CATEGORY
Authentication 2,312 crates
Data as of 2026-07-25 (crates.io database dump, timestamp 2026-07-25T02:00:36Z). Source: crates.io · db-dump.tar.gz · methodology & corrections.
dpp-cryptoEd25519 key management, JWS signing/verification, and did:web document builder526Apache-2.0
tdln-gateTDLN — Policy Gate (preflight/decision) with proof-carrying determinism.524MIT
bedrock-jwtVerify Minecraft Bedrock Edition jwt chains and extract player claims.524MIT
hodei-authz-postgresPostgreSQL policy store adapter for Hodei authorization framework523MIT OR Apache-2.0
hodei-authz-redisRedis cache invalidation adapter for Hodei authorization framework520MIT OR Apache-2.0
mini-mail-authA minimal DKIM signing library for Rust, for those who just need to sign an email.520Apache-2.0 OR MIT
latticearcProduction-ready post-quantum cryptography. Hybrid ML-KEM+X25519 by default, all 4 NIST standards (FIPS 203–206), and FIPS 140-3…520Apache-2.0
hodei-authz-axumAxum web framework integration for Hodei authorization519MIT OR Apache-2.0
no-way-jose-coreCore traits, token types, and JWK support for the no-way-jose JOSE library518Apache-2.0
codoraShip Rust application faster than you could ever517MIT
authnz-argon2Pure Rust implementation of the Argon2 password hashing function with support
for the Argon2d, Argon2i, and Argon2id algorithmic…512MIT OR Apache-2.0
codlet-core(Deprecated) Migrated to [`codlet`](https://crates.io/crates/codlet).512Apache-2.0
permitryPluggable license management SDK with anti-rollback guarantees511MIT OR Apache-2.0
freebird-commonCommon utilities and shared types for the Freebird privacy-preserving authentication system510MIT OR Apache-2.0
nexo-plugin-googleGoogle APIs (Gmail/Calendar/Drive) tool plugin for Nexo agents (out-of-tree subprocess).510MIT OR Apache-2.0
emberlinkProgrammable trust between humans and machines — local-first, scoped, time-bound, revocable delegation of authority508MIT OR Apache-2.0
pepPolicy Enforcement Point - OIDC authentication and authorization library507MIT OR Apache-2.0
sudpSecret-Use Delegation Protocol — protocol-level secret use for agentic systems502Apache-2.0
glomeGeneric low-overhead message exchange with cryptographic integrity protection500Apache-2.0
openauth-oauthOAuth support for OpenAuth.498MIT
rooky-coreNostr based protocol for sharing chess data.493MIT
lvqr-authPluggable authentication providers for LVQR (static tokens, JWT, custom backends)490AGPL-3.0-or-later
neuron-authAuthentication provider traits for neuron487MIT OR Apache-2.0
age-plugin-argon2Argon2id recipient/identity plugin for the age encryption format486MIT OR Apache-2.0
unkey-rsAsync Rust SDK for the Unkey v2 API478MIT
toolkit-zeroA feature-selective Rust utility crate — a modular collection of opt-in utilities spanning encryption, HTTP networking,…473MIT
authkestra-tokenJWT token handling for the authkestra framework473MIT OR Apache-2.0
zerodds-bridge-securityShared security layer for ZeroDDS bridge daemons (ws/mqtt/coap/amqp/grpc/corba): §7.1 TLS (rustls), §7.2 auth modes…472Apache-2.0
toq-coreEncrypted agent-to-agent communication protocol library471Apache-2.0
tsafe-coreCore runtime engine for tsafe — encrypted credential storage, process injection contracts, audit log, RBAC471AGPL-3.0-or-later
anzarAnzar is a lightweight authentication and authorization framework that runs as a separate microservice470GPL-3.0
siwx-rsMulti-chain Sign-In with X (SIWX) library supporting Ethereum and Solana470Apache-2.0
