authentik logo

authentik

Website

Open-source Identity Provider (IdP) for SSO, OIDC, and SAML

25.2k stars 2k forks last commit first released

Actively maintained

Last commit 27 Aug 2026.

authentik screenshot

authentik is an open-source Identity Provider designed for modern single sign-on and authentication workflows. It provides protocol support and configurable authentication flows to secure web, API, and remote-access use cases.

Key Features

  • Supports standard identity protocols: OAuth2 / OIDC, SAML2, LDAP, RADIUS, SCIM and Kerberos for broad application compatibility
  • Flexible multi-stage authentication flows, policy engine, and enrollment flows for MFA and conditional access (GeoIP, impossible-travel checks)
  • MFA and modern second-factor support including TOTP and WebAuthn (passkeys)
  • Application proxy / outpost model for protecting internal apps and enabling remote access (RDP, SSH, VNC) behind the IdP
  • Rich admin, user, and flow interfaces plus REST APIs and SDKs for automation and integration
  • Pluggable federation and social login sources, fine-grained policies, and templates for customizing login and enrollment behavior
  • Deployment options and tooling for Docker Compose, Kubernetes (Helm), and cloud templates; background workers and channel layers for scale
  • Caching and async task support via Redis; persistent storage and migrations for relational databases

Use Cases

  • Enterprise replacement or augmentation of commercial IdPs to provide SSO, delegated access, and centralized authentication for web and API applications
  • Protecting internal or home-lab applications using the outpost/application-proxy model to enforce authentication and authorization policies
  • Integrating existing LDAP/AD directories and provisioning flows (SCIM) to enable consolidated identity management and MFA across services

Limitations and Considerations

  • Some legacy native desktop or mobile clients that embed outdated browser engines may not support the full web-based login flow; a simplified flow executor (SFE) or alternate API-key approach may be required for such clients
  • Major-version upgrades can require careful attention to migrations and worker restarts; administrators should test upgrades in staging before production rollouts

authentik provides a comprehensive, protocol-rich IdP with configurable flows and deployment flexibility. It is suited for organizations that need a self-hosted, extensible SSO solution with enterprise-grade features and automation capabilities.

Categories:

Tags:

Tech Stack:

Share:

Similar to authentik

Casdoor logo

Casdoor

UI-first IAM and SSO platform for modern authentication

14.3k
1.8k
Last commit

Casdoor is an open-source, UI-first IAM/SSO platform supporting OAuth 2.0, OIDC, SAML, LDAP, SCIM, WebAuthn and MFA, with an admin web UI and SDKs.

Apache-2.0Actively maintained
Alternative to:
Okta logo
Okta
+19
Logto logo

Logto

Authentication and authorization platform for apps and APIs

14.5k
1.2k
Last commit

Open-source authentication and authorization infrastructure with OIDC/OAuth 2.1, SAML SSO, multi-tenancy, MFA, and RBAC for SaaS and AI apps.

MPL-2.0Actively maintained
Alternative to:
Auth0 logo
Auth0
+19
Authgear logo

Authgear

Identity and authentication platform for apps and APIs

2k
125
Last commit

Open-source Auth0/Clerk/Firebase Auth alternative with passkeys, MFA, SSO (OIDC/SAML), user management portal, and extensible auth flows for web and mobile apps.

Apache-2.0Actively maintained
Alternative to:
Auth0 logo
Auth0
+19
Keycloak logo

Keycloak

Open-source identity and access management with SSO

36.4k
8.9k
Last commit

Keycloak is an open-source IAM server providing single sign-on, user federation, and centralized authentication and authorization using OIDC, OAuth 2.0, and SAML.

Apache-2.0Actively maintained
Alternative to:
Okta logo
Okta
+19
ZITADEL logo

ZITADEL

API-first identity and access management platform for applications

14.9k
1.3k
Last commit

ZITADEL is an open source IAM/CIAM platform providing SSO, MFA, OIDC/OAuth2, SAML, user management, and multi-tenant organizations with audit logging.

AGPL-3.0Actively maintained
Alternative to:
Auth0 logo
Auth0
+19
FusionAuth logo

FusionAuth

Self-hosted identity and access management for applications

FusionAuth is a self-hosted authentication and IAM platform supporting OAuth2, OIDC and SAML, with SSO, MFA, user management and developer-focused integrations.

Activity unknown
Alternative to:
Auth0 logo
Auth0
+19