CATEGORY
Authentication 2,312 crates
Data as of 2026-07-25 (crates.io database dump, timestamp 2026-07-25T02:00:36Z). Source: crates.io · db-dump.tar.gz · methodology & corrections.
cadenServer-side WebAuthn/Passkey library implementing the W3C WebAuthn Level 2 specification248MIT OR Apache-2.0
openauth-telemetryTelemetry support for OpenAuth.248MIT
auth0-integrationAuth0 client library for M2M token retrieval and JWT validation (RS256)247MIT
gatekeepCode-first authorization engine for Rust246MIT OR Apache-2.0
rustauth-oauthOAuth support for RustAuth.245MIT
converge-policyCedar-based Policy Decision Point for Converge gate model241MIT
netviper-talosA Rust-based secure licensing system.238MIT
iron_token_managerAPI token lifecycle management and usage tracking237MIT
gamlastan-mdqSAML Metadata Query Protocol (MDQ) client for gamlastan237BSD-2-Clause
securitydept-realipReal IP of SecurityDept, a layered authentication and authorization toolkit built as reusable Rust crates.233MIT
authboxA lightweight, modular authentication framework for Rust built around traits, async support, and pluggable component231Apache-2.0
p47h-engineCore engine for p47h governance - pure library, no WASM artifact231Apache-2.0
lilo-im-coreIdentity Matters core: Authorizer trait, Principal types, peer credential extraction (Helioy v1 IAM)231MIT
gitway-libCore SSH transport library for Git hosting services (GitHub, GitLab, Codeberg, and self-hosted).230GPL-3.0-or-later
tbz-jisAlias for tibet-zip-jis — JIS identity binding and authorization228MIT OR Apache-2.0
jwtypeTypes for jwtiny226MIT
coldstar-walletWallet management — key generation, encrypted storage, backup/restore226MIT
llm-securityComprehensive LLM security layer to prevent prompt injection and manipulation attacks225MIT
tufa-rsA terminal-based TOTP authenticator225MIT
doxa-authProvider-agnostic OIDC / RFC 7519 / RFC 7662 auth middleware with a pluggable Cedar policy engine. Generic over a…225Apache-2.0
tauri-plugin-siwaSign In with Apple for Tauri 2 — supports iOS and macOS.224MIT
hyperstack-authAuthentication and authorization utilities for Hyperstack223non-standard
ratify-protocolDelegated-authority proofs for human-agent and agent-agent interactions — Rust reference SDK for the Ratify Protocol.223Apache-2.0
authx-axumAxum integration for authx-rs: Tower middleware, session management, CSRF, rate limiting, and route handlers223MIT
keepassxc-proxy-libClient library for communicating with KeePassXC via its browser integration protocol222MIT
crabkey-coreUmbrella crate re-exporting all crabkey components222MIT
op-mcpMCP server providing LLM access to 1Password CLI221MIT
auths-mcp-coreReusable per-tool-call enforcement for the bounded-agent MCP gateway: scope ⊆ parent, quantitative budget, expiry, revocation,…220Apache-2.0
rustauth-social-providersSocial OAuth provider definitions for RustAuth.219MIT
pleme-rbacAuthorization library for Pleme platform219MIT
secretxBackend-agnostic secrets retrieval. One trait, many stores. URI-driven backend selection.218MIT
authsDecentralized identity for developers — cryptographic commit signing with Git-native storage218Apache-2.0
samlifyMaintained compatibility re-export of saml-rs.217MIT
auths-mcp-serverReference MCP tool server with Auths-backed JWT and KERI-presentation authorization216Apache-2.0
drasi-identity-awsAWS identity provider plugin for Drasi216Apache-2.0
kpxPure Rust KeePassXC browser integration client with a simple synchronous API215MIT
claude_profile_coreLayer 1 domain logic: token status and account management for Claude Code215MIT
tauri-plugin-secure-elementTauri plugin for secure element use on iOS (Secure Enclave) and Android (Strongbox and TEE).214Apache-2.0
securitydept-token-set-contextToken Set Context of SecurityDept, a layered authentication and authorization toolkit built as reusable Rust crates.214MIT
ubl-axum-kitShared Axum middleware for UBL services: JWT/PoP verification, rate limiting, tenant extraction213MIT OR Apache-2.0
rustbasic-permissionRole and Permission management package for the RustBasic Framework.213MIT
rs-ali-stsAlibaba Cloud STS (Security Token Service) SDK for Rust212MIT
