CATEGORY
Authentication 2,312 crates
Data as of 2026-07-25 (crates.io database dump, timestamp 2026-07-25T02:00:36Z). Source: crates.io · db-dump.tar.gz · methodology & corrections.
roka-totpZero-dependency TOTP / HOTP for Rust — RFC 4226 / 6238, std-only, no unsafe.40Apache-2.0 OR MIT
attestixAttestix offline credential verifier - verify Ed25519 W3C Verifiable Credentials and UCAN delegation chains issued by the…40Apache-2.0
moss-sdkCryptographic signing for AI agents using ML-DSA-44 (post-quantum)40BSL-1.0
bsv-middleware-rsFramework-agnostic BRC-31 authentication and BRC-29 payment middleware for BSV39MIT OR Apache-2.0
skg-secret-vaultStub secret resolver for HashiCorp Vault KV39MIT OR Apache-2.0
ghtknGitHub token management — OAuth device flow with keyring caching and config-driven app selection39MIT
idprova-registryIDProva Registry — HTTP service for AID resolution and management39Apache-2.0
offline-license-validatorOffline license validation library using Ed25519 signatures39MIT
hsh-cliCommand-line companion for the `hsh` password-hashing library: hash / verify / rehash / inspect / calibrate.39MIT OR Apache-2.0
agent-safe-splSPL (Safe Policy Lisp) evaluator for Agent-Safe capability tokens. 150 lines, zero deps core, microseconds.39MIT
drs-coreDRS cryptographic core — Ed25519, SHA-256, JCS, capability index39Apache-2.0
rustauth-actix-webActix Web integration for RustAuth.39MIT
sdkeyOfficial Rust client for the SDKey license authentication protocol39MIT
hashicorp-keyvaultA simple secret management crate for CRUD operations on secrets38MIT
openkit403HTTP-native wallet authentication for Solana38MIT
corteqEnterprise-grade multi-tenant SaaS framework for Rust with security-first design38MIT
skg-hook-securitySecurity middleware for skelegent — redaction and exfiltration detection38MIT OR Apache-2.0
secure-authA high-security, enterprise-grade Rust authentication layer for handling user signup and login with encrypted storage.38MIT
ows-cantonCanton Network chain family plugin for Open Wallet Standard38MIT
hestiaHestia — local-first Web4 trust layer for AI agents. The core daemon: credential vault, MCP server, society state, witness chain.38AGPL-3.0-or-later
riley-auth-cliCLI for riley_auth — server management, key generation, and administration38MIT
hxrts-aura-agentCapability-based agents with clean service layer architecture for identity management38Apache-2.0
tibet-iddropIdentity-bound capability transfer protocol — offer-first (proximity) + request-first (wire) over TBZ v2 sealed envelopes38MIT OR Apache-2.0
stellar-agent-smart-accountSmart-account orchestration layer for the Stellar agent wallet (OZ stellar-accounts v0.7.2 consumer).38Apache-2.0
rok-auth-socialSocial OAuth providers (Google, GitHub, Discord) for the rok framework37MIT
idprova-middlewareIDProva Middleware — Tower/Axum layer for DAT bearer token verification37Apache-2.0
codexswitch-cliUltra-fast, cross-platform profile switching for ChatGPT, Codex, and third-party providers37MIT
scimeraA convenient re-export facade for the scim-rs SCIM 2.0 protocol engine.37MIT
vaultmuxUnified async interface for password managers and cloud secret vaults - write once, support pass, Bitwarden, AWS, GCP, Azure37MIT OR Apache-2.0
delegated-redisRedis-backed trust state for delegated capability evaluation37MIT OR Apache-2.0
traffic-orchestratorOfficial Rust client for Traffic Orchestrator license validation, management, and analytics37MIT
cheers-verifyVerify-only surface for cheers — PasetoV4PublicVerifier (Ed25519 public key), RevocationReader, and the EdgeVerifier facade.…37MIT OR Apache-2.0
