Authentication plugins for Payload CMS 27

Authentication plugins for Payload CMS: OAuth, SSO, MFA, RBAC, passkeys and better-auth integrations. Compare and install community solutions.

Better Auth

Better Auth adapter and plugins for Payload CMS.

Passkey

Adds WebAuthn passkey login and management to Payload CMS accounts via Better Auth.

TOTP

Add an extra layer of security with Time-based One-time Passwords (TOTP).

Subscribers

Manage subscribers and channels with magic link authentication.

Keycloak SSO

Adds Keycloak single sign-on to Payload CMS 3 via an OIDC auth strategy with PKCE, silent token refresh, and permission-based access control.

Simple Social Login

Adds Google and Microsoft (Entra ID) OAuth social login buttons to the Payload admin panel and authenticated collections.

payload-auth

Integrates Better Auth for enhanced authentication in Payload CMS.

Auth Pwless

Passwordless authentication for Payload CMS with passkeys, magic links, OAuth, and refresh-token sessions.

RBAC

Add role-based access control features to Payload CMS.

Masquerade

Masquerade user for Payload CMS.

oAuth plugin

Integrates OAuth authentication into Payload CMS using passport-oauth2.

auth plugin

Adds authentication capabilities to Payload CMS.

OAuth2

OAuth2 plugin for Payload CMS, enabling integration with various providers.

RBAC permissions UI

Adds a permissions management UI for roles in Payload CMS.

Auth Cookie

Authenticate users with SSO and cookies in Payload CMS.

Auth WorkOS

Integrates WorkOS for OAuth-based user authentication in Payload CMS.

Zitadel integration

Integrates Zitadel authentication into Payload CMS applications.

Gatekeeper

Adds role-based access control to Payload CMS v3 with wildcard permissions, auto-generated permissions per collection, and a managed Roles collection.

OIDC plugin

Integrate OpenID Connect authentication into Payload CMS.

reCAPTCHA v3

This plugin protects Payload collection operations using Google reCAPTCHA v3.

Authentication plugins add user identity to Payload CMS — from OAuth and SSO sign-in to multi-factor auth, passkeys and fine-grained RBAC/ABAC access control. They extend Payload's built-in auth rather than replacing it, so you keep the admin login while adding providers and policies.

What these plugins cover

  • OAuth / SSO providers and social login
  • MFA, TOTP and passkeys (WebAuthn)
  • Passwordless and magic-link sign-in
  • Role- and attribute-based access (RBAC/ABAC)
  • Session, JWT and API-key management
  • better-auth and Auth.js integrations

Choosing an auth approach

For a public app, start with social OAuth plus optional MFA; for internal tools, layer RBAC/ABAC on top of SSO. Pair access rules with admin tooling for audit logs.

See also admin tooling, custom fields and third-party integrations.

Frequently asked questions

Which auth methods do Payload plugins support?

Community plugins cover OAuth and SSO providers, multi-factor auth (TOTP, passkeys) and role- or attribute-based access control, plus better-auth and Auth.js adapters.

How do these integrate with Payload's built-in auth?

Most plugins extend the existing auth collection and access-control hooks — you keep Payload's admin login and add providers, strategies or policies on top, rather than replacing the auth system.

Are these authentication plugins free?

Every plugin listed on Payload Market is open-source and free to install; pricing only applies to optional hosted services some authors offer.