Bumps the prod group with 15 updates in the /apps/docs directory: | Package | From | To | | --- | --- | --- | | [@inkeep/cxkit-react](https://github.com/inkeep/widget/tree/HEAD/packages/react) | `0.5.117` | `0.5.119` | | [@scalar/api-reference](https://github.com/scalar/scalar/tree/HEAD/packages/api-reference) | `1.57.5` | `1.64.0` | | [@shikijs/rehype](https://github.com/shikijs/shiki/tree/HEAD/packages/rehype) | `4.0.2` | `4.4.1` | | [@shikijs/types](https://github.com/shikijs/shiki/tree/HEAD/packages/types) | `4.0.2` | `4.4.1` | | [fumadocs-core](https://github.com/fuma-nama/fumadocs) | `16.8.10` | `16.14.0` | | [fumadocs-mdx](https://github.com/fuma-nama/fumadocs) | `14.3.2` | `15.2.1` | | [fumadocs-openapi](https://github.com/fuma-nama/fumadocs) | `10.8.2` | `11.2.2` | | [fumadocs-ui](https://github.com/fuma-nama/fumadocs) | `16.8.10` | `16.14.0` | | [js-yaml](https://github.com/nodeca/js-yaml) | `4.3.0` | `5.2.3` | | [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `0.577.0` | `1.28.0` | | [mixpanel-browser](https://github.com/mixpanel/mixpanel-js) | `2.78.0` | `2.81.0` | | [next](https://github.com/vercel/next.js) | `16.2.6` | `16.2.12` | | [react](https://github.com/react/react/tree/HEAD/packages/react) | `19.2.6` | `19.2.8` | | [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) | `19.2.6` | `19.2.8` | | [shiki](https://github.com/shikijs/shiki/tree/HEAD/packages/shiki) | `3.23.0` | `4.4.1` | Updates `@inkeep/cxkit-react` from 0.5.117 to 0.5.119 - [Commits](https://github.com/inkeep/widget/commits/HEAD/packages/react) Updates `@scalar/api-reference` from 1.57.5 to 1.64.0 - [Release notes](https://github.com/scalar/scalar/releases) - [Changelog](https://github.com/scalar/scalar/blob/main/packages/api-reference/CHANGELOG.md) - [Commits](https://github.com/scalar/scalar/commits/HEAD/packages/api-reference) Updates `@shikijs/rehype` from 4.0.2 to 4.4.1 - [Release notes](https://github.com/shikijs/shiki/releases) - [Commits](https://github.com/shikijs/shiki/commits/v4.4.1/packages/rehype) Updates `@shikijs/types` from 4.0.2 to 4.4.1 - [Release notes](https://github.com/shikijs/shiki/releases) - [Commits](https://github.com/shikijs/shiki/commits/v4.4.1/packages/types) Updates `fumadocs-core` from 16.8.10 to 16.14.0 - [Release notes](https://github.com/fuma-nama/fumadocs/releases) - [Commits](https://github.com/fuma-nama/fumadocs/compare/fumadocs-core@16.8.10...fumadocs@16.14.0) Updates `fumadocs-mdx` from 14.3.2 to 15.2.1 - [Release notes](https://github.com/fuma-nama/fumadocs/releases) - [Commits](https://github.com/fuma-nama/fumadocs/compare/fumadocs-mdx@14.3.2...fumadocs-mdx@15.2.1) Updates `fumadocs-openapi` from 10.8.2 to 11.2.2 - [Release notes](https://github.com/fuma-nama/fumadocs/releases) - [Commits](https://github.com/fuma-nama/fumadocs/commits/fumadocs-openapi@11.2.2) Updates `fumadocs-ui` from 16.8.10 to 16.14.0 - [Release notes](https://github.com/fuma-nama/fumadocs/releases) - [Commits](https://github.com/fuma-nama/fumadocs/compare/fumadocs-ui@16.8.10...fumadocs@16.14.0) Updates `js-yaml` from 4.3.0 to 5.2.3 - [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md) - [Commits](https://github.com/nodeca/js-yaml/compare/4.3.0...5.2.3) Updates `lucide-react` from 0.577.0 to 1.28.0 - [Release notes](https://github.com/lucide-icons/lucide/releases) - [Commits](https://github.com/lucide-icons/lucide/commits/1.28.0/packages/lucide-react) Updates `mixpanel-browser` from 2.78.0 to 2.81.0 - [Release notes](https://github.com/mixpanel/mixpanel-js/releases) - [Changelog](https://github.com/mixpanel/mixpanel-js/blob/master/CHANGELOG.md) - [Commits](https://github.com/mixpanel/mixpanel-js/compare/v2.78.0...v2.81.0) Updates `next` from 16.2.6 to 16.2.12 - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](https://github.com/vercel/next.js/compare/v16.2.6...v16.2.12) Updates `react` from 19.2.6 to 19.2.8 - [Release notes](https://github.com/react/react/releases) - [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/react/react/commits/v19.2.8/packages/react) Updates `react-dom` from 19.2.6 to 19.2.8 - [Release notes](https://github.com/react/react/releases) - [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/react/react/commits/v19.2.8/packages/react-dom) Updates `shiki` from 3.23.0 to 4.4.1 - [Release notes](https://github.com/shikijs/shiki/releases) - [Commits](https://github.com/shikijs/shiki/commits/v4.4.1/packages/shiki) --- updated-dependencies: - dependency-name: "@inkeep/cxkit-react" dependency-version: 0.5.119 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod - dependency-name: "@scalar/api-reference" dependency-version: 1.58.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod - dependency-name: "@shikijs/rehype" dependency-version: 4.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod - dependency-name: "@shikijs/types" dependency-version: 4.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod - dependency-name: fumadocs-core dependency-version: 16.9.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod - dependency-name: fumadocs-mdx dependency-version: 15.0.10 dependency-type: direct:production update-type: version-update:semver-major dependency-group: prod - dependency-name: fumadocs-openapi dependency-version: 10.10.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod - dependency-name: fumadocs-ui dependency-version: 16.9.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod - dependency-name: js-yaml dependency-version: 4.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod - dependency-name: lucide-react dependency-version: 1.17.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: prod - dependency-name: mixpanel-browser dependency-version: 2.80.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod - dependency-name: next dependency-version: 16.2.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod - dependency-name: react dependency-version: 19.2.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod - dependency-name: react-dom dependency-version: 19.2.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod - dependency-name: shiki dependency-version: 4.2.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: prod ... Signed-off-by: dependabot[bot] <support@github.com>
The Identity Infrastructure for Developers
ZITADEL is an open-source identity and access management platform built for teams that need more than basic auth. Whether you're securing a SaaS product, building a B2B platform, or self-hosting a production IAM stack — ZITADEL gives you everything out of the box: SSO, MFA, Passkeys, OIDC, SAML, SCIM, and a battle-tested multi-tenancy model.
No vendor lock-in. No compromise on control. Just a robust, API-first identity platform you can own.
🏡 Website | 💬 Chat | 📋 Docs | 🧑💻 Blog | 📞 Contact
Why ZITADEL
We built ZITADEL to handle the hardest IAM challenges at scale — starting with multi-tenancy.
| ZITADEL | FusionAuth | Keycloak | Auth0/Okta | |
|---|---|---|---|---|
| Open-source | ✅ | ❌ | ✅ | ❌ |
| Self-hostable | ✅ | ✅ | ✅ | ❌ |
| Infrastructure-level tenants | ✅ Instances (High scale) | ✅ Tenants | 🟡 Realms (Scaling limits) | ❌ (Multi-tenant = multi-account) |
| B2B Organizations | ✅ Native & Unlimited | 🟡 via Entity Management | ✅ (Recent addition) | 🟡 (Plan/Account dependent) |
| Full audit trail | ✅ Comprehensive Event Stream* | 🟡 Audit logs | 🟡 Audit logs | 🟡 Audit logs |
| Passkeys (FIDO2) | ✅ | ✅ | ✅ | ✅ |
| Actions / webhooks | ✅ | ✅ | 🟡 via SPI | ✅ |
| API-first (gRPC + REST) | ✅ | 🟡 REST only | 🟡 REST only | 🟡 REST only |
| SaaS + self-host parity | ✅ | ✅ | ➖ N/A | ➖ N/A |
ZITADEL Cloud and self-hosted ZITADEL run the same codebase.