dmarcguardOfficial Rust SDK for the DMARCguard API (https://dmarcguard.io) - DMARC, SPF, and DKIM monitoring and reporting.36Apache-2.0
doasA Rust implementation of doas, a minimal sudo alternative with PAM authentication36MIT
df-verifyEd25519 verifier for Dynamic Feed (dynamicfeed.ai) DF-VERIFY/1 signed envelopes — byte-identical canonicalization with the Python…36MIT
agent-idAgent Identity Protocol - cryptographic identity and authentication for AI agents36Apache-2.0
wamiWho Am I - Multicloud Identity, IAM, STS, and SSO operations library for Rust36MIT
omegon-shuttlePure-Rust SSH remote execution extension for Omegon — HKDF-derived key auth, no key files on disk36MIT
tauri-plugin-rekognition-livenessAWS Rekognition Face Liveness for Tauri 2 — native Android/iOS UI bindings.36MIT
deputy-idMATA mID verification (pure Rust) and Deputy's identity & session model.36MIT OR Apache-2.0
nexaraPolicy-bound capability and tool runtime for AI systems36MIT
kyriotes-csk2Kyriotēs-CSK2 makes encrypted data require permission, not just a key. Even if someone has the decryption key, Kyriotēs-CSK2 can…36MIT
eid-coreShared seam for the nordisk eIDs frida/tyr: holder (WebAuthn/PKCS#11/platform) auth+sign abstraction, challenge/assertion types,…360BSD
tenzro-device-keyHardware-backed device keys for Tenzro — macOS/iOS Secure Enclave P-256 signing + ECIES secret-wrapping, with a biometric…36Apache-2.0
aae-protocolAccountable Agentic Execution — protocol SDK for Rust36MIT OR Apache-2.0
personaeThe identity and carry layer for the Merely ecosystem: a master Ed25519 keypair, deterministic per-protocol key derivation…36MIT OR Apache-2.0
mcp-credentials-vaultCredentials Vault MCP server for ADK-Rust Enterprise — scoped, auditable credential access with pluggable vault backends35Apache-2.0
okamiPost-quantum cryptographic identity for AI agents35MIT OR Apache-2.0
solana-keyring-biometricBiometric authentication (TouchID) for Solana keyring35Apache-2.0
mtls-tcpRaw TCP adapter for mTLS authentication with IP whitelisting35GPL-3.0
kael_secretsSecure OS-keychain credential storage for Kael35Apache-2.0
axum-jwt-bridgeJWT encode/decode for Axum: HS256 shared-secret or EdDSA (Ed25519) public/private key auth, with optional Laravel interop and…35MIT
agentid-verifyVerify AI agent passports — Ed25519 JWT credentials with W3C did:key34MIT
tenzro-walletMPC wallet for Tenzro Network — FROST-Ed25519 + ML-DSA-65 hybrid threshold wallets, Argon2id keystore, transaction history,…34Apache-2.0
xenv-vaultA Rust library for loading and decrypting .env.vault files encrypted with AES-256-GCM34MIT
trustgrant-errorError types for the TrustGrant delegation protocol34MIT OR Apache-2.0
spherenet-regulated-token-clientGenerated Rust client for the Spherenet regulated token program34Apache-2.0
spherenet-regulated-token-interfaceInstructions and types for interacting with the regulated token standard34Apache-2.0
pgb-iamIAM-Aware PostgreSQL Connection Pooler — production-ready PgBouncer alternative with native AWS RDS IAM and GCP Cloud SQL IAM…33Apache-2.0
mtls-rocketRocket fairing for mTLS authentication with IP whitelisting33GPL-3.0
mtls-grpcgRPC adapter for mTLS authentication with IP whitelisting33GPL-3.0
auth4freeA modern, secure authentication library for Rust applications with password validation, JWT tokens, bcrypt hashing, session…33MIT
kwtKDL Web Token (KWT) — production Rust implementation33GPL-3.0-or-later
fprint-coreModern, GObject-free Rust core for fingerprint readers: device/print domain model and backend traits, shared by a libfprint (FFI)…33MIT OR Apache-2.0
