Back to articles
Technology Insight

Deploying Logto Auth Server on Cloud VPS: A Modern Identity Management Solution (OIDC/OAuth2) for Web and Mobile Applications

June 1, 2026

Introduction to Modern Identity Management

In the rapidly evolving digital landscape, securing user identities and managing access control has become a cornerstone of modern software development. Traditionally, building a robust, secure, and compliant authentication system required extensive engineering hours and deep cryptographic expertise. Today, businesses are shifting away from monolithic, homegrown authentication systems toward specialized Customer Identity and Access Management (CIAM) solutions.

Among the emerging open-source leaders in this space is Logto, a powerful, developer-friendly alternative to Auth0 and Keycloak. Built on top of the OpenID Connect (OIDC) and OAuth2 standards, Logto offers a seamless developer experience alongside enterprise-grade security features. This guide provides an in-depth walkthrough of deploying Logto Auth Server on a self-hosted Cloud Virtual Private Server (VPS), offering your business complete data sovereignty, predictable costs, and maximum architectural flexibility.

Why Choose Logto on Cloud VPS?

When architecting a CIAM strategy, organizations generally choose between third-party SaaS providers and self-hosted open-source software. Deploying Logto on a dedicated Cloud VPS strikes an ideal balance, combining the simplicity of a modern SaaS UI with the control of a self-managed infrastructure.

1. Complete Data Sovereignty and Compliance

By hosting Logto on your own Cloud VPS, your organization retains 100% control over user data. This is critical for businesses operating under strict regulatory frameworks such as GDPR, HIPAA, or local data localization laws. User credentials, profile data, and access logs never leave your isolated network perimeter.

2. Predictable and Cost-Effective Scaling

Commercial CIAM SaaS platforms often scale their pricing models based on Monthly Active Users (MAU). As your user base grows, these costs can escalate exponentially. A Cloud VPS deployment incurs a fixed, predictable monthly infrastructure cost, allowing you to scale to hundreds of thousands of users without a corresponding surge in licensing fees.

3. Advanced Customization and Open Standards

Because Logto is natively built on OIDC and OAuth2 protocols, it ensures out-of-the-box compatibility with virtually any frontend framework (React, Vue, Next.js) and mobile platform (iOS, Android, Flutter). Self-hosting allows you to deeply integrate Logto with your internal logging, monitoring, and backup workflows.

System Requirements and Architecture Overview

Before initiating the deployment process, it is essential to provision a Cloud VPS with adequate resources and understand the underlying architecture components.

Recommended Hardware Specifications

  • CPU: 2 Cores (Minimum) / 4 Cores (Recommended for production)
  • RAM: 4 GB (Minimum) / 8 GB (Recommended to accommodate database caching)
  • Storage: 40 GB SSD or NVMe with automated daily backups
  • OS: Ubuntu 22.04 LTS or Ubuntu 24.04 LTS

Architecture Components

A production-ready Logto deployment consists of three primary layers:

  1. Reverse Proxy Layer (Nginx / Caddy): Handles SSL/TLS termination, manages Let's Encrypt certificates, and routes traffic securely to the application core.
  2. Application Layer (Logto Core): The Node.js-based auth server engine that processes authentication requests, issues JWT tokens, and serves the Admin Console.
  3. Database Layer (PostgreSQL): The persistent storage engine where identity schemas, application configurations, and session states are securely stored.

Step-by-Step Deployment Guide via Docker Compose

Using Docker Compose is the highly recommended approach for deploying Logto, as it containerizes the application and its dependencies, ensuring environment consistency and simplified updates.

