License & Deployment Mix: 19 tools – 6 OSS, 9 SaaS. (OSS and SaaS counts can overlap when an open-source tool also offers a vendor-hosted edition.)
Overview
Multi-Factor Authentication (MFA) adds one or more verification steps beyond passwords to prove a user’s identity. MFA combines factors from different categories so that compromising one factor (e.g., a stolen password) is not enough to gain access.
The three factor categories are:
- Something you know – password, PIN, security question
- Something you have – hardware token, phone, smart card
- Something you are – fingerprint, face scan, iris scan
MFA platforms provide:
- TOTP (Time-based One-Time Password) – a 6-8 digit code generated every 30 seconds by an authenticator app (RFC 6238); the most widely supported second factor
- WebAuthn / FIDO2 – passwordless or second- factor authentication using hardware security keys (YubiKey, Titan), platform authenticators (Touch ID, Windows Hello), or passkeys; phishing- resistant by design
- Push notifications – approve or deny a login request on a registered mobile device; user taps “approve” instead of typing a code
- SMS / voice – one-time codes delivered via text message or phone call; widely supported but vulnerable to SIM swapping and SS7 attacks; not recommended as the sole second factor
- Hardware tokens – dedicated devices that generate one-time codes (RSA SecurID, YubiKey OTP) or provide cryptographic attestation (FIDO2); most secure but highest per-user cost
- Email codes – one-time codes sent to a registered email address; weaker than other methods (email accounts are often the target)
- Smart cards / PIV – X.509 certificate-based authentication via smart cards; common in government and military (CAC/PIV cards)
- Biometrics – fingerprint, face, iris, or voice recognition; typically used as a platform authenticator (Touch ID, Windows Hello) rather than a standalone MFA factor
- Risk-based / adaptive MFA – dynamically adjust MFA requirements based on login context (location, device, behaviour, risk score); skip MFA for trusted contexts, require stronger factors for risky ones
The information on these pages was researched by a combination of human review and large language models. To suggest an addition or correction, please contact us. Prepared by Rhodium Systems Inc., author of the ResorsIT platform — a unified IT operations management platform for IT teams and MSPs that integrates a curated suite of open-source, commercial, and SaaS applications into a single system with shared identity, single sign-on, access control, and a common audit trail. Use this catalogue only as a starting point for your own research, and review any tool carefully against your own requirements before relying on it. Catalogue data version 2026.197.
Comparison
An IdP such as Authentik provides built-in MFA (TOTP + WebAuthn); dedicated MFA platforms integrate via RADIUS or federation.
Factor Support Comparison
| Tool | TOTP | WebAuthn | Push | SMS | HW Token | Smart Card |
|---|---|---|---|---|---|---|
| privacyIDEA | Yes | Yes | No | Yes | Yes (HOTP) | Yes (PIV) |
| LinOTP | Yes | No | No | Yes | Yes (HOTP) | No |
| multiOTP | Yes | No | No | Yes | Yes (HOTP) | No |
| Cisco Duo | Yes | Yes | Yes | Yes | Yes | No |
| WatchGuard AuthPoint | Yes | No | Yes | No | Yes | No |
| Silverfort | Yes | Yes | Yes | No | Yes | Yes |
| Twilio Verify | Yes | No | Yes | Yes | No | No |