ingress-ingestStructured ingress log ingest helpers for Gatewarden.33AGPL-3.0-only
xaorAdaptive regenerative cryptographic engine — memory-hard, chaos-keyed, GPU/ASIC-resistant33MIT
trustgrant-domainCore domain types for the TrustGrant protocol (authority IDs, selector kinds, principal IDs, operation names)33MIT OR Apache-2.0
warpin-dingtalkDingTalk OpenAPI client primitives for Warpin applications33MIT
rok-cryptoPure cryptographic primitives — encryption, password hashing, ID generation, TOTP, JWT, password policies, and secure random…32MIT
codex-auth-managerA deadly simple Codex auth manager.32MIT
abolA high-performance, asynchronous, dictionary-driven RADIUS framework.32MIT OR Apache-2.0
wasi-authProduction authentication, authorization, and trusted ingress for WASI applications32MIT OR Apache-2.0
oxigeo-securityEnterprise security features for OxiGeo: encryption, access control, compliance32Apache-2.0
rtotpRust one-Time Password — a terminal TOTP (RFC 6238) client32MIT
hyperion-vpn-clientHyperion VPN admin client: knock + Noise tunnel, local port forwards, and fake-IP TUN mode32AGPL-3.0-only
hyperion-vpn-serverHyperion VPN server daemon: SPA knock sniffer, nftables gating, and the egress-allowlisted relay32AGPL-3.0-only
paseto-authPaseto v4.public microservice compatible library for token creation and validation31MIT OR Apache-2.0
tenzro-keystore-unlockPlatform-agnostic keystore-unlock trait for Tenzro wallets — lets node embedders supply the keystore password from any source…31Apache-2.0
axum-authentik-authAxum extractor and middleware for authentik Proxy Provider forward auth31MIT OR Apache-2.0
fortress-passA powerful, feature-rich password generator with strength scoring, policies, and memorable passwords31MIT
oauthkitProvider-registry-driven OAuth SDK for CLIs: authorization-code+PKCE, device-code, and API-key sign-in across many model…31Apache-2.0
trustgrant-documentTrustGrant document parsing, validation, normalization, and JSON schema types31MIT OR Apache-2.0
secretx-tpm2TPM 2.0 backend for secretx.30MIT
aegis-auth-navchetnaAegis Auth is a unified identity management system providing memory-safe Rust-based authentication. Consolidation of disparate…30MIT
mcp-shieldSecurity proxy for MCP (Model Context Protocol) — auth, rate limiting, payload filtering, and audit logging between AI agents and…30Apache-2.0
abac-rsGeneric Attribute-Based Access Control (ABAC) evaluation engine with hbac-rs performance characteristics30MIT OR Apache-2.0
captcha-sdkUnified server-side CAPTCHA verification for Rust30MIT
dig-node-control-interfaceCanonical client <-> dig-node CONTROL interface contract: the method catalog for controlling/querying a running dig-node (config,…30Apache-2.0 OR MIT
mac-processUser-mode library for querying and verifying integrity of MacOS processes29MIT
ubl-directorySubject registry for UBL: people, orgs, LLMs, devices — links chip owners to identity29MIT OR Apache-2.0
oxigeo-gatewayEnterprise API gateway with rate limiting, authentication, GraphQL, and WebSocket support for OxiGeo29Apache-2.0
trustgrant-discoveryAuthority discovery document parsing and signer binding resolution29MIT OR Apache-2.0
vaid-popVAID proof-of-possession signing primitive (Rust): the canonical JCS→SHA-256→Ed25519 primitive of the verifiable agent-action…28Apache-2.0
kangoufuA strictly compliant, no_std portable WebAuthn Relying Party implementation.28MIT OR Apache-2.0
aigpAIGP — AI Governance Proof. Open standard for proving your AI agents used the approved policies, prompts, and tools.28Apache-2.0
