Authentication plugins for Payload CMS 27
Authentication plugins for Payload CMS: OAuth, SSO, MFA, RBAC, passkeys and better-auth integrations. Compare and install community solutions.
Better Auth
Better Auth adapter and plugins for Payload CMS.
Passkey
Adds WebAuthn passkey login and management to Payload CMS accounts via Better Auth.
TOTP
Add an extra layer of security with Time-based One-time Passwords (TOTP).
Subscribers
Manage subscribers and channels with magic link authentication.
Keycloak SSO
Adds Keycloak single sign-on to Payload CMS 3 via an OIDC auth strategy with PKCE, silent token refresh, and permission-based access control.
Simple Social Login
Adds Google and Microsoft (Entra ID) OAuth social login buttons to the Payload admin panel and authenticated collections.
payload-auth
Integrates Better Auth for enhanced authentication in Payload CMS.
Auth Pwless
Passwordless authentication for Payload CMS with passkeys, magic links, OAuth, and refresh-token sessions.
RBAC
Add role-based access control features to Payload CMS.
Masquerade
Masquerade user for Payload CMS.
oAuth plugin
Integrates OAuth authentication into Payload CMS using passport-oauth2.
auth plugin
Adds authentication capabilities to Payload CMS.
OAuth2
OAuth2 plugin for Payload CMS, enabling integration with various providers.
RBAC permissions UI
Adds a permissions management UI for roles in Payload CMS.
Auth Cookie
Authenticate users with SSO and cookies in Payload CMS.
Auth WorkOS
Integrates WorkOS for OAuth-based user authentication in Payload CMS.
Zitadel integration
Integrates Zitadel authentication into Payload CMS applications.
Gatekeeper
Adds role-based access control to Payload CMS v3 with wildcard permissions, auto-generated permissions per collection, and a managed Roles collection.
OIDC plugin
Integrate OpenID Connect authentication into Payload CMS.
reCAPTCHA v3
This plugin protects Payload collection operations using Google reCAPTCHA v3.
Authentication plugins add user identity to Payload CMS — from OAuth and SSO sign-in to multi-factor auth, passkeys and fine-grained RBAC/ABAC access control. They extend Payload's built-in auth rather than replacing it, so you keep the admin login while adding providers and policies.
What these plugins cover
- OAuth / SSO providers and social login
- MFA, TOTP and passkeys (WebAuthn)
- Passwordless and magic-link sign-in
- Role- and attribute-based access (RBAC/ABAC)
- Session, JWT and API-key management
- better-auth and Auth.js integrations
Choosing an auth approach
For a public app, start with social OAuth plus optional MFA; for internal tools, layer RBAC/ABAC on top of SSO. Pair access rules with admin tooling for audit logs.
See also admin tooling, custom fields and third-party integrations.
Frequently asked questions
Which auth methods do Payload plugins support?
Community plugins cover OAuth and SSO providers, multi-factor auth (TOTP, passkeys) and role- or attribute-based access control, plus better-auth and Auth.js adapters.
How do these integrate with Payload's built-in auth?
Most plugins extend the existing auth collection and access-control hooks — you keep Payload's admin login and add providers, strategies or policies on top, rather than replacing the auth system.
Are these authentication plugins free?
Every plugin listed on Payload Market is open-source and free to install; pricing only applies to optional hosted services some authors offer.