| RSA SecurID | Yes | Yes | Yes | Yes | Yes (HW) | Yes |
| Thales SafeNet | Yes | Yes | Yes | Yes | Yes (HW) | Yes (PKI) |
| Yubico (YubiKey) | Yes | Yes | No | No | Yes (native) | Yes (PIV) |
| HYPR | No | Yes | Yes | No | Yes | No |
| SecureAuth | Yes | Yes | Yes | Yes | Yes | Yes |
| PingID | Yes | Yes | Yes | Yes | Yes | No |
| Okta Verify | Yes | Yes | Yes | Yes | Yes | No |
Protocol / Integration Comparison
| Tool | RADIUS | LDAP Proxy | SAML | OIDC | REST API | PAM Module |
|---|---|---|---|---|---|---|
| privacyIDEA | Yes | Yes | No | No | Yes | Yes |
| LinOTP | Yes | No | No | No | Yes | Yes |
| multiOTP | Yes | No | No | No | Yes | Yes |
| Cisco Duo | Yes | Yes | Yes | Yes | Yes | Yes |
| WatchGuard AuthPoint | Yes | Yes | Yes | No | Yes | No |
| Silverfort | Yes | Yes | Yes | Yes | Yes | No |
| RSA SecurID | Yes | Yes | Yes | Yes | Yes | Yes |
| Thales SafeNet | Yes | Yes | Yes | Yes | Yes | Yes |
| HYPR | No | No | Yes | Yes | Yes | No |
| SecureAuth | Yes | Yes | Yes | Yes | Yes | No |
| Twilio Verify | No | No | No | No | Yes | No |
| FreeRADIUS | Yes | No | No | No | No | No |
Deployment Model
| Tool | Self-Hosted | SaaS | License |
|---|---|---|---|
| privacyIDEA | Yes | No | AGPL-3.0 |
| LinOTP | Yes | No | AGPL-3.0 |
| multiOTP | Yes | No | LGPL-3.0 |
| FreeRADIUS | Yes | No | GPL-2.0 |
| Nitrokey | N/A (hardware) | N/A | GPL-3.0 (firmware) |
| SoloKeys | N/A (hardware) | N/A | Apache 2.0 + MIT |
| Yubico | N/A (hardware) | YubiEnterprise | Proprietary |
| Google Titan | N/A (hardware) | N/A | Proprietary |
| Feitian | N/A (hardware) | N/A | Proprietary |
| RSA SecurID | Yes | Yes | Proprietary |
| Thales SafeNet | Yes | Yes | Proprietary |
| Cisco Duo | No | Yes | Proprietary |
| WatchGuard AuthPoint | No | Yes | Proprietary |
| Silverfort | Yes | Yes | Proprietary |
| Twilio Verify | No | Yes | Proprietary |
| HYPR | No | Yes | Proprietary |
| SecureAuth | Yes | Yes | Proprietary |
| PingID | No | Yes | Proprietary |
| Okta Verify | No | Yes | Proprietary |
OS Login MFA (Windows / Linux)
| Tool | Windows CP | Linux PAM | macOS | RDP | SSH |
|---|---|---|---|---|---|
| privacyIDEA | Yes | Yes | No | Yes | Yes |
| LinOTP | No | Yes | No | No | Yes |
| multiOTP | Yes | Yes | No | Yes | Yes |
| Cisco Duo | Yes | Yes | Yes | Yes | Yes |
| Silverfort | Yes | Yes | Yes | Yes | Yes |
| RSA SecurID | Yes | Yes | Yes | Yes | Yes |
| Thales SafeNet | Yes | Yes | No | Yes | Yes |
| WatchGuard AuthPoint | Yes | Yes | Yes | Yes | No |
Windows CP = Windows Credential Provider Linux PAM = Linux PAM module
Hardware Token Management
| Tool | Inventory | Provisioning | Revocation | Replacement | Reporting |
|---|---|---|---|---|---|
| privacyIDEA | Yes | Yes | Yes | Yes | Yes |
| LinOTP | Yes | Yes | Yes | Yes | Yes |
| Cisco Duo | No | Manual | Yes | Manual | Limited |
| RSA SecurID | Yes | Yes | Yes | Yes | Yes |
| Thales SafeNet | Yes | Yes | Yes | Yes | Yes |
| YubiEnterprise | Yes | Yes (delivery) | Yes | Yes | Yes |
Authentik Integration Paths
For customers with existing MFA platforms, these are the integration options with Authentik:
| Customer MFA | Integration Method |
|---|---|
| Cisco Duo | Authentik Duo stage (native); or RADIUS |
| RSA SecurID | RADIUS proxy via FreeRADIUS |
| MS Authenticator | Entra ID federation to Authentik |
| WatchGuard AuthPoint | SAML federation |
| privacyIDEA | RADIUS or REST API from Authentik |
| YubiKey | Authentik native WebAuthn support |
Tools
19 tools.
