logto.io

.io crawl

First seen 2026-04-11 · Last seen 2026-05-18 · ok HTTP/1.1 200 692 ms crawled 2026-05-18

US · 172.66.40.214 · AS13335 Cloudflare, Inc.

Reputation 95/100 weak security headers

Classifying

HTML metadata

Title
Logto: Modern auth infrastructure for developers
Description
Logto adds multi-tenancy, enterprise SSO, and RBAC to your SaaS or AI apps. All with OIDC and OAuth 2.1 made simple, fast, and developer-friendly.
Language
en
Canonical
https://logto.io/
Translations
  • ar
  • de
  • en
  • es
  • fi
  • fr
  • it
  • ja
  • ko
  • nl
  • pl
  • pl-pl
  • pt
  • pt-br
  • pt-pt
  • ru
  • sv
  • th
  • tr
  • tr-tr
  • zh
  • zh-cn
  • zh-hk
  • zh-tw

Open Graph

url
https://logto.io/
title
Logto: Modern auth infrastructure for developers
site name
Logto
description
Logto adds multi-tenancy, enterprise SSO, and RBAC to your SaaS or AI apps. All with OIDC and OAuth 2.1 made simple, fast, and developer-friendly.

Technology

CDN
Cloudflare

Social

DNS records live

NS
  • jacqueline.ns.cloudflare.com
  • reese.ns.cloudflare.com
MX
  • 1 aspmx.l.google.com
  • 10 aspmx2.googlemail.com
  • 10 aspmx3.googlemail.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
TXT
Show 4 TXT records
  • yandex-verification: f750adeeebdb2537
  • MS=ms93549204
  • _pejivftfef7nmslk6wuvit04zk1xpji
  • google-site-verification=3EYzsnarDwG6zL2dlHvyC8ySVcV6Q3RGlvh7-bvhb2k

Email authentication strong

SPF
v=spf1 include:_spf.google.com ~all
softfail (~all)
DMARC
v=DMARC1; p=quarantine; rua=mailto:18e7014184f44df4ae961762ff124b30@dmarc-reports.cloudflare.net; pct=100
policy: quarantine
DKIM
  • google: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArNL/yo1vEEV+7e5k29yLAEc6CqbGv/RoQAOM4XjJujQgw6rqXLIeiBcuNeZj81OclygKXpYTDbeKgu…
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0sd5soda8YetImifVnFBm3lIAxOnP0x/Qrl5iU+zbWBd5I1ipY/zf7iZN5kki2VJbnJPSBdtBVCUp1nX57…
  • s2: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtoAbcaYckYetp6Xvchn3pfrU0qi5eNO35l51b3ix0fD1Otzg0dddlIPOoxMUYEeycKol1z2i2wd+U3hd5q…
selectors probed

Certificate (current)

WE1
from 2026-04-03 to 2026-07-03
Expires in 45 days

HTTP security headers

Header hygiene 30/100 Checked live page: https://logto.io/

findings
  • missing HSTS
  • missing Content Security Policy
  • missing frame protection
  • missing content type protection
  • missing Referrer Policy
  • missing Permissions Policy

Links to (10)

Linked from (4)