Self-hosted identity infrastructure for applications, APIs, wallets, and enterprise systems.
Product · Documentation · Developer Portal & API Sandbox · Releases · OpenAPI
OpenProof provides one canonical identity layer while keeping authentication, proof, trust, sessions, and authorization as separate security boundaries. It is designed to run inside your own infrastructure and keep identity data under your control.
Current release: 1.1.0-rc4 · C++26 · PostgreSQL · self-hosted
- Account enrollment, verified email/phone ownership, profiles, sessions, MFA, recovery codes and passkeys.
- OAuth 2.0 / OpenID Connect with Authorization Code + PKCE, Device Flow, client credentials, token exchange, PAR, JAR/JARM, revocation and introspection.
- Federated sign-in with Google, GitHub, Microsoft, Apple, LinkedIn, Telegram and X.
- Ethereum wallet authentication with SIWE and Farcaster authentication with SIWF.
- SAML, LDAPS and SCIM for enterprise identity and provisioning.
- Organization membership, RBAC, application/client registration and an owner-protected administration surface.
- Evidence and trust primitives that remain separate from authorization policy.
- C++, JavaScript, Swift and Kotlin SDK foundations.
OpenProof sits between the ways a person can prove who they are and the applications that need to trust that identity.
Different sign-in methods converge into one canonical OpenProof identity. Applications receive OAuth/OIDC tokens; they do not need to own provider credentials, wallet proofs, passwords, or the OpenProof browser session.
flowchart LR
subgraph Methods["Ways to authenticate"]
direction TB
Password["Email / Password"]
Social["Google · GitHub · Apple · Microsoft · LinkedIn · Telegram · X"]
Passkey["Passkeys / MFA"]
Wallet["Ethereum / Farcaster"]
Enterprise["SAML / LDAP / SCIM"]
end
OpenProof["OpenProof<br/><b>one canonical identity</b>"]
App["Your application"]
API["Your protected API"]
Password --> OpenProof
Social --> OpenProof
Passkey --> OpenProof
Wallet --> OpenProof
Enterprise --> OpenProof
OpenProof -->|"OAuth / OIDC tokens"| App
App -->|"access token"| API
API -.->|"validate / introspect when needed"| OpenProof
The important part is the convergence: the same person can sign in with several methods without becoming several unrelated product accounts.
For example, a user can first sign in with GitHub and later attach an Ethereum wallet. Both proofs can resolve to the same OpenProof subject, so the application still sees one user.
A normal application integration can be understood as six steps:
flowchart TB
S1["1 · User chooses Sign in"]
S2["2 · Application redirects to OpenProof"]
S3["3 · OpenProof verifies the chosen sign-in method"]
S4["4 · The proof resolves to one canonical identity"]
S5["5 · OpenProof returns OAuth/OIDC tokens to the application"]
S6["6 · The application calls its API with the access token"]
S1 --> S2 --> S3 --> S4 --> S5 --> S6
Behind those six steps, OpenProof owns the security-sensitive work: provider callbacks, authentication ceremonies, identity linking, session lifecycle, token issuance, assurance, policy, and durable identity state.
For the internal C++ module graph and trust boundaries, see docs/ARCHITECTURE.md.
On a supported Ubuntu or Debian host:
curl -fsSL https://genyleap.com/install/openproof | sudo shThe production installer downloads a matching prebuilt runtime bundle and verifies its published SHA-256 checksum. It never compiles OpenProof or installs compiler toolchains on the target host; missing release artifacts fail explicitly. The wizard then guides you through PostgreSQL, secrets, the initial owner, email delivery, authentication providers, Nginx and TLS.
See Installation for package-only, version-pinned and non-interactive deployments.
OpenProof currently targets GCC 16 with C++26 modules.
Required components:
- GCC 16
- CMake 3.30+
- Ninja
- OpenSSL 3+
- Boost 1.88+
- PostgreSQL client libraries 15+
- tomlplusplus
cmake --preset gcc-release
cmake --build --preset gcc-release
ctest --preset gcc-releaseFor compiler/module details, see C++26 toolchain notes.
./scripts/quickstart-local-demo.shThe demo creates an isolated temporary PostgreSQL instance, starts OpenProof behind a local TLS edge, exercises the identity/OAuth flow, and removes the temporary environment when it exits.
For the interactive Qt/QML client and local Developer Portal:
./scripts/run-qml-demo.shYou can also explore the public browser-isolated sandbox without installing anything:
https://docs.genyleap.com/openproof/api/
A single generic configuration example is kept in examples/openproof.toml.
Before starting a real deployment, use the complete configuration reference and the reviewed templates in deploy/.
./cmake-build-gcc-release/apps/opp/opp check-config --config openproof.toml
./cmake-build-gcc-release/apps/opp/opp server --config openproof.tomlOpenProof should normally listen on loopback behind a trusted TLS reverse proxy.
A minimal C++ relying-party integration is available in examples/reference-client.
| SDK | Location |
|---|---|
| C++ | sdk/cpp |
| JavaScript | sdk/javascript |
| Swift | sdk/swift |
| Kotlin | sdk/kotlin |
The protocol remains HTTP + OAuth/OIDC, so using an OpenProof SDK is optional.
| Topic | Repository reference |
|---|---|
| Deployment & developer handbook | docs/HANDBOOK.md |
| AI / LLM / MCP integration | docs/AI_AND_MCP.md |
| Installation | docs/INSTALLATION.md |
| Architecture | docs/ARCHITECTURE.md |
| Configuration | docs/CONFIGURATION.md |
| API integration | docs/API_GUIDE.md |
| Provider setup | docs/PROVIDER_SETUP.md |
| Operations | docs/OPERATIONS.md |
| Delivery webhook | docs/DELIVERY_WEBHOOK.md |
| WalletConnect / EVM wallets | docs/WALLETCONNECT.md |
| Threat model | docs/THREAT_MODEL.md |
| Security invariants | docs/SECURITY_INVARIANTS.md |
| Release process | docs/RELEASING.md |
| OpenAPI 3.1 | docs/openapi.yaml |
The hosted documentation is the best entry point for application developers:
- Docs: https://docs.genyleap.com/openproof/
- Interactive API: https://docs.genyleap.com/openproof/api/
- Product: https://genyleap.com/products/openproof
apps/ OpenProof server binary
src/ identity, auth, OAuth/OIDC, policy, storage and protocol modules
sdk/ client SDK foundations
examples/ one deployment config, reference client and QML demo
migrations/ PostgreSQL migrations
tests/ unit, integration and security tests
fuzz/ boundary fuzzing harness
deploy/ generic Linux/systemd/Nginx templates
docs/ implementation and operator documentation
scripts/ local demos, verification and qualification tooling
OpenProof handles credentials and identity state. Review SECURITY.md before reporting a vulnerability and docs/THREAT_MODEL.md before deploying the service.
Do not commit provider credentials, signing keys, database URLs, bearer tokens, or production configuration secrets.
Small, focused changes are preferred. Build and test the affected surface before opening a pull request. See CONTRIBUTING.md.