Authelia
A self-hosted single sign-on and multi-factor authentication portal that protects web applications, certified for OpenID Connect and ready for post-quantum cryptography.
- GitHub stars
- 29k
- Last commit
- yesterday
- Latest release
- v4.39.28
- Licence
- Apache-2.0
- Self-hosted
- Yes

Authelia is an open-source authentication and authorization server that provides single sign-on and multi-factor authentication for web applications. It sits in front of your services, usually alongside a reverse proxy, so users sign in once at a portal and are checked against policies before reaching an app.
Supported factors and backends include TOTP, push notifications, two-factor methods and LDAP, according to its topics, and it is described as OpenID Certified and ready for post-quantum cryptography. It is written in Go and runs well as a small container, with documentation for Docker and Kubernetes deployments. Self-hosters often use it to add a consistent login and second factor to tools that have weak or no authentication of their own.
Authelia is licensed under Apache-2.0. As an authentication component, it is meant to be run on your own infrastructure, and it suits home labs, small organizations and teams wanting a lightweight identity layer without a heavier enterprise identity platform.
Key features
- Single sign-on portal for web apps
- Multi-factor authentication including TOTP
- Push notification verification
- LDAP user backend support
- OpenID Connect support
- Docker and Kubernetes deployment
Pricing: Free and open source under the Apache-2.0 license.