Key differentiators for architects:
- Relational core, event-driven soul — every mutation is written as an immutable event for a complete, API-accessible audit trail. Unlike systems that log only select activities, ZITADEL provides a comprehensive event stream that can be audited or streamed to external systems via Webhooks.
- Strict multi-tenant hierarchy — Identity System → Organizations → Projects, with isolated data and policy scoping at multiple levels
- API-first design — every resource and action is available via connectRPC, gRPC, and HTTP/JSON APIs
- Zero-downtime updates and horizontal scalability without external session stores
Get Started in 3 Minutes
ZITADEL Self-Hosted
# Docker Compose — up and running in under 3 minutes
curl -LO https://raw.githubusercontent.com/zitadel/zitadel/main/deploy/compose/docker-compose.yml \
&& curl -LO https://raw.githubusercontent.com/zitadel/zitadel/main/deploy/compose/.env.example \
&& cp .env.example .env \
&& docker compose up -d --wait
Full deployment guides:
Need professional support for your self-hosted deployment? Contact us.
ZITADEL Cloud (SaaS)
Start for free at zitadel.com — no credit card required. Available in US · EU · AU · CH. Pay-as-you-go pricing.
Integrate with the V2 API
ZITADEL exposes every capability over a typed API. Here's how to create a user with the V2 REST API:
curl -X POST https://$ZITADEL_DOMAIN/v2/users/human \
-H "Authorization: Bearer $ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"username": "alice@example.com",
"profile": { "givenName": "Alice", "familyName": "Smith" },
"email": { "email": "alice@example.com", "sendCode": {} }
}'
Explore the full API reference — including connectRPC and gRPC transports — or jump straight to quickstart examples.
Features
Authentication
- Single Sign On (SSO) · Username/Password · Passkeys (FIDO2 / WebAuthn)
- MFA: OTP, U2F, OTP Email, OTP SMS
- LDAP · Enterprise IdPs and social logins
- OpenID Connect certified · SAML 2.0 · Device authorization
- Machine-to-machine: JWT Profile, PAT, Client Credentials
- Token exchange and impersonation
- Custom sessions for flows beyond OIDC/SAML
- Hosted Login V2
Multi-Tenancy
- Identity brokering with pre-built IdP templates
- Customizable B2B onboarding with self-service for customers
- Delegated role management to third parties
- Domain discovery
Integration
- gRPC, connectRPC, and REST APIs for every resource
- Actions: webhooks, custom code, token enrichment
- RBAC · SCIM 2.0 Server
- Audit log and SOC/SIEM integration
- SDKs and example apps
Self-Service & Admin
- Self-registration with email/phone verification
- Administration Console for orgs and projects
- Custom branding per organization
Deployment
- PostgreSQL (≥ 14) · Zero-downtime updates · High scalability
Track upcoming features on our roadmap and follow our changelog for recent updates.
Showcase
Login V2
Our new, fully customizable login experience — documentation
Adopters & Ecosystem
Used in production by organizations worldwide. See the full Adopters list — and add yours by submitting a pull request.
- SDKs: All supported languages and frameworks
- Examples: Clone and use our examples
How To Contribute
ZITADEL is built in the open and welcoming to contributions of all kinds.
- 📖 Read the Contribution Guide to get started
- 💬 Join the conversation on Discord
- 🐛 Report bugs or request features via GitHub Issues
Contributors
Made with contrib.rocks.
Security
Security policy: SECURITY.md
Vulnerability Disclosure Policy — how to responsibly report security issues.
Technical Advisories are published for major issues that could impact security or stability in production.
License
AGPL-3.0 — see LICENSING.md for the full licensing policy, including Apache 2.0 and MIT exceptions for specific directories.


