CATEGORY
Authentication 2,312 crates
Data as of 2026-07-25 (crates.io database dump, timestamp 2026-07-25T02:00:36Z). Source: crates.io · db-dump.tar.gz · methodology & corrections.
omnicaptchaFacade crate for the captcha-sdk server-side CAPTCHA API20MIT
idprova-mcpIDProva MCP auth middleware — drop-in identity verification for MCP servers20Apache-2.0
atlas-ecdh-bridgeDerive deterministic Ed25519 signing keys from WebAuthn/Passkey P-256 ECDH — zero persistent secrets, hardware-bound identity20MIT OR Apache-2.0
aauth-httpsigFramework-independent HTTP Message Signatures with Signature-Key support20Apache-2.0
attestationOne Attestation to Rule them All20MIT
apollo-http-sigv4AWS SigV4 request signing for the Apollo platform20Elastic-2.0
nietzsci-clavisClavis SDK for Rust — offline license verification with Ed25519 signatures20MIT OR Apache-2.0
cedar-agent-schemasCanonical Cedar schema library for agent action verbs (exec, open, connect, request_tool). Rust helpers for constructing Cedar…20Apache-2.0
yubiwalletSeedless multi-chain hardware wallet on a YubiKey — sign Solana, Ethereum, Sui and Bitcoin with keys that never leave the device20MIT OR Apache-2.0
ferra-authAuthentication providers for the Ferra API framework — JWT Bearer, JWKS, API keys, and composite strategies. Coming soon.20MIT OR Apache-2.0
webgates-tonicTonic server-side transport adapter for webgates authentication and authorization.20MIT
trana_guardTrana Guard - Onchain passkey authorization primitive for Solana20Apache-2.0
forgedb-authSchema-agnostic verify-only JWT authentication + tenant cross-check for ForgeDB generated servers20MIT OR Apache-2.0
rust-cas-clientOne System CAS SSO client for Rust — build the login URL and validate single-use tokens server-to-server.19MIT
ldap-acisLDAP Access Control Instructions (ACI) system built on acls-rs19MIT OR Apache-2.0
authenA robust, modular, high-level, and secure authentication crate for Rust.19Apache-2.0
hardboundHardbound — public trait surface for the enterprise hardware-bound trust tier of Web4. Implementations of these traits anchor…19AGPL-3.0-or-later
rsauthAn authentication library for Rust (placeholder, work in progress)19MIT OR Apache-2.0
rok-bouncerBouncer-style abilities and Policy authorization for the rok ecosystem19MIT
agvtAgent-first secrets manager and context vault: agvt:// references, env injection, sensitivity-tiered dossier, autonomy charter,…19MIT OR Apache-2.0
seglAn OAuth library for Rust19MIT OR Apache-2.0
kindred-agent-idSelf-custody DID + capability VC profile for AI agents (Rust port of @p-vbordei/agent-id)19Apache-2.0
authvaultAuthentication and authorization vault with multi-provider support19MIT OR Apache-2.0
uvb-actix-webActix-web middleware for Universal Verification Broker (UVB)19MIT
uvb-rocketRocket fairing for Universal Verification Broker (UVB)19MIT
hanzo-kbsHanzo AI - Key Broker Service (KMS + attestation + post-quantum vault)19MIT OR Apache-2.0
nexara-cliCommand-line tools for Nexara policy authoring and demos19MIT
age-otpGenerate and verify time-based OTP codes from age public keys19MIT
keysat-licensing-clientClient library for Keysat. Verifies signed license keys offline and wraps the HTTP API for purchase and revocation checks.19MIT OR Apache-2.0
saml-mdqA Rust client for the SAML Metadata Query (MDQ) Protocol (IETF draft-young-md-query-saml)19MIT OR Apache-2.0
sekuire-sdkThe official SDK for the Sekuire Agent Identity Protocol18non-standard
patronus-arkHybrid Rust security scanners for prompt injection, DLP, PII, and agentic tool risks.18GPL-3.0-only
open-authOfficial re-export alias for the openauth crate.18MIT
opaque-ke-hybridML-KEM hybrid extension for opaque-ke18MIT OR Apache-2.0
soul-authFramework-agnostic JWT claims and auth error primitives for the Soul platform.18MIT
aauth-httpsig-policyIndependent, fail-closed verification policy for HTTP Message Signatures18Apache-2.0
seshcookieStateless, encrypted, type-safe session cookies for Rust web applications.18MIT
awiki-im-coreRust IM SDK for Awiki clients built on Agent Network Protocol (ANP)18MIT
challengeA lightweight CLI for ALTCHA Proof-of-Work v2 challenges.18MIT
rok-auth-sessionCookie-based session guard for the rok ecosystem — Memory/Database/Redis/Cookie drivers18MIT
rem-exec-vaultSecret store for remote execution workflows. age-encrypted files, keyctl-backed identity.18MIT
tenzro-identityTenzro Decentralized Identity Protocol (TDIP) — unified human and machine identity, W3C DID, delegation scopes, cascading…18Apache-2.0
idkollen-clientAPI client for the IDkollen REST API18MIT
rok-hashPassword hashing façade with Argon2, Bcrypt, and Scrypt drivers for the rok ecosystem18MIT
aithos-coreAithos Core protocol — pure logic: no I/O, no clock, no network.18BUSL-1.1
rok-aclDatabase-backed ACL — roles, permissions, and route guards for rok/Axum apps18MIT
ducia-auth-dbDatabase-backed auth plugin for ducia (JWT + bcrypt + SQLite)18MIT
colloid-coreA zero-I/O, panic-free authentication engine built on Rust's typestate pattern - compile-time-enforced login state transitions,…18MIT OR Apache-2.0
agentidCryptographic passports for AI agents — issue, manage, and revoke Ed25519 JWT credentials backed by W3C did:key17MIT
agent-roomsRust port of the parley protocol core (@p-vbordei/agent-rooms): canonical encoding, Ed25519 signing, message validation17AGPL-3.0-or-later
sndrEasily and securely share files from the command line.