o42sdkOfficial OAuth42 SDK for Rust - OAuth2/OIDC client library with Actix-web, Axum, and Rocket support467non-standard
rustfs-appauthApplication authentication and authorization for RustFS, providing secure access control and user management.465Apache-2.0
leash-sdkRust SDK for the Leash platform — unified async client for auth, env, and integrations.465Apache-2.0
drasi-identity-azureAzure identity provider plugin for Drasi465Apache-2.0
git-lfs-credsCredential helper bridge for Git LFS (git credential fill/approve/reject)463MIT
claw-guardSecurity, session, and policy engine for ClawDB.461Apache-2.0
steam-auth-rsSteam authentication and session management457MIT
better-auth-allsourceAllsource DatabaseAdapter for better-auth-rs — event-sourced auth persistence457MIT
assay-authAuthentication, OIDC (client + provider), passkey, Argon2, JWT, Biscuit capability tokens, session management, and Zanzibar-style…450Apache-2.0
solid-pod-rs-idpSolid-OIDC identity provider (authorization-code + DPoP-bound tokens, JWKS, credentials, dynamic client registration) — Rust port…449AGPL-3.0-only
jerrycan-authAuthentication extension for the jerrycan framework: argon2 password hashing, encrypted sessions, JWT, role guards.…448MIT
vortex-sdkVortex Rust SDK for authentication and invitation management447MIT
scp-identityDecentralized identity (DID) management for SCP (Shared Context Protocol)447Apache-2.0
rustywallet-signerECDSA and Schnorr message signing and verification for Bitcoin and Ethereum446MIT
corevpn-authAuthentication and authorization for CoreVPN - OAuth2, OIDC, SAML support446MIT OR Apache-2.0
rustywallet-mnemonicBIP39 mnemonic (seed phrase) generation and management for cryptocurrency wallets444MIT
openauth-social-providersSocial OAuth provider definitions for OpenAuth.441MIT
jwtiny-deriveMacros for jwtiny440MIT
cloudillo-idpIdentity provider subsystem for Cloudillo: registration, API keys, and tenant lifecycle438LGPL-3.0-only
agentic-identityCryptographic identity anchor for AI agents — persistent identity, signed actions, revocable trust435MIT
authx-coreCore authentication primitives for authx-rs: crypto, JWT/EdDSA, RBAC/ABAC, events, and models433MIT
signet-coreCryptographic action receipts for AI agents431Apache-2.0 OR MIT
arbiter-cliCLI for Arbiter agent lifecycle management430Apache-2.0
grpc-jwt-tonicJWT authentication and authorization middleware for servers in Rust + Tonic ecosystem417MIT OR Apache-2.0
arbiter-mcp-firewallArbiter: MCP tool-call firewall, integration binary414Apache-2.0
vaultproxySecure credential sidecar for MCP servers — injects auth from Vaultwarden without exposing secrets to AI agents412MIT
forgejo-keycloak-mcp-policyPolicy registry and generated Forgejo API classification data for forgejo-keycloak-rust-mcp.410AGPL-3.0-or-later
hessra-context-tokenContext token implementation for Hessra - information flow control via exposure tracking410Apache-2.0
webauthn-rs-proto-icpWebauthn Specification Bindings409MPL-2.0
ppoppo-sdk-coreInternal shared primitives for the Ppoppo SDK family (pas-external, pas-plims, pcs-external) — verifier port, audit trait,…404MIT OR Apache-2.0
chie-cryptoCryptographic primitives for CHIE Protocol403Apache-2.0
nklave-coreCore signing logic, BLS/Ed25519 keys, and slashing protection rules for Nklave398MIT
tibet-zip-jistibet-zip JIS integration: .jis.json parser, authorization, repository identity binding398MIT OR Apache-2.0