agent-governancePublic Preview — Rust SDK for the Agent Governance Toolkit (policy, trust, audit, identity)28MIT
aap-protocolAgent Accountability Protocol — Rust SDK28MIT
stellar-agent-sep10SEP-10 Stellar Web Authentication client: challenge validation, ephemeral-key signing, and JWT session handling.28Apache-2.0
trustgrant-revocationRevocation state management and proof verification for the TrustGrant protocol28MIT OR Apache-2.0
cc_validatorCredit card validation library for Rust - work in progress27MIT
mcp-guardA lightweight, high-performance security gateway for MCP servers27AGPL-3.0
axum-totpUser authentication with TOTP two-factor authentication for Axum web applications27LGPL-2.1
qhermes-kernelQHermes 26 — post-quantum delegation chain primitives (ML-DSA-65, HKDF-SHA3-512)27LicenseRef-Copertino-1.0
chip-registryChip lifecycle API: mint, transfer, revoke, fork — Git for Capabilities27MIT OR Apache-2.0
solana-actorCore credential provider traits for Solana signing and transaction submission27Apache-2.0
oint-keysA Simple Standard Cryptography-Suite For Web 3.20, offering cryptographic abstraction (Generic Signing/Verifying, Generic…27Apache-2.0 OR MIT
opaque-rsA Rust implementation of the OPAQUE protocol for secure password authentication.27MIT
trustgrant-portsBackend-agnostic port traits for the TrustGrant protocol (storage, discovery, revocation sources)27MIT OR Apache-2.0
relativelylightWeb-app building blocks: auto-generated CRUD JSON API from your ORM entities, an auto-generated Alpine.js CRUD UI bound to that…26MIT
google-auth-middlewareGoogle OAuth authentication middleware with session management for Rust web applications26MIT OR Apache-2.0
lazarus-receiptsLazarus Receipts SDK - Cryptographic receipt verification26Apache-2.0
timely-pass-cliCommand-line tool for managing time-based password policies.26MIT
dusk-auth-core-rustAn opinionated, framework-agnostic authentication core enforcing correct session-based auth practices26MIT
noctahashMemory-hard password hashing algorithm designed to resist GPU, ASIC, and side-channel attacks26MIT
grammers-stringsessionExport/restore a grammers session as a portable base64 string.26MIT OR Apache-2.0
rust-mcp-coreConfig-driven MCP server framework built on the official rmcp SDK. Fully implements the Model Context Protocol spec — define…26MIT
licensegatelicensegate client: offline verification of license keys, activation receipts, and CRLs26MIT OR Apache-2.0
webgates-actixActix integration layer for the webgates authentication and authorization core.25MIT
passay-rsA password validation library inspired by the Java Passay library.25MIT OR Apache-2.0
stalwart-rsStalwart Mail Server OAuth PKCE, device flow, and admin API extensions25MIT OR Apache-2.0
sentinel-agent-authAuthentication agent for Sentinel reverse proxy - JWT, API keys, and Basic auth25MIT OR Apache-2.0
quarlus-securityJWT/OIDC security module for Quarlus - token validation, JWKS cache, and AuthenticatedUser extractor25Apache-2.0
rust-signDocument signing library using BLAKE3 hashing and Ed25519 signatures25MIT
foodshare-cryptoCryptographic utilities for webhook verification and HMAC25MIT
keytuiKeyTUI is a high-velocity Terminal User Interface for managing API tokens, service keys, and credentials.25AGPL-3.0
sigillum-fido2FIDO2 hardware key unlock and Shamir secret sharing for Sigillum25MIT OR Apache-2.0
totpyxMinimal, dependency-free RFC 6238 TOTP implementation24Apache-2.0
fidoriumA FIDO2/CTAP2 authenticator daemon for Linux backed by TPM 2.024MIT OR Apache-2.0