kaccy-reputationReputation and scoring system for Kaccy Protocol - trust, fraud detection, and tier management212Apache-2.0
huskarl-loginOAuth2/OIDC login flow helpers for huskarl.212MIT OR Apache-2.0
secretx-fileFilesystem backend for secretx.211MIT
pgjwt_rsPostgreSQL extension for JWT verification with RS256 and Ed25519 support211AGPL-3.0-only
hasp-coreCore contracts, errors, and traits for hasp.211MIT OR Apache-2.0
secretx-envEnvironment variable backend for secretx.210MIT
openauth-sqlxSQLx database adapters for OpenAuth.210MIT
gonauthOAuth2/OIDC callback flows, signed OAuth state, and JWT helpers for web backends209Apache-2.0
ats-sdkAllfeat Timestamp Service SDK — Reference implementation209MIT
gaia-clientRust client library for Gaia secret management daemon209MIT
openauthRust authentication toolkit.209MIT
hodei-authz-sdkComplete Cedar Policy-based authorization SDK with auto-discovery and builder pattern208MIT OR Apache-2.0
vigil-policyPolicy engine for Vigil — declarative ALLOW/DENY rules, OAuth scope allowlist DSL, capability levels207Apache-2.0
syntarq-coreCore cryptographic identity and data management library for Syntarq207MIT
idprova-verifyIDProva verification utilities — DAT and receipt log verification206Apache-2.0
axum-email-otp-authA production-ready, framework-agnostic Rust library for OTP email authentication.205MIT
huskarl-pingoraPingora integration for huskarl OAuth2 resource server.205MIT OR Apache-2.0
rust-license-keyA production-grade Rust library for creating and validating offline software licenses using Ed25519 cryptography203MIT OR Apache-2.0
hap-pairingHomeKit Accessory Protocol Pair Setup / Pair Verify orchestration, pairings management, and persistence.203Apache-2.0
hodei-kernelCore types and traits for Hodei authorization system with Cedar Policy203MIT
oxirs-didW3C DID and Verifiable Credentials implementation with Signed RDF Graphs for OxiRS203Apache-2.0
hodei-provider-deriveProcedural macros for Hodei authorization system with Cedar Policy201MIT
win-security-identifierWindows Security Identifier (SID) library201MIT OR Apache-2.0
authorization-bridgeAn Actix Web middleware for authenticating HTTP requests through a remote API. It validates Authorization headers or cookies and…200MIT
authkestra-axumAxum integration for the authkestra authentication framework199MIT OR Apache-2.0
kavach-pqPost-quantum transport security, ML-KEM key encapsulation, ML-DSA signatures, hybrid channels, verdict signing199LicenseRef-Elastic-2.0
lilo-im-stubIdentity Matters v1 stub: StubAuthorizer that audits decisions without enforcement199MIT
agent-id-coreCore identity primitives for the Agent Identity Protocol198Apache-2.0
propelAxum middleware for Supabase Auth on Google Cloud Run198MIT OR Apache-2.0
webgates-coreCore domain types, permission system, and authorization building blocks for webgates.198MIT
actix-securitySpring Security-like authentication and authorization for Actix Web197MIT OR Apache-2.0
actpub-httpsigDual-stack HTTP Message Signatures (Cavage draft-12 + RFC 9421) with RSA & Ed25519 via aws-lc-rs.196MIT OR Apache-2.0
hodei-providerProvider traits and inventory system for Hodei authorization with Cedar Policy196MIT
crypt-ioAEAD encryption (ChaCha20-Poly1305, AES-256-GCM), hashing (BLAKE3, SHA-2), MAC (HMAC, BLAKE3 keyed), and KDF (HKDF, Argon2id) for…196Apache-2.0 OR MIT
gk-authenticatorA command line OTP authenticator app195MIT
livy-teeIntel TDX quote generation and verification for the Livy provenance system. Open-source so users can independently verify TEE…195MIT
key-vaultEnterprise-grade key management vault for Rust. 9-layer defense-in-depth: fragmentation, decoy bytes, codex transform, mlock +…195Apache-2.0 OR MIT
axiam-sdk-macrosProc-macro Actix-Web authorization attributes for the AXIAM Rust SDK (axiam-sdk)193Apache-2.0
basil-natsGeneric, dependency-light builder for NATS account/user JWTs (ed25519-nkey) where signing is delegated to an external signer…193Apache-2.0
openauth-pluginsOfficial OpenAuth plugin modules.193MIT
firebase-adminAn open-source Firebase Admin SDK for Rust: Authentication and Cloud Messaging192MIT OR Apache-2.0