securitydept-credsCredentials of SecurityDept, a layered authentication and authorization toolkit built as reusable Rust crates.394MIT
saml-rsPure-Rust SAML 2.0 Service Provider and Identity Provider support.394MIT
hessra-cap-tokenCapability token implementation for Hessra392Apache-2.0
paytourCliente Rust para autenticação e consumo da API Paytour (login e passeios)391MIT
coldstar-signerSecure signing core — AES-256-GCM, Argon2id, Ed25519, secp256k1, ZK proofs, mlock'd memory390MIT
anpRust SDK for Agent Network Protocol (ANP)390MIT
securitydept-oauth-providerOAuth Provider of SecurityDept, a layered authentication and authorization toolkit built as reusable Rust crates.388MIT
dig-ipc-protocolCanonical dig-app ⇄ dig-node IPC session/signing contract: domain-separated challenge/callback/user-sign message builders (app…385Apache-2.0 OR MIT
supabase-client-authAuth (GoTrue) client for supabase-client383MIT OR Apache-2.0
user-permission-coreAsync user / group / permission core (SQLite backend, Argon2, JWT, optional HTTP relay)381MIT OR Apache-2.0
auth_envauth_env379MulanPSL-2.0
rs-machineidGet the unique machine ID of any host (without admin privileges).378MIT
authkestra-sessionSession management and persistence for the authkestra framework377MIT OR Apache-2.0
hyperdb-api-salesforceSalesforce Data Cloud OAuth authentication for Hyper database376MIT OR Apache-2.0
klauthed-protocolProtocol types for klauthed: OAuth2, OpenID Connect, JWKS, and SCIM.374MIT OR Apache-2.0
hessra-identity-tokenIdentity token implementation for Hessra374Apache-2.0
passkiA simple and secure WebAuthn/Passkey authentication library372Apache-2.0
rustauth-coreCore types and primitives for RustAuth.371MIT
authx-storageStorage abstraction layer for authx-rs: repository traits, in-memory store, and PostgreSQL adapter370MIT
pidge-clientMicrosoft 365 / Graph client and OAuth flows for the pidge CLI368MIT
klauthed-securitySecurity primitives for klauthed: JWT, sessions, authorization, AEAD, MFA/TOTP, password and key derivation, API keys.366MIT OR Apache-2.0
auths-jwtShared JWT claim types for the Auths identity system366Apache-2.0
libauth-rsUnified authentication and authorization library with Stytch, Clerk, and MSAL support365MIT
authkestra-guardAuthentication guard and strategies for the authkestra framework363MIT OR Apache-2.0
permkitGeneric permission registry, permission derive macro, and route guard macro363MIT
agentic-paymentsAutonomous multi-agent Ed25519 signature verification with Byzantine fault tolerance362MIT OR Apache-2.0
ai-connectConnect to AI provider accounts via OAuth 2.0 + PKCE. Supports Anthropic, OpenAI, and custom providers.362MIT
inferadbOfficial Rust SDK for InferaDB362Apache-2.0
forgejo-keycloak-mcp-auditToken-safe audit event schema for forgejo-keycloak-rust-mcp.360AGPL-3.0-or-later
svault-aiSecret access layer for cooperative AI agents — structured, policy-gated, audited credential access359Apache-2.0
anprotoRust implementation of ANProto: the Authenticated and Non-networked protocol358Apache-2.0
mailledger-oauthOAuth2 authentication library for email protocols357MIT
darkstrata-credential-checkRust SDK for DarkStrata credential breach checking API with k-anonymity privacy protection356Apache-2.0
forgejo-keycloak-mcp-identityKeycloak OIDC discovery, JWKS, and bearer-token validation for forgejo-keycloak-rust-mcp.354AGPL-3.0-or-later
wae-sessionWAE Session - 会话管理,支持内存存储354MIT
fusionauth_jwt_rsWASI-compatible FusionAuth JWT verification (JWKS / RS256) for wasmCloud components353MIT