cm-email-webhook-verificationSDK for verifying CM Email webhook signatures24MIT
mpc-wallet-relayMessage relay service for MPC agent wallet with approval flows24MIT OR Apache-2.0
sentinel-agent-spiffeSPIFFE/SPIRE workload identity agent for Sentinel reverse proxy24Apache-2.0
elizaos-plugin-secrets-managerMulti-level secrets management plugin for elizaOS with encryption and dynamic plugin activation24MIT
tower-webflowtower-webflow is a crate that simplifies validating webhooks received from Webflow24MIT
portaThe gate to LLM providers - OAuth subscription handling for Claude and more24MIT
warrant-coreCore library for warrant-shell capability policies24MIT OR Apache-2.0
azauthA simple, pluggable, configurable authentication backend24MIT
oidc-jwks-converterCLI tool to extract and convert OIDC public keys to PEM certificate format24MIT
bkeyBKey SDK — biometric approval, vault, and checkout for AI agents24Apache-2.0
trustgrant-ownershipOwnership authority transition verification for the TrustGrant protocol24MIT OR Apache-2.0
better-auth-poemPoem framework integration for better-auth-rs23MIT OR Apache-2.0
nullsec-discord-shieldDiscord token hardening and anti-theft protection - Monitors, encrypts, and protects Discord tokens from stealers and grabbers23MIT
jorttAsync Rust SDK for the Jortt API with typed modules, hybrid OAuth helpers, and raw operation escape hatch23MIT
oauth-db-cliCommand-line tool for managing OAuth-DB platform23MIT
rustywallet-silentSilent Payments (BIP352) for rustywallet23MIT
captcha-coreFacade crate for captcha-sdk core server-side CAPTCHA types23MIT
neuron-auth-fileFile-based auth provider that reads a bearer token from disk23MIT OR Apache-2.0
neuron-secret-envSecret resolver that reads from process environment variables23MIT OR Apache-2.0
neuron-secret-keystoreStub secret resolver for OS keystore (macOS Keychain, Windows DPAPI, Linux Secret Service)23MIT OR Apache-2.0
nklave-cosmosCosmos/CometBFT remote signer protocol (Tendermint PrivValidator) for Nklave23MIT
nklave-cliCommand-line tools for Nklave key management and operations23MIT
nklave-serverMain server binary for Nklave with TLS, metrics, and configuration23MIT
oauth2-pg-storePostgreSQL-backed secure token store for OAuth2 in Rust. Hashes tokens with BLAKE3 (never plaintext), supports revocation,…23MIT
authkestra-resourceResource server enforcement and validation for the authkestra framework23MIT OR Apache-2.0
ez-tokenCLI tool for generating OAuth2 access tokens via PKCE and Client Credentials for Microsoft Entra ID and Auth023Apache-2.0
zk-citadel-walletWallet CLI for the Citadel protocol.23MPL-2.0
portcullisA quotient lattice for AI agent permissions that prevents the 'uninhabitable state'23MIT OR Apache-2.0
agent-governance-mcpPublic Preview — MCP governance and security primitives for the Agent Governance Toolkit23MIT
radius-tokio-eapTLS-tunnelled EAP methods (EAP-TLS, PEAP, EAP-TTLS) for radius-tokio23BSD-2-Clause
agent-payL402 + DID-signed invoices: agent-to-agent Lightning payments (Rust port of @p-vbordei/agent-pay)22Apache-2.0
huskarl-crypto-macosmacOS Secure Enclave backed ES256 signing for the huskarl (OAuth2 client) ecosystem.22MIT OR Apache-2.0
wpa-nextHybrid post-quantum resistant Wi-Fi security protocol prototype (ML-KEM-768 + X25519 + HKDF-SHA384)22MIT
rustywallet-frostFROST threshold signatures for rustywallet22MIT
rustywallet-coinjoinCoinJoin and PayJoin (BIP78) utilities for rustywallet22MIT
actraActra – deterministic control for automated system actions.22Apache-2.0
