Skip to content

Introduction

Goiabada is an open-source server that signs your users in, so your apps don’t have to.

You run it yourself. Your apps send users to Goiabada to sign in, and get back tokens that say who the user is and what they’re allowed to do. Goiabada speaks OAuth2 and OpenID Connect, the standards almost every language and framework already has a library for.

  • Sign-in with passwords and two-factor authentication. Users sign in with a password, and optionally a code from an authenticator app. Each app chooses whether a code is required. See Require two-factor authentication.
  • Single sign-on. Users sign in once and can use all your apps without signing in again. See Single sign-on across clients.
  • Permissions. You decide who can do what in your APIs, with resources, permissions and groups. See Resources and permissions.
  • Custom claims. You add groups and your own user and group attributes to ID tokens, access tokens or both. See Attributes.
  • API protection. Apps and services get tokens for calling your APIs, with or without a user. See Protect an API.
  • Self-service accounts. Users update their own profile, picture, email, phone, address, password and two-factor authentication, end their sessions and revoke the consents they gave.
  • Self-registration and password recovery. People create their own accounts, with or without email verification, and reset a forgotten password by email. See Self-registration and Password recovery.
  • Dynamic client registration. Apps such as MCP clients can register themselves, when you turn it on. See Let clients register themselves (DCR).
  • An admin API. Your scripts and tools can do everything the admin console does, with an OpenAPI reference and permissions as narrow as read-only. See API authentication.
  • An audit log. Sign-ins, failed passwords and every change an administrator makes are recorded. See Audit log.
  • A setup wizard. It asks a few questions and writes a ready-to-run configuration for Docker Compose, Kubernetes or the native binaries, keys and passwords included. See Setup wizard.
  • Ready for Kubernetes. Generated manifests with probes, graceful shutdown and disruption budgets, Prometheus metrics, and servers that scale out to several replicas. See Kubernetes and Monitoring.

Goiabada has three parts:

  • The auth server signs users in and issues tokens. It serves the OAuth2 and OpenID Connect endpoints, the sign-in pages, and an API for managing everything.
  • The admin console is the web app where you manage clients, users, groups, permissions and settings, and where users manage their own account. It’s a client of the auth server and talks to it over HTTP.
  • The database holds everything: MySQL, PostgreSQL, SQL Server or SQLite. Only the auth server connects to it.
Your apps and the admin console talk to the auth server, which is the only part that reaches the database.

Both servers are written in Go, and each ships as a Docker image and a native binary for Linux, macOS and Windows.

If OAuth2 and OpenID Connect are new to you, the glossary explains each term in plain English.

These docs are also published as plain text, for AI agents and tools that read documentation:

  • /llms.txt lists every page, with its title, URL and a one-line description.
  • /llms-full.txt holds every page in full, as Markdown, in one file.