nucleus-identity-projectionIdentity projection lifter for the Nucleus substrate. Lifts a JWT-SVID (SPIFFE 2.0) into a Projection::Identity body that the…352MIT OR Apache-2.0
fuse-coreCore VCE protocol implementation for verifiable compliance proofs351Apache-2.0
oxify-authnAuthentication module for OxiFY - JWT, OAuth2, SAML, LDAP support (ported from OxiRS)346MIT OR Apache-2.0
oxify-authzReBAC (Relationship-Based Access Control) authorization engine - Google Zanzibar implementation345MIT OR Apache-2.0
authrsA comprehensive authentication library for Rust345MIT
arete-authAuthentication and authorization utilities for Arete343non-standard
bliss-cryptoCryptographic primitives for Bliss cryptocurrency342MIT OR Apache-2.0
ironsealLightweight identity-free attestation protocol341MPL-2.0
swink-agent-authCredential management and OAuth2 support for swink-agent340MIT
futureauthOTP authentication SDK — local session management with FutureAuth OTP delivery338MIT
dioxus-cookieUnified cookie storage for Dioxus fullstack apps that fills the gap in native platforms with keychain integration and encrypted…337MIT
authkestra-providers-discordDiscord OAuth provider for the authkestra framework335MIT OR Apache-2.0
supso-projectOffline software license verification for project maintainers via Supported Source.335Apache-2.0
pakery-spake2SPAKE2 balanced PAKE protocol (RFC 9382)335MIT OR Apache-2.0
auths-pairing-daemonEmbeddable LAN pairing daemon for Auths - HTTP server, rate limiting, mDNS discovery333Apache-2.0
kirinoZero-trust authentication and authorization framework with RBAC and dynamic risk assessment.330non-standard
rok-authJWT authentication and RBAC for the rok ecosystem327MIT
webauthn-rs-core-icpWebauthn Cryptographic Operation Handling326MPL-2.0
asport-hyphae-handshakeNoise protocol framework handshakes for QUIC326MIT OR Apache-2.0
rbp-authJWT and Argon2 authentication for robopoker326MIT
crabkey-middlewareAxum middleware for API key auth, usage tracking, and request IDs326MIT
mailrs-auth-guardPer-IP + per-(IP, username) failed-auth counter with exponential-backoff lockout. IPv6 normalized to /64 prefix. Sharded DashMap;…325Apache-2.0 OR MIT
oauth-card-coreProvider-agnostic OAuth card decision + Adaptive Card rendering logic (no component exports), shared by the oauth-card component…325MIT
huskarl-google-cloudGoogle Cloud support for huskarl (OAuth2 client) ecosystem.325MIT OR Apache-2.0
rain-sdkA modern, type-safe Rust SDK for the Rain xyz API324MIT OR Apache-2.0
get-github-app-tokenCLI tool to obtain a GitHub App Installation Access Token via JWT323MIT
authkestra-flowOAuth2 and OIDC flow orchestration for the authkestra framework323MIT OR Apache-2.0
dog-authAuthentication system for DogRS framework323MIT OR Apache-2.0
vault-client-rsA Rust client for the HashiCorp Vault HTTP API321Apache-2.0 OR MIT
keylightKeylight licensing SDK — activate/validate licenses with offline Ed25519 lease verification.319MIT
sigil-protocolSIGIL — Sovereign Identity-Gated Interaction Layer. An open protocol for securing AI agent-to-tool interactions.316EUPL-1.2
schema-registry-securitySecurity, authentication, authorization, and SOC 2 compliance for LLM Schema Registry316Apache-2.0
turul-jwt-validatorGeneric JWT validator with JWKS caching and kid-miss refresh316MIT OR Apache-2.0
meganz-account-generatorAutomated MEGA.nz account generator using temporary email315MIT