authvaderOfficial Rust SDK for AuthVader Identity Platform - Coming Soon22non-standard
openidauthzenOpenID AuthZEN Authorization API 1.0 — Policy Decision and Enforcement Points for Rust22MIT OR Apache-2.0
sekuire-cliCLI for the Sekuire Agent Identity Protocol22Apache-2.0
xlockx-lock bot protection middleware for Rust22MIT
neuron-hook-securitySecurity hooks for neuron — redaction and exfiltration detection22MIT OR Apache-2.0
stoatStreaming OAuth Transformer — a config-driven local reverse proxy for OAuth token lifecycle management22MIT OR Apache-2.0
neuron-auth-staticStatic auth provider that always returns the same token (dev/test)22MIT OR Apache-2.0
neuron-auth-oidcStub OIDC client credentials / token exchange auth provider22MIT OR Apache-2.0
neuron-auth-k8sStub Kubernetes ServiceAccount projected token auth provider22MIT OR Apache-2.0
neuron-secret-vaultStub secret resolver for HashiCorp Vault KV22MIT OR Apache-2.0
neuron-secret-awsStub secret resolver for AWS Secrets Manager22MIT OR Apache-2.0
neuron-secret-gcpStub secret resolver for GCP Secret Manager22MIT OR Apache-2.0
neuron-secret-k8sStub secret resolver for Kubernetes Secrets22MIT OR Apache-2.0
sigillumSecure secret management with hardware-backed encryption22MIT OR Apache-2.0
signv4AWS Signature Version 4 implementation for Rust22MIT
rune-axum-bruteAccount lockout middleware for Axum — rate-limit authentication failures per key with configurable thresholds22MIT
spherenet-regulated-token-cliCLI for interacting with the Sphere Foundation regulated-token program22Apache-2.0
get401-axumAxum integration for get401 authentication — extractors and Tower middleware.21MIT
rok-auth-basicHTTP Basic authentication guard for the rok ecosystem21MIT
openapeOpenApe — namespace placeholder. The real Rust SDK for the OpenApe agent/identity platform will ship under this crate.21MIT
tripfuseA one-time use container for sensitive values21MIT OR Apache-2.0
botchaRust SDK for Botcha — the reverse CAPTCHA for AI agents. Coming soon.21MIT
sekuireThe official SDK for the Sekuire Agent Identity Protocol21Apache-2.0
smbcloud-auth-pyPython bindings for the smbCloud Auth SDK.21MIT
passwd-strengthA Rust library for analyzing password strength — entropy calculation, pattern detection, crack time estimation, and improvement…21MIT
fprint-pipelineThe host-image fingerprint pipeline in a few lines: turn a grayscale frame into minutiae with MINDTCT, build an NBIS template,…21MIT OR Apache-2.0
sync-authBidirectional auth credential sync for dev tools (Claude Code, GitHub CLI, GitLab CLI, Codex, Gemini CLI, and more) via Git…21Unlicense
acme-championA tiny DNS resolver to answer ACME challenges21non-standard
nip46-signerNIP-46 remote signing server — per-client permissions, session management, and Heartwood signing extensions.21MIT
himitsu-cliAge-based secrets management with transport-agnostic sharing21MIT
stellar-agent-x402-identitySEP-10 counterparty-identity pre-payment gate for x402 Exact Stellar payments (payer side).21Apache-2.0
herald-jmap-stalwartStalwart Mail Server OAuth PKCE, device flow, and admin API extensions21MIT OR Apache-2.0
trustgrant-verifyCold-path verification pipeline for the TrustGrant protocol21MIT OR Apache-2.0
lastid-sdkRust SDK for LastID IDP integration - request and verify credentials with type-safe policy builders20MIT OR Apache-2.0
tangled-configConfiguration and secure session management for the Tangled CLI20MIT OR Apache-2.0
qhermes-a2aQHermes 26 — A2A identity and authorization layer (Agent Cards, credential chains, KEM session handshake)20LicenseRef-Copertino-1.0