Documentation
Halo documentation
Halo is an open-source identity and access management (IAM) platform that you host yourself: single sign-on over OpenID Connect and SAML, passkeys, SCIM provisioning, conditional access policies and access governance. It has not published a release yet; CHANGELOG.md lists what works today.
Start here
Get startedrun Halo on your computer, create the first administrator, and sign in to an example application through Halo.Conceptsusers, groups and their rules, roles, applications, sessions, sign-in methods, and the sign-in and audit logs.
Run Halo
Self-hosting
Configurationevery environment variable, with its default and an example, and the settings you change in the console.Emailconnect a mail server, the outbox, and magic sign-in links.what a production installation looks like, with the step-by-step guide in deploy/README.md.
Manage access
Access policiesconditional access, report-only mode, network zones, devices, sign-in risk, allowed sign-in methods and the simulator.Access governanceaccess packages, requests and approvals, access reviews, and joiner, mover and leaver rules.Federationsign-in with Google, Microsoft Entra ID, GitHub or any OpenID Connect provider, account linking and accounts created on first sign-in.Infrastructure accessHalo's SSH certificate authority,
halo login and halo ssh-cert.Automate and integrate
Provisioning and automationservice accounts and API keys, SCIM from Okta or Microsoft Entra ID into Halo, and SCIM from Halo into your applications.Webhookssigned delivery of audit and sign-in events, with a Go receiver.API resourcesprotect your own APIs with Halo access tokens and validate them.
API
the JSON API behind the console and the account portal, with its OpenAPI document.
Understand Halo
Architecturethe components, the Go packages, and how a sign-in to an application flows through them.Security modelhow Halo authenticates people and protects sessions, secrets and tokens, and its known limitations.
Integrations
Step-by-step guides for connecting applications to Halo:
Generic OpenID Connectendpoints, claims and tokens for any application that supports OpenID Connect.GrafanaForgejoNextcloudKubernetes with kubeloginProxmox VEOutlineHeadscale
SAML 2.0
for applications that do not support OpenID Connect, with guides for AWS IAM Identity Center and Slack.
Contribute
CONTRIBUTING.md covers the development environment, tests and code style. Report security problems privately as SECURITY.md describes.