cloudillo-auth-adapter-sqliteSQLite-backed authentication adapter for Cloudillo: JWT, signing keys, passwords, WebAuthn, and TLS certificates192LGPL-3.0-only
auths-cliCommand-line interface for Auths decentralized identity system192Apache-2.0
totp-gatewayA high-performance TOTP-based authentication gateway built on Cloudflare's Pingora framework for securing private network access191MIT
paseto-v2PASETO/PASERK V2 based on RustCrypto191Apache-2.0
myidRust client library for MyID SDK API — user identification and verification190MIT OR Apache-2.0
llm-edge-securitySecurity layer for LLM Edge Agent (auth, validation, PII redaction)190Apache-2.0
rs-auth-coreCore types, crypto, and domain logic for rs-auth.189MIT OR Apache-2.0
bsv-auth-actix-middlewareBSV BRC-31 authentication middleware for Actix-web189non-standard
paseto-v1PASETO/PASERK V1 based on RustCrypto188Apache-2.0
subduction_keyhive_policyKeyhive-based authorization policy for Subduction connections188MIT OR Apache-2.0
shipper-output-sanitizerSanitize cargo command output before persistence and logging188MIT OR Apache-2.0
bsv-authBSV Blockchain SDK - Authentication, certificates, and peer communication187MIT
riley-auth-coreCore library for riley_auth — config, database, JWT, and OAuth primitives187MIT
securitydept-session-contextSession Context of SecurityDept, a layered authentication and authorization toolkit built as reusable Rust crates.186MIT
kurbu5-kdb-rsSafe, idiomatic Rust API for writing MIT Kerberos KDB driver plugins186BSD-2-Clause
arium-wireFramework-agnostic wire types shared across arium auth crates.185MIT OR Apache-2.0
devboy-storageSecure credential storage for devboy-tools — OS keychain (macOS/Windows/Linux) with redacted SecretString plumbing.185Apache-2.0
doxaFacade crate re-exporting the doxa family: OpenAPI docs, auth, policy, audit, and secret types. Enable only the features you need.184Apache-2.0
securitydept-basic-auth-contextBasic Auth Context of SecurityDept, a layered authentication and authorization toolkit built as reusable Rust crates.183MIT
rust-yt-uploaderHigh-performance YouTube video uploader in Rust with OAuth 2.0, concurrent uploads, and comprehensive validation183MIT
vigil-firewallFail-closed effect firewall for Vigil — policy engine, approval queue, PII scanner, OAuth scope allowlist182Apache-2.0
llm-config-securitySecurity hardening and validation for LLM Config Manager with input validation, rate limiting, and threat protection182Apache-2.0
frame-sentinelMulti-dimensional trust scoring and relationship management for AI systems182MIT
truthlinked-mcpOn-chain MCP registry, agent policy, tool-call, and private-balance primitives for TruthLinked.182MIT
claude-usageFetch Claude API usage data from Anthropic182MIT OR Apache-2.0
secrets-rs-macrosProcedural macros for secrets-rs182MIT
palisade-configSecurity-conscious configuration management for honeypot systems with cryptographic tag derivation181Apache-2.0
duke-crypto-coreCore cryptographic library for generating mnemonics and ED25519 key pairs with BIP39 and SLIP-10 support179MIT OR Apache-2.0
securitydept-creds-manageCredentials Management of SecurityDept, a layered authentication and authorization toolkit built as reusable Rust crates.179MIT
securitydept-coreCore of SecurityDept, a layered authentication and authorization toolkit built as reusable Rust crates.179MIT
mws-climws — one CLI for Microsoft 365 / Microsoft Graph (Outlook mail, OneDrive, Teams, Entra). cargo install mws-cli.177MIT OR Apache-2.0
authoraOfficial Rust SDK for the Authora agent authorization platform177MIT
gauge-authEd25519 challenge/response authentication and JWT issuance for Gauge, the privacy-first developer telemetry platform.176MIT OR Apache-2.0
icebox-govRuntime governance for autonomous offensive security — the single seam every human operator, REST client, and LLM agent must pass…176MIT
hyper-keyringHyperliquid key management — HD wallet, BIP-39 mnemonic, OS keychain integration174MIT
webgatesApplication-facing composition crate for webgates authentication and authorization.174MIT
basil-keystore-backendOptional Basil key-store backends over db-keystore and 1Password.174Apache-2.0