A fully featured Send client (formerly ffsend, rebranded by tarnover).17GPL-3.0
secretx-signatureAdapter bridging secretx::SigningBackend to signature::Signer.17MIT
hbac-rsFreeIPA Host-Based Access Control (HBAC) rule evaluation17MIT OR Apache-2.0
fgtwFractal Gradient Trust Web — the client substrate for TOKEN identity: fleet membership, per-member fan-out of scoped keys,…17MIT OR Apache-2.0
im-coreRust IM SDK for Awiki clients built on Agent Network Protocol (ANP)17MIT
rune-jwtDecode and inspect JWT claims without verification — tear open any token for debugging and CTF work17MIT
kovra-native-windowsWindows Hello (UserConsentVerifier) Confirmer for kovra (free core, [host]-validated).17BUSL-1.1
l1fe-didShared DID parsing and validation logic for the L1fe ecosystem (Zer0 Runtime, Forge, Factory, CLI).17Apache-2.0
age-vaultA secure vault for managing age-encrypted accounts and data.17MIT
agent-toolprintDouble-signed receipts for AI-agent tool invocations — DSSE + JCS + Ed25519, verifiable offline (Rust port of…17Apache-2.0
anthropic-oauthOAuth login for Anthropic Claude Pro/Max (Claude Code session)17MIT
atshield-coreStateless primitives for ATProto PLC: audit-log verification, classification, and proof-of-possession17MIT OR Apache-2.0
rs-ocid-axumAn Axum router builder for OpenID Connect login flows.17MIT
hasp-clihasp CLI — unified secrets command-line tool. Thin shell over the hasp library.17MIT OR Apache-2.0
cheers-serverOrigin-side surface for cheers — secret-key minter, symmetric codecs, UserStore/RefreshStore, refresh rotation, RevocationWriter,…17MIT OR Apache-2.0
stellar-agent-approval-remoteTLS-protected, passkey-authenticated remote approval HTTP surface for the Stellar agent wallet: lets an operator approve or…17Apache-2.0
stellar-agent-webauthn-bridgeLocalhost HTTP listener that ferries WebAuthn ceremony bytes from the operator's browser into the wallet-owned approval spine.17Apache-2.0
reallyme-jose-protoReallyMe JOSE protobuf boundary messages generated with Buffa.17Apache-2.0
spherenet-badge-cliCLI for interacting with the Badge program17Apache-2.0
rune-axum-apikeyAPI key extractor and middleware for Axum — validates keys from headers, bearer tokens, or query parameters with constant-time…16MIT
hopf-authTrustPolicy, IdentityMaterial, and SASL mechanisms for Hopf16LGPL-2.1-or-later
arbitusSecurity proxy for MCP (Model Context Protocol) — auth, rate limiting, payload filtering, and audit logging between AI agents and…16MIT
fprint-backend-libfprintM1 shim: implements fprint-core's Backend/Device by dynamically linking the C libfprint, owning the FFI directly via…16MIT OR Apache-2.0
claw-auth-gateA lightweight authentication gateway and session manager for zeroclaw built with Axum and SQLite.16MIT
pow-captchaRust client and server-side verifier helpers for pow-captcha-server.16MIT
trustgrant-issueDraft and signable TrustGrant document construction16MIT OR Apache-2.0
trustgrant-evaluateHot-path evaluation engine for TrustGrant grants16MIT OR Apache-2.0
egideEgide - self-hosted Secrets Manager and Transit encryption in Rust (umbrella crate; KMS and PKI planned)16MIT OR Apache-2.0
agentic-receiptsSigned, tamper-evident execution receipts for AI agents, tool calls, GPU workloads, and distributed jobs.15MIT
cotsCots.ai SDK for Rust. cots::agents::AgentClient — configure once with tenant_id/agent_id, then guard() every governed action…15MIT
authentication-verifierOffline RS256 JWT verification for the Main X Index federation: fetch the authentication-service JWKS once, then verify…15MIT OR Apache-2.0 OR GPL-2.0 OR GPL-3.0 OR BSD-3-Clause
aauth-coreRust implementation of the AAuth protocol — authentication and authorization for autonomous agents, built on HTTP Message…15Apache-2.0