Step 1: Connect to Your VPS and Install Dependencies

First, access your server via SSH and ensure all system packages are fully updated. Then, install Docker and Docker Compose.

sudo apt update && sudo apt upgrade -y
sudo apt install docker.io docker-compose-plugin -y
sudo systemctl enable --now docker

Step 2: Configure the Environment and Docker Compose File

Create a dedicated directory for your Logto installation and define the multi-container setup. Create a file named docker-compose.yml and insert the following configuration:

version: '3.8'

services:
postgres:
image: postgres:14-alpine
container_name: logto-postgres
environment:
POSTGRES_USER: logto_admin
POSTGRES_PASSWORD: YourSuperSecurePasswordHere
POSTGRES_DB: logto_db
volumes:
- pgdata:/var/lib/postgresql/data
restart: always

logto:
image: ghcr.io/logto-io/logto:latest
container_name: logto-core
ports:
- "3001:3001"
- "3002:3002"
environment:
- DB_URL=postgresql://logto_admin:YourSuperSecurePasswordHere@postgres:5432/logto_db
- ENDPOINT=[https://auth.yourdomain.com](https://auth.yourdomain.com)
- ADMIN_ENDPOINT=[https://admin.yourdomain.com](https://admin.yourdomain.com)
depends_on:
- postgres
restart: always

volumes:
pgdata:

Note: Replace "YourSuperSecurePasswordHere" with a strong, randomly generated alphanumeric string, and update the domain endpoints to match your company's domain infrastructure.

Step 3: Database Initialization and Launch

Logto requires a database schema migration before the core service can spin up successfully. Run the initialization command provided by the Logto image:

docker compose run logto npm run alter

Once the database schemas are successfully provisioned, launch the containers in detached mode:

docker compose up -d

Configuring the Reverse Proxy and SSL Certificates

Exposing raw ports (3001 and 3002) directly to the public internet introduces significant security vulnerabilities. To mitigate this, we will configure Nginx as a reverse proxy and secure the connection using Let's Encrypt SSL certificates via Certbot.

1. Install Nginx and Certbot

sudo apt install nginx certbot python3-certbot-nginx -y

2. Configure Nginx Server Blocks

Create a new configuration file at /etc/nginx/sites-available/logto to handle traffic for both the user authentication endpoint and the admin console:

server {
server_name auth.yourdomain.com;
location / {
proxy_pass http://localhost:3001;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;

}

server {
server_name admin.yourdomain.com;
location / {
proxy_pass http://localhost:3002;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}

Enable the site configuration and restart Nginx:

sudo ln -s /etc/nginx/sites-available/logto /etc/nginx/sites-enabled/
sudo systemctl restart nginx

3. Obtain SSL Certificates

Execute Certbot to automatically fetch and configure SSL certificates, ensuring all HTTP traffic is forcefully redirected to secure HTTPS:

sudo certbot --nginx -d auth.yourdomain.com -d admin.yourdomain.com

Production Hardening and Best Practices

Deploying the software is only the first phase; maintaining a secure, production-ready posture is paramount for identity infrastructure.

  • Implement Strict Firewall Rules: Configure ufw (Uncomplicated Firewall) to block public access to internal ports. Only ports 80 (HTTP) and 443 (HTTPS) should be exposed externally.
  • Automated Database Backups: Establish a nightly cron job that utilizes pg_dump to compress and back up the PostgreSQL database volume to an offsite S3-compatible cloud object storage.
  • SMTP Configuration: Configure Logto's email provider settings using an enterprise SMTP provider (e.g., SendGrid, Mailgun) to ensure highly reliable delivery of verification codes, password resets, and multi-factor authentication (MFA) prompts.
  • Log Monitoring: Aggregate container logs using systems like Fluentd or Grafana Loki to monitor for anomalous authentication spikes or brute-force patterns.

Conclusion

Deploying Logto on a self-hosted Cloud VPS equips your business with a world-class, centralized identity management system built on enterprise-grade OIDC and OAuth2 standards. This approach effectively balances structural autonomy, regulatory compliance, and excellent cost predictability. By following the deployment steps, reverse proxy configurations, and security hardening protocols detailed in this guide, your engineering team can seamlessly deliver a frictionless, secure authentication experience for both web and mobile application ecosystems.

Deploying Logto Auth Server on Cloud VPS: A Modern Identity Management Solution (OIDC/OAuth2) for Web and Mobile Applications | DPTCloud