Authentik
Description
Authentik is an open-source Identity Provider (IdP) and single sign-on solution, and a self-hosted alternative to Okta, Auth0, and Microsoft Entra ID. A configurable flow engine models every authentication, enrollment, and recovery journey as a sequence of stages, so policies like MFA, captcha, and consent are composed rather than coded. It speaks SAML, OAuth2/OpenID Connect, LDAP, RADIUS, and SCIM, letting one directory back every app you run.
Features
- Protocol support: SAML 2.0, OAuth2/OIDC, LDAP, RADIUS, SCIM, and proxy/forward-auth outposts.
- Flow engine: Visual, stage-based flows for login, enrollment, MFA, and password recovery.
- Multi-factor auth: TOTP, WebAuthn/passkeys, SMS, email, and static recovery codes.
- Directory sync: Inbound and outbound sync with Active Directory, Entra ID, and Google Workspace.
- Application proxy: Add authentication in front of apps that have none via reverse-proxy outposts.
- Self-service: Branded user portal, admin interface, and a full REST API.
Technology Stack
- Python / Django core with a Go-based outpost proxy
- PostgreSQL database and Redis for caching and tasks
- TypeScript / Lit web interface
- Docker Compose and Helm for deployment
Requirements
- Docker and Docker Compose (or Kubernetes with the official Helm chart)
- PostgreSQL and Redis (bundled in the sample compose file)
- Minimum ~2 GB RAM; an SMTP server for email notifications
Categories
Topics
GitHub Metrics
Stars
25,406Forks
1,994Contributors
1,994Last Updated
9/8/2026Ad
Sponsor this page
Get seen without shouting for attention. Clean placement, real audience.
Learn more