supertokens-core: Build Authentication Into Your Applications

Summary
SuperTokens Core is a self-hostable authentication service that handles core login, user, and session operations for backend SDKs. It suits teams that want managed auth features while keeping user data in their own database and deployment.
At a glance
- Language
- Java
- License
- NOASSERTION
- Stars
- 15.3k
- Forks
- 841
- Added to OSRepos
- February 10, 2026
- Last analyzed
- October 4, 2026
Topics
Click on any tag to explore related repositories
Use at your own risk
OSRepos shares public repositories for knowledge and discovery only. Any installation, execution, configuration, or use of code from these repositories is the user's own responsibility. Always review the repository, source code, dependencies, licenses, and security implications before running or installing anything. OSRepos is not responsible for issues, damages, or losses resulting from third-party repositories.
Overview
SuperTokens Core is the Java HTTP service behind SuperTokens, an authentication system that applications connect to through frontend and backend SDKs. It handles core authentication logic and database operations, while SDKs provide application-facing APIs and manage client sessions.
It is aimed at teams that want to add authentication without building the underlying flows themselves, and prefer the option to deploy the service with their own database. The repository is the core service, not a standalone frontend login UI or a drop-in SDK for every application language.
Key Features
- Supports passwordless, social, email-password, and phone-password login flows.
- Provides session management, including session refresh operations through backend SDKs.
- Includes multi-factor authentication and multi-tenancy or organization support.
- Offers user roles and microservice authentication capabilities.
- Separates frontend SDKs, backend SDKs, and the core service so teams can integrate the parts they need.
- Supports on-premises deployment with user data stored in the operator's database.
Use Cases
- Product teams adding sign-up, sign-in, and session handling without implementing authentication logic from scratch.
- Organizations that need to keep authentication data within their own deployment and database.
- Applications that want passwordless, social, or password-based login options through supported SDKs.
- Teams seeking session management integrations alongside another login provider, as described by the project.
- Services that need authentication features such as roles, multi-factor authentication, or tenant support.
Project Facts
- Language: Java
- License: NOASSERTION
- Stars: 15.3k
- Forks: 841
- Topics: auth0, authentication, aws-cognito, email-password, email-password-login, firebase-auth, hacktoberfest, java, keycloak, login, oauth, password, passwordless, passwordless-authentication, passwordless-login, session-management, signin, social-login, supertokens
- Archived: false
Getting Started
The README points to the SuperTokens guides for setup and the build-from-source wiki for compiling the core. Start with the repository README to choose an integration path and deployment method.
Considerations
- The core service is one part of a system: application integration also involves frontend and backend SDKs.
- The README notes that session verification commonly happens in backend SDKs rather than contacting the Java core, so SDK compatibility and deployment design matter.
- Building from source requires following separate wiki instructions; the provided input does not specify a one-command installation procedure.
- The repository reports its license as NOASSERTION. Its README describes Apache 2.0 licensing for content outside specified exceptions, and separate licensing for the
ee/directory if present. Review the repository license files for the terms that apply to your use.
Source repository
Open the original repository on GitHub.
7 counted GitHub visits
Related repositories
Similar repositories that may be relevant next.

awesome-java: Find Java Frameworks, Libraries, Tools, and Resources
July 12, 2026
A community-curated directory of Java frameworks, libraries, tools, and learning resources. Browse 839 projects across 81 categories to compare options for common development tasks.

opendataloader-pdf: Extract Structured Data and Accessibility Tags from PDFs
May 30, 2026
OpenDataLoader PDF parses digital, scanned, and tagged PDFs into structured formats for AI and document workflows. It also automates conversion of untagged PDFs into Tagged PDFs, with optional hybrid processing for complex documents.

CompreFace: Run Self-Hosted Face Recognition APIs
April 12, 2026
CompreFace is a Docker-based face analysis service with REST APIs for recognition, verification, detection, and related tasks. It suits teams that need to integrate face processing into applications while keeping deployment on their own infrastructure.

openaev: Plan and Run Cyber Adversary Simulations
February 22, 2026
OpenAEV helps security teams plan, schedule, and run adversary simulation campaigns and exercises. Use it to coordinate teams, monitor activity, and review security gaps in relation to current threats.