Cisco Duo
Cisco Duo (formerly Duo Security) is the most widely deployed cloud MFA service, protecting over 100,000 organizations.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC
Feitian
Feitian Technologies is a Chinese manufacturer of security hardware including FIDO2 keys, OTP tokens, smart cards, and biometric authenticators.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none
FreeRADIUS
FreeRADIUS is the most widely deployed RADIUS server in the world, handling authentication, authorization, and accounting (AAA) for network access.
License: GPL-2.0-only (OSS) · Kind: web · Deploy: native · SSO: none
Google Titan Security Key
Google Titan Security Key is a FIDO2/U2F hardware security key designed by Google and manufactured with a custom secure element chip.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none
HYPR
HYPR is a passwordless MFA platform built on FIDO2/WebAuthn that replaces passwords with device-bound credentials, offering mobile and desktop authenticators, risk- based step-up, and RADIUS integration.
License: Proprietary (proprietary) · Kind: web · Deploy: native, saas · SSO: none
LinOTP
LinOTP (Linux One-Time Password) is an open-source OTP authentication server originally developed by LSE Leading Security Experts (now KeyIdentity).
License: AGPL-3.0-only (OSS) · Kind: web · Deploy: native, docker · SSO: none
multiOTP
multiOTP is a lightweight, standalone OTP server designed for simplicity and ease of deployment. It supports HOTP, TOTP, mOTP, and Yubikey OTP validation with built-in RADIUS server capabilities.
License: LGPL-3.0-or-later (OSS) · Kind: web · Deploy: native · SSO: none
Nitrokey
Nitrokey produces open-source, open-hardware security keys manufactured in Germany. The Nitrokey 3 series supports FIDO2/WebAuthn, FIDO U2F, OpenPGP, PIV, OTP (HOTP/TOTP), and passwords.
License: GPL-3.0-only (OSS) · Kind: web · Deploy: native · SSO: none
Okta Verify
Okta Verify is the MFA component of the Okta Identity Cloud platform, the market-leading IDaaS (Identity-as-a-Service) provider.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none
PingID
PingID is the multi-factor authentication service from Ping Identity, one of the major enterprise identity vendors.
License: Proprietary (proprietary) · Kind: web · Deploy: native, saas · SSO: none
privacyIDEA
privacyIDEA is a comprehensive multi-factor authentication server that manages hardware and software tokens for organizations of any size.
License: AGPL-3.0-only (OSS) · Kind: web · Deploy: native, docker · SSO: none
RSA SecurID
RSA SecurID is one of the oldest and most recognized MFA brands, originally known for its hardware OTP tokens with the distinctive changing number display.
License: Proprietary (proprietary) · Kind: web · Deploy: native, saas · SSO: none
SecureAuth
SecureAuth is an adaptive authentication platform that combines identity management with risk-based multi-factor authentication.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none
Silverfort
Silverfort provides agentless, adaptive multi-factor authentication by intercepting protocols like Kerberos, NTLM, LDAP, RADIUS, SSH, and RDP at the network level without agents or application changes.
License: Proprietary (proprietary) · Kind: web · Deploy: native, appliance · SSO: none
SoloKeys
SoloKeys produces open-source FIDO2/WebAuthn security keys with fully open firmware and hardware designs.
License: Apache-2.0 (OSS) · Kind: web · Deploy: saas · SSO: none
Thales SafeNet
Thales SafeNet (formerly Gemalto SafeNet) is an enterprise MFA platform combining hardware tokens, software tokens, smart cards, and a cloud-based authentication service.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none
Twilio Verify
Twilio Verify is an API-first multi-factor authentication service built on Twilio’s global communications platform. Unlike standalone MFA products, Verify is designed to be embedded into custom applications via API calls.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none
WatchGuard AuthPoint
WatchGuard AuthPoint is a cloud-based MFA service with push, TOTP, and QR-code authentication, RADIUS and SAML IdP support, and multi-tenant management through WatchGuard Cloud.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none
Yubico / YubiKey
Yubico’s YubiKey is a line of hardware security keys supporting FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH TOTP/HOTP, PIV smart card, and OpenPGP, with FIPS-validated models available.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: none