics, and servers that scale out to several replicas.

  • Your data stays with you. You host it, so your users’ data lives on your servers.
  • Free and open source. MIT licensed, with no fees or subscriptions.
  • Standard. Anything that speaks OAuth2 or OpenID Connect works with it.

The sign-in page, where users enter their email and password

The admin console’s account pages, where a user updates their phone number

The admin console’s list of users

These docs are also published as plain text, for AI agents and tools that read documentation:

  • /llms.txt lists every page, with its title, URL and a one-line description.
  • /llms-full.txt holds every page in full, as Markdown, in one file.