lilo-im-storeIdentity Matters audit storage: SqliteAuditSink and filtered audit query API172MIT
rustsamlMaintained compatibility re-export of saml-rs.172MIT
frame-presenceSession tracking and device fingerprinting for AI systems171MIT
authbox-coreCore authentication traits and types for AuthBox170Apache-2.0
tsafe-agentLocal session agent for tsafe — holds vault unlock state over named pipe/socket for passwordless exec169AGPL-3.0-or-later
agent-protocolsRust SDK for Agent Identity, Agent Profile, Agent Delegation, and Agent Discourse protocols169MIT
secretx-wolfhsmwolfHSM secure element backend for secretx.169MIT
cf-gears-static-authn-pluginAuthN resolver plugin with static token-to-identity mapping for development and testing166Apache-2.0
tinyscramMinimal, sync SCRAM-SHA-256 (RFC 5802 / RFC 7677) state machine for server and client roles, with channel-binding-aware GS2…166Apache-2.0
basil-coreBasil daemon core, broker services, transport, and offline admin command implementations.165Apache-2.0
rustauth-tokio-postgrestokio-postgres database adapter for RustAuth.164MIT
nostro2-traitsSigning traits for the nostro2 ecosystem (NostrSigner, NostrKeypair).164MIT
passcorePasscore is a lightweight Rust library that scores password strength.163MIT
kryphocronPrivacy-first ATProto substrate primitives: type architecture, audit vocabulary, inter-service auth, and encryption hook surfaces163MPL-2.0
actpub-webfingerWebFinger (RFC 7033) client and server primitives for ActivityPub.162MIT OR Apache-2.0
agdr-akiCryptographically-sealed AI decision records with provenance, audit, and compliance. Court-admissible inference logging for LLM…161Apache-2.0 OR CC0-1.0
self-agent-sdkRust SDK for Self Agent ID — on-chain AI agent identity with proof-of-human161BUSL-1.1
zvault-coreCore library for ZVault — AES-256-GCM barrier, Shamir seal, token auth, policy engine, audit logging161MIT OR Apache-2.0
securoCryptographic impl for hybrid classical-post-quantum authentication and secure communication161MIT
rustauth-sqlxSQLx database adapters for RustAuth.161MIT
skg-authAuthentication provider traits for skelegent160MIT OR Apache-2.0
rs_ai_oauthOAuth flows and runtime model discovery for AI providers (xAI Grok, OpenAI ChatGPT)160ISC
astraguardOfficial AstraGuard SDK - license validation, HWID binding, anti-debug, and offline cache for Rust applications159MIT
stfx-cryptoCore cryptographic primitives for the Sovereign Trust Framework (STFx).159Apache-2.0
steamworks-encrypted-app-ticketSafe Rust wrapper for decrypting Steam Encrypted App Tickets159MIT OR Apache-2.0
wristbandIn and out privileges: Consent-gated, domain-scoped reader for the user's own browser session cookies159CC0-1.0
digisacCliente Rust para autenticação e consumo da API Digisac (webhooks e mensagens)158Apache-2.0
authkestra-oidcOIDC support for the authkestra framework158MIT OR Apache-2.0
rustauth-pluginsOfficial RustAuth plugin modules.158MIT
pic-protocolPIC Protocol - Provenance Identity Continuity Protocol157Apache-2.0
herald-sdkRust SDK for Herald — multi-tenant auth, billing & points API client156Apache-2.0
gamploHTTPS Gamplo Client API156GPL-3.0-only
authkestra-actixActix-web integration for the authkestra authentication framework156MIT OR Apache-2.0
siwx-evmSign In with X155MIT OR Apache-2.0
siwx-svmSign In with X155MIT OR Apache-2.0
hessra-cap-policyDefault CList policy backend for the Hessra capability engine155Apache-2.0
llm-secretsWorkload identity for AI agents — prove who you are, access only what you should, for only as long as you need154MIT
smith-jailerSecure sandboxing and isolation for capability execution153MIT
rustywalletCryptocurrency wallet utilities for Rust - keys, addresses, mnemonics, HD wallets, and signing153MIT
pq-jwtPost-Quantum JWT implementation using ML-DSA (FIPS 204) signatures for quantum-resistant authentication153MIT OR Apache-2.0
lkr-cliCLI for LLM Key Ring — manage LLM API keys via macOS Keychain153MIT OR Apache-2.0
axess-identityIdentity primitives for the axess workspace: typed identifiers
(TenantId, UserId, DeviceId, SessionId, EventId; all…152MIT OR Apache-2.0
secretx-gcp-smGCP Secret Manager backend for secretx.151MIT