crypt-sha512no_std SHA512-crypt ($6$) password hashing, ported from Ulrich Drepper's reference implementation. Pluggable crypto backend…315BSD-2-Clause
idprova-coreCore library for IDProva — AI agent identity, delegation, and audit314Apache-2.0
llm-cost-ops-complianceCompliance, authentication, and audit logging for LLM Cost Ops313Apache-2.0
lib-client-google-authGoogle OAuth2 authentication library for ADI308BSL-1.0
schlusselCross-platform OAuth 2.0 with PKCE for CLI applications308MIT
bt_auth0An Auth0 authentication API that returns the access token and user info307CC-BY-NC-ND-4.0
securitydept-oidc-clientOIDC Client of SecurityDept, a layered authentication and authorization toolkit built as reusable Rust crates.305MIT
nyxpassSecure command line utility to manage passwords, authenticator app OTP codes, SSH keys, and notes.303Apache-2.0 OR MIT
ingress-coreCore request, identity, and event types for Gatewarden.303AGPL-3.0-only
ppoppo-tokenJWT (RFC 9068, EdDSA) issuance + verification engine for the Ppoppo ecosystem. Single deep module with a small interface (issue,…302MIT
beeper-desktop-apiRust API wrapper for Beeper Desktop API301MIT
atproto-poemATProto OAuth integration for Poem299MPL-2.0
auths-scimSCIM 2.0 resource types and protocol logic for Auths agent provisioning299Apache-2.0
user-permissionAsync user / group management — axum REST API + WebUI library and a ready-to-run server binary296MIT OR Apache-2.0
ssh-commander-keychainmacOS Keychain credential storage for ssh-commander-core. A small synchronous leaf crate shared by the SSH and PostgreSQL layers.293MIT OR Apache-2.0
tauri-plugin-appauthTauri 2 mobile plugin that bridges OAuth 2.0 / OIDC flows to AppAuth-iOS and AppAuth-Android.293Apache-2.0
token-analyzerFast, parallel token security analyzer - Detect exposed secrets, API keys, and sensitive tokens in your codebase292MIT
authx-pluginsAuth plugin collection for authx-rs: email/password, TOTP, magic link, OAuth, API keys, organizations, and more291MIT
noah-sdkA modern, type-safe Rust SDK for the Noah Business API290MIT OR Apache-2.0
nexara-coreCore types, policy, registry, broker, and audit schema for Nexara290MIT
tail-fin-credentialsShared credential-storage primitives for tail-fin: 0o600 file IO, cookie entry shape, JWT subject extraction289MIT
actix-security-coreSpring Security-like authentication and authorization for Actix Web - Core library289MIT OR Apache-2.0
doxa-policyFramework-neutral Cedar-based authorization policy engine. Policy / PolicyExtension / PolicyStore / PolicyRouter traits with a…289Apache-2.0
perfgate-authAuthentication and authorization types for perfgate288MIT OR Apache-2.0
tofa-coreCore library for tofa — encrypted TOTP vault288MIT
hessra-cap-engineCapability engine for the Hessra authorization system288Apache-2.0
actix-security-codegenProcedural macros for actix-security (Spring Security-like annotations)288MIT OR Apache-2.0
forgejo-keycloak-rust-mcpClean-room Rust MCP gateway for Forgejo with Keycloak identity and Forgejo ACL enforcement.287AGPL-3.0-or-later
siwxSign In with X287MIT OR Apache-2.0
csv-adapter-coreChain-agnostic core traits and types for CSV (Client-Side Validation) adapters286MIT OR Apache-2.0
hessra-cliCommand-line interface for Hessra authentication and identity management286Apache-2.0
reverse_resonance_idSelf-checking symmetric tokens based on reversing squared user identifiers.283MIT OR Apache-2.0
ssh-commander-coreAsync Rust domain layer for SSH, SFTP, FTP/FTPS, PostgreSQL, and connection management — the engine behind midnight-ssh.283MIT OR Apache-2.0
