Skip to content

Repository files navigation

OpenProof

Self-hosted identity infrastructure for applications, APIs, wallets, and enterprise systems.

Product · Documentation · Developer Portal & API Sandbox · Releases · OpenAPI

OpenProof provides one canonical identity layer while keeping authentication, proof, trust, sessions, and authorization as separate security boundaries. It is designed to run inside your own infrastructure and keep identity data under your control.

Current release: 1.1.0-rc4 · C++26 · PostgreSQL · self-hosted

What OpenProof includes

  • Account enrollment, verified email/phone ownership, profiles, sessions, MFA, recovery codes and passkeys.
  • OAuth 2.0 / OpenID Connect with Authorization Code + PKCE, Device Flow, client credentials, token exchange, PAR, JAR/JARM, revocation and introspection.
  • Federated sign-in with Google, GitHub, Microsoft, Apple, LinkedIn, Telegram and X.
  • Ethereum wallet authentication with SIWE and Farcaster authentication with SIWF.
  • SAML, LDAPS and SCIM for enterprise identity and provisioning.
  • Organization membership, RBAC, application/client registration and an owner-protected administration surface.
  • Evidence and trust primitives that remain separate from authorization policy.
  • C++, JavaScript, Swift and Kotlin SDK foundations.

What OpenProof does

OpenProof sits between the ways a person can prove who they are and the applications that need to trust that identity.

Different sign-in methods converge into one canonical OpenProof identity. Applications receive OAuth/OIDC tokens; they do not need to own provider credentials, wallet proofs, passwords, or the OpenProof browser session.

flowchart LR
    subgraph Methods["Ways to authenticate"]
        direction TB
        Password["Email / Password"]
        Social["Google · GitHub · Apple · Microsoft · LinkedIn · Telegram · X"]
        Passkey["Passkeys / MFA"]
        Wallet["Ethereum / Farcaster"]
        Enterprise["SAML / LDAP / SCIM"]
    end

    OpenProof["OpenProof<br/><b>one canonical identity</b>"]
    App["Your application"]
    API["Your protected API"]

    Password --> OpenProof
    Social --> OpenProof
    Passkey --> OpenProof
    Wallet --> OpenProof
    Enterprise --> OpenProof

    OpenProof -->|"OAuth / OIDC tokens"| App
    App -->|"access token"| API
    API -.->|"validate / introspect when needed"| OpenProof
Loading

The important part is the convergence: the same person can sign in with several methods without becoming several unrelated product accounts.

For example, a user can first sign in with GitHub and later attach an Ethereum wallet. Both proofs can resolve to the same OpenProof subject, so the application still sees one user.

Sign-in flow

A normal application integration can be understood as six steps:

flowchart TB
    S1["1 · User chooses Sign in"]
    S2["2 · Application redirects to OpenProof"]
    S3["3 · OpenProof verifies the chosen sign-in method"]
    S4["4 · The proof resolves to one canonical identity"]
    S5["5 · OpenProof returns OAuth/OIDC tokens to the application"]
    S6["6 · The application calls its API with the access token"]

    S1 --> S2 --> S3 --> S4 --> S5 --> S6
Loading

Behind those six steps, OpenProof owns the security-sensitive work: provider callbacks, authentication ceremonies, identity linking, session lifecycle, token issuance, assurance, policy, and durable identity state.

For the internal C++ module graph and trust boundaries, see docs/ARCHITECTURE.md.

Install

On a supported Ubuntu or Debian host:

curl -fsSL https://genyleap.com/install/openproof | sudo sh

The production installer downloads a matching prebuilt runtime bundle and verifies its published SHA-256 checksum. It never compiles OpenProof or installs compiler toolchains on the target host; missing release artifacts fail explicitly. The wizard then guides you through PostgreSQL, secrets, the initial owner, email delivery, authentication providers, Nginx and TLS.

See Installation for package-only, version-pinned and non-interactive deployments.

Build from source

OpenProof currently targets GCC 16 with C++26 modules.

Required components:

  • GCC 16
  • CMake 3.30+
  • Ninja
  • OpenSSL 3+
  • Boost 1.88+
  • PostgreSQL client libraries 15+
  • tomlplusplus
cmake --preset gcc-release
cmake --build --preset gcc-release
ctest --preset gcc-release

For compiler/module details, see C++26 toolchain notes.

Run the local end-to-end demo

./scripts/quickstart-local-demo.sh

The demo creates an isolated temporary PostgreSQL instance, starts OpenProof behind a local TLS edge, exercises the identity/OAuth flow, and removes the temporary environment when it exits.

For the interactive Qt/QML client and local Developer Portal:

./scripts/run-qml-demo.sh

You can also explore the public browser-isolated sandbox without installing anything:

https://docs.genyleap.com/openproof/api/

Configure a deployment

A single generic configuration example is kept in examples/openproof.toml.

Before starting a real deployment, use the complete configuration reference and the reviewed templates in deploy/.

./cmake-build-gcc-release/apps/opp/opp check-config --config openproof.toml
./cmake-build-gcc-release/apps/opp/opp server --config openproof.toml

OpenProof should normally listen on loopback behind a trusted TLS reverse proxy.

SDKs

A minimal C++ relying-party integration is available in examples/reference-client.

SDK Location
C++ sdk/cpp
JavaScript sdk/javascript
Swift sdk/swift
Kotlin sdk/kotlin

The protocol remains HTTP + OAuth/OIDC, so using an OpenProof SDK is optional.

Documentation

Topic Repository reference
Deployment & developer handbook docs/HANDBOOK.md
AI / LLM / MCP integration docs/AI_AND_MCP.md
Installation docs/INSTALLATION.md
Architecture docs/ARCHITECTURE.md
Configuration docs/CONFIGURATION.md
API integration docs/API_GUIDE.md
Provider setup docs/PROVIDER_SETUP.md
Operations docs/OPERATIONS.md
Delivery webhook docs/DELIVERY_WEBHOOK.md
WalletConnect / EVM wallets docs/WALLETCONNECT.md
Threat model docs/THREAT_MODEL.md
Security invariants docs/SECURITY_INVARIANTS.md
Release process docs/RELEASING.md
OpenAPI 3.1 docs/openapi.yaml

The hosted documentation is the best entry point for application developers:

Repository layout

apps/         OpenProof server binary
src/          identity, auth, OAuth/OIDC, policy, storage and protocol modules
sdk/          client SDK foundations
examples/     one deployment config, reference client and QML demo
migrations/   PostgreSQL migrations
tests/        unit, integration and security tests
fuzz/         boundary fuzzing harness
deploy/       generic Linux/systemd/Nginx templates
docs/         implementation and operator documentation
scripts/      local demos, verification and qualification tooling

Security

OpenProof handles credentials and identity state. Review SECURITY.md before reporting a vulnerability and docs/THREAT_MODEL.md before deploying the service.

Do not commit provider credentials, signing keys, database URLs, bearer tokens, or production configuration secrets.

Contributing

Small, focused changes are preferred. Build and test the affected surface before opening a pull request. See CONTRIBUTING.md.

About

An open protocol for portable identity, authentication, authorization, trust, and secure access.

Topics

Resources

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages