{"data":{"slug":"dex-idp","name":"Dex","tagline":"Apache-2.0 federated OIDC IdP that owns no user state","category":"nextjs","categoryName":"Next.js","url":"https://dexidp.io","github":"https://github.com/dexidp/dex","pricing":"open-source","hook":"Dex is the OIDC adapter in front of GitHub, LDAP, or SAML — it does not keep your users.","whatsGood":"Apache-2.0. Federated OIDC / OAuth 2.0 provider with pluggable connectors (GitHub, Google, LDAP, SAML, OIDC). Apps speak OIDC to Dex once. Go binary, Helm chart, CNCF sandbox.","theCatch":"Protocol adapter, not a user directory and not a proxy gate. Distinct from Authelia (reverse-proxy SSO) and from authentik/ZITADEL/Keycloak (they store users). Dex owns no user state. You still need an upstream IdP.","verdict":"Apache-2.0 OIDC facade. Connectors in, standards out, no user table.","addedAt":"2026-09-03","featured":false,"domain":"Auth","subSpecialty":"Auth","capabilities":["oidc","federation"],"surfaces":["Self-host"],"ecosystem":["Go"],"licenseModel":"Apache-2.0","githubStars":11082},"related":[{"slug":"vercel","name":"Vercel","tagline":"The platform that made Next.js deployment trivial"},{"slug":"prisma","name":"Prisma","tagline":"Type-safe database access with killer DX"},{"slug":"drizzle","name":"Drizzle ORM","tagline":"TypeScript ORM that feels like SQL"},{"slug":"trpc","name":"tRPC","tagline":"End-to-end typesafe APIs without codegen"},{"slug":"clerk","name":"Clerk","tagline":"Auth that actually ships with your UI"}],"links":{"self":"/api/gems/dex-idp","html":"/gems/dex-idp","markdown":"/gems/dex-idp.md","category":"/api/gems?category=nextjs","categoryPage":"/stacks/nextjs"}}