openid-federationA Rust implementation of the OpenID Federation 1.0 standard282Apache-2.0
fynx-protoProduction-ready SSH and IPSec/IKEv2 protocol implementations with comprehensive testing and high-level APIs279MIT OR Apache-2.0
cloudillo-authAuthentication subsystem for Cloudillo: login, JWT tokens, and WebAuthn passwordless auth279LGPL-3.0-only
signedby-sdkSIGNEDBYME SDK - Human-Controlled Identity for Autonomous Agents277LicenseRef-SSAL-1.0
skg-secretSecret resolution traits and types for skelegent275MIT OR Apache-2.0
cirrus-authSalesforce OAuth 2.0 authentication flows for the Cirrus SDK.275MIT
kurbu5-rsSafe, idiomatic Rust API for writing MIT Kerberos non-KDB plugin modules274BSD-2-Clause
tumpa-cliOpenPGP operations and SSH agent backed by tumpa keystore.273GPL-3.0-or-later
turbine-rpc-proxyMulti-chain RPC proxy with intelligent endpoint rotation273MIT
securitydept-oauth-resource-serverOAuth Resource Server of SecurityDept, a layered authentication and authorization toolkit built as reusable Rust crates.272MIT
kafka_clientA pure Rust Kafka client library with SASL authentication support271Apache-2.0 OR MIT
bunnyapp-licenseLicense validation SDK for Bunny subscriptions271MIT
hap-cryptoHomeKit Accessory Protocol pairing crypto: Pair Setup (SRP-6a) and Pair Verify (X25519/Ed25519); HAP-BLE broadcast key derivation…269Apache-2.0
spn-keyringOS keychain wrapper for SuperNovae CLI268MIT OR Apache-2.0
idiolect-identityDID resolution for idiolect: maps did:plc and did:web identifiers to their DID documents, handles, and PDS service URLs. Ships a…267MIT
ubl-idUniversal Business Ledger identity primitives: DIDs (did:ubl:*), CIDs (cid:blake3:*), Wallets, and PoP headers. RFC-0001…266MIT OR Apache-2.0
tail-fin-bootstrapCredential-acquisition primitives for tail-fin: stealth Chromium launch, CDP cookie export, dedupe-and-filter helpers260MIT
klauthedUmbrella starter crate for the klauthed framework — re-exports the klauthed-* libraries behind feature flags.259MIT OR Apache-2.0
grindvaktReusable, runtime-agnostic OAuth2 / OpenID Connect / OpenID Federation protocol library built on jose-rs.257BSD-2-Clause
asport-quinn-hyphaeNoise protocol framework handshakes for the Quinn QUIC library256MIT OR Apache-2.0
philiprehberger-webhook-signatureHMAC-SHA256 webhook signing and verification for Rust255MIT
authz-coreZanzibar-style authorization engine — model parser, resolver, policy traits, and CEL condition evaluation255Apache-2.0
steamworks-encrypted-app-ticket-sysLow-level bindings for Steam's sdkencryptedappticket254MIT OR Apache-2.0
smbcloud-auth-sdk-pyPython bindings for the smbCloud Auth SDK.254Apache-2.0
secret-resolversPluggable secret resolution from multiple backends253MIT
sigilforge-clientClient library for Sigilforge authentication daemon253MIT OR Apache-2.0
nklave-storagePersistence layer for Nklave: append-only decision logs, checkpoints, and EIP-3076 interchange252MIT
pdfluent-signPDF digital signature validation — PAdES, CMS, certificate chain, DocMDP/FieldMDP, LTV.252non-standard
kavach-coreCore execution boundary engine, gate, verdicts, identity, policy, drift, invariants252LicenseRef-Elastic-2.0
tauri-plugin-keylightTauri v2 plugin for the Keylight licensing SDK (Rust side)250MIT
x0x-symphony-signingx0xd signing and verification infrastructure for x0x-symphony.249AGPL-3.0-or-later
lkr-coreCore library for LLM Key Ring — secure LLM API key management via macOS Keychain248MIT OR Apache-2.0