dyolo-kyaKnow Your Agent (KYA): cryptographic chain-of-custody for recursive AI delegation with provable scope narrowing, namespace…151MIT OR Apache-2.0
authkestra-providers-githubGitHub OAuth provider for the authkestra framework149MIT OR Apache-2.0
authforgeAuthForge SDK — license validation, HWID binding, and heartbeat verification149MIT
aitp-envelopeAITP envelope signing and verification (no I/O, no HTTP)149MIT OR Apache-2.0
nvlp-coreCore library for nvlp: encrypt files to GitHub users via their SSH keys149MIT
authotronAuthentication and authorization gateway for web APIs. Validates credentials from multiple providers, enriches users with roles,…149Apache-2.0
cf-gears-rg-tr-pluginTenant resolver plugin with RG hierarchy resolution148Apache-2.0
libmacaroonMacaroons (bearer credentials with contextual caveats) in pure Rust, with first-party and third-party caveats, WASM support, and…148MIT
poh-sdkProof of Human SDK — scan wallets, poll async jobs, access signal methods148MIT
tsafe-mcpBound-contract MCP server for tsafe — run policy-scoped commands without exposing secret values.147AGPL-3.0-or-later
cellos-broker-envEnvironment-variable SecretBroker for CellOS — resolves spec secretRefs from process env. Dev/CI default.147MIT OR Apache-2.0
ubl-mcpSecure, audited Model Context Protocol (MCP) client/server with policy gates and audit logging.147MIT
qv-coreSigvault — post-quantum cryptographic tokens (ML-DSA-87 + Falcon-512/1024, XChaCha20-Poly1305, SHA3-256, mutation-chain replay…147Apache-2.0 OR AGPL-3.0-only
cellos-broker-vaultHashiCorp Vault SecretBroker for CellOS — runtime-leased credentials per cell with auto-revoke on teardown.146MIT OR Apache-2.0
convergio-securityAuth, HMAC, crypto, audit logging, trust, sandbox146MIT
cf-gears-tr-authz-pluginAuthZ resolver plugin with tenant hierarchy resolution via Tenant Resolver146Apache-2.0
webgates-secretsSecret value and hashing primitives for the webgates authentication and authorization ecosystem.146MIT
gamlastan-actixSAML 2.0 actix-web integration - extractors, responders, SP/IdP handlers146BSD-2-Clause
pakery-opaqueOPAQUE augmented PAKE protocol (RFC 9807)146MIT OR Apache-2.0
reauth-typesShared types and crypto primitives for Reauth authentication145MIT
axiam-sdkOfficial Rust client SDK for AXIAM IAM145Apache-2.0
cellos-broker-fileFilesystem SecretBroker for CellOS — resolves spec secretRefs from on-disk files (Kubernetes-mounted secrets, systemd…145MIT OR Apache-2.0
cellos-broker-oidcOIDC SecretBroker for CellOS — fetches workload identity tokens via OIDC token exchange (GitHub Actions, GitLab CI, Azure DevOps).145MIT OR Apache-2.0
osnma-longan-nanoGalileo OSNMA demo in a Longan Nano board145MIT OR Apache-2.0
valinor-identityCryptographic identity and key management for MudWorld platform145MIT OR Apache-2.0
webgates-codecsFramework-agnostic JWT codecs and validation helpers for webgates.145MIT
secrets-rsSafely surface secrets to Rust applications — masked by default, explicit opt-in for real values145MIT
kamu-snap-cryptoFramework-agnostic cryptography for Bank Indonesia SNAP BI integrations (HMAC, RSA, recipe helpers, webhook verifier)144MIT OR Apache-2.0
claude_profileClaude Code account credential management and token status144MIT
rustauth-deadpool-postgresdeadpool-postgres database adapter for RustAuth.143MIT
obsigilA shared-secret JWT alternative: a mandate-token format splitting a public, advisory manifest from a secret-sealed, authenticated…143MIT OR Apache-2.0
pakery-cpaceCPace balanced PAKE protocol (draft-irtf-cfrg-cpace)143MIT OR Apache-2.0
wardnCredential isolation proxy — agents never see real API keys142MIT
oxigdal-gatewayEnterprise API gateway with rate limiting, authentication, GraphQL, and WebSocket support for OxiGDAL142Apache-2.0
fido_mds3_attestation_caLibrary for extracting FIDO Metadata Service (MDS3) attestation trust anchors for WebAuthn authenticator verification, compatible…142MIT OR Apache-2.0
pakery-spake2plusSPAKE2+ augmented PAKE protocol (RFC 9383)142MIT OR Apache-2.0
vigil-sdkStable public SDK facade for embedding Vigil's local AI safety runtime — typed decisions/audit + firewall execution + redaction…141Apache-2.0