Authentik

Authentik

Description

Authentik is an open-source Identity Provider (IdP) and single sign-on solution, and a self-hosted alternative to Okta, Auth0, and Microsoft Entra ID. A configurable flow engine models every authentication, enrollment, and recovery journey as a sequence of stages, so policies like MFA, captcha, and consent are composed rather than coded. It speaks SAML, OAuth2/OpenID Connect, LDAP, RADIUS, and SCIM, letting one directory back every app you run.

Features

  • Protocol support: SAML 2.0, OAuth2/OIDC, LDAP, RADIUS, SCIM, and proxy/forward-auth outposts.
  • Flow engine: Visual, stage-based flows for login, enrollment, MFA, and password recovery.
  • Multi-factor auth: TOTP, WebAuthn/passkeys, SMS, email, and static recovery codes.
  • Directory sync: Inbound and outbound sync with Active Directory, Entra ID, and Google Workspace.
  • Application proxy: Add authentication in front of apps that have none via reverse-proxy outposts.
  • Self-service: Branded user portal, admin interface, and a full REST API.

Technology Stack

  • Python / Django core with a Go-based outpost proxy
  • PostgreSQL database and Redis for caching and tasks
  • TypeScript / Lit web interface
  • Docker Compose and Helm for deployment

Requirements

  • Docker and Docker Compose (or Kubernetes with the official Helm chart)
  • PostgreSQL and Redis (bundled in the sample compose file)
  • Minimum ~2 GB RAM; an SMTP server for email notifications

Categories

Topics

GitHub Metrics

Stars
25,406
Forks
1,994
Contributors
1,994
Last Updated
9/8/2026
Ad

Sponsor this page

Get seen without shouting for attention. Clean placement, real audience.

Learn more
MohsenI built this — follow on X