sekuire-agent-cliCLI for the Sekuire Agent Identity Protocol15Apache-2.0
vaid-clientVAID reference client SDK (Rust) for the verifiable agent-action identity standard. First capability: proof-of-possession request…15Apache-2.0
sanctum-sdkSanctum CRP v2 client SDK for AI agents — use, don't retrieve15Apache-2.0
authkestra-providersConsolidated OAuth providers for the authkestra framework15MIT OR Apache-2.0
reqkeyOfficial Rust SDK for ReqKey API key validation, credit metering, and analytics15MIT
aithos-bundleAithos Core bundle layout and storage — the only crate that touches I/O.15BUSL-1.1
majik-keyA post-quantum ready seed phrase account library for the Majikah ecosystem. Manages deterministic X25519 and ML-KEM-768…15Apache-2.0
stellar-agent-sep45SEP-45 Web Authentication for Contract Accounts: challenge validation, ephemeral-key signing, and JWT session handling.15Apache-2.0
gatedhouseEmbedded authorization library — Rust SDK15MIT
leptos-nostr-authHeadless Nostr authentication modal widget for Leptos15Apache-2.0
agentid-coreCryptographic identity for AI agents. Replaces hardcoded API keys with offline-verifiable Ed25519 tokens.14Apache-2.0
harbor-sdkAdd API key auth and billing to your Rust API in one line. Harbor handles validation so your users can authenticate with keys…14MIT
agent-uri-cliCommand-line tool for the agent:// identity scheme: key ceremony, attestation minting, verification, and inspection14MIT OR Apache-2.0
cryptcatadmin-rsIn-process Windows CatRoot catalog lookup service backed by SQLite14MIT
atshield-cliCommand-line client for atshield did:plc identity-tampering detection14MIT OR Apache-2.0
rune-axum-jwtJWT extractor and middleware layer for Axum — validates HS256/384/512 tokens with configurable claim checks13MIT
fandhe-backend-plugin-hub-wiringfandhe-backend の hub 共通配線プラグイン(TASK-9.1 / TASK-9.2)。コアの RequestGate 拡張点上に TenantGate を実装し、RS256 + JWKS による JWT 検証 → org_id 抽出 →…13MIT OR Apache-2.0
machine-krbManage an Active Directory machine-account Kerberos ticket (keytab renew/mint) and verify the AD join, on Linux, via the system…13MIT OR Apache-2.0
authkestra-opOpenID Provider (OP) support for the authkestra framework — issue tokens and run the authorization code grant, rather than only…13MIT OR Apache-2.0
s3-headers-liteA minimal, lightweight alternative to the official AWS crates. Only the headers necessary for communicating with S3-like services.13Apache-2.0
crabauthHost-approved credentials and Secure Enclave passkeys for browser VMs13MIT
trustgrantFacade crate re-exporting all TrustGrant protocol types for convenience13MIT OR Apache-2.0
quarb-awsShared AWS plumbing for the Quarb adapters: SigV4 signing and the credential chain12MIT OR Apache-2.0
appsurfaceSemantic web-app model: endpoints, roles, access matrix, ownership, and multi-role replay12MIT OR Apache-2.0
cheers-sqlxsqlx-backed UserStore / PasskeyCredentialStore / RefreshStore / Revocation impls for cheers — Postgres and SQLite backends.12MIT OR Apache-2.0
cheers-providersIdentity providers (OIDC, Apple Sign In, passkey, email magic-link, password, LAN-pair) and native credential stores built on…12MIT OR Apache-2.0
cheers-storeDevice-tier credential storage (OS keyring, encrypted file) implementing cheers-core's CredentialStore — no token crypto.11MIT OR Apache-2.0
cheers-redisredis-backed RefreshStore and Revocation impls for cheers — the TTL hot-path tier.11MIT OR Apache-2.0
cheers-axumaxum 0.8 route handlers for cheers — OIDC login/callback (Google, Apple), passkey, magic-link wiring into a SessionAuthority.11MIT OR Apache-2.0
keepassxc-clientKeePassXC browser native-messaging protocol client (associate, get-logins, set-login, ...)6MIT OR Apache-2.0