Self-host Logto
updated Sep 2026deployed by usprices checked · Jul 2026Install verified on Ubuntu 26.04 · Sep 2026 · how we test
We earn commissions when you shop through the links below. Full disclosure →
An open-source authentication and authorization service built on OIDC and OAuth 2.1, with multi-tenancy, SSO, RBAC and prebuilt sign-in flows for SaaS and AI apps. It runs as a Node.js service on PostgreSQL, with a separate admin console.
Auth0 / yr$420
Self-hosted / yr~$283
You keep$137/yr
Pocket the difference — spin it up on a cheap VPS in minutes.Start free on Kamatera → (opens in new tab)
Key facts
CategorySSO & Identity
LicenseMPL-2.0
StackTypeScript, Node.js, PostgreSQL
Min RAM8192 MB
Official imageyes
Measured idle RAM259 MB
Difficulty
Websitelogto.io (opens in new tab)
What you need
- Any VPS with at least 8192 MB of RAM
- A domain you control — most self-hosted setups need HTTPS in front of them
- Under an hour if you've used Docker before
Where to host itaffiliate disclosure
Hetzner Cloudrun it on
From $23.59/mo · 2 vCPU / 4 GB / 80 GB · EU + USKamaterafree trial
From $4/mo · 1 vCPU / 1 GB / 20 GB · US + EU + AsiaDigitalOceanalso works on
From $6/mo · 1 vCPU / 1 GB / 25 GB · US + EU + AsiaPaid link — we earn a commission if you shop through it.
Install
Run these commands on your server:
# Logto + PostgreSQL — API on :3001, admin console on http://SERVER_IP:3002
echo "PG_PASS=$(openssl rand -hex 16)" > .env
cat > docker-compose.yml <<'EOF'
services:
app:
image: svhd/logto:1.43.0
depends_on: { postgres: { condition: service_healthy } }
entrypoint: ["sh", "-c", "npm run cli db seed -- --swe && npm start"]
restart: unless-stopped
ports: ["3001:3001", "3002:3002"]
environment:
TRUST_PROXY_HEADER: 1
DB_URL: postgres://postgres:${PG_PASS}@postgres:5432/logto
ENDPOINT: http://SERVER_IP:3001
ADMIN_ENDPOINT: http://SERVER_IP:3002
postgres:
image: postgres:17-alpine
user: postgres
restart: unless-stopped
environment: { POSTGRES_USER: postgres, POSTGRES_PASSWORD: "${PG_PASS}" }
volumes: ["logto-db:/var/lib/postgresql/data"]
healthcheck: { test: ["CMD-SHELL", "pg_isready"], interval: 5s, timeout: 5s, retries: 10 }
volumes: { logto-db: {} }
EOF
docker compose up -d # then create the admin account in the console on :3002An alternative to
More in SSO & Identity
SSO & Identity
Authelia
Go
moderateRead guide →
SSO & Identity
authentik
PythonGoTypeScript
moderateRead guide →
SSO & Identity
Casdoor
GoReact
easyRead guide →
SSO & Identity
Keycloak
JavaQuarkus
hardRead guide →