7,380 open-source and SaaS tools, with GitHub stats refreshed every day.

Authentik

Open source

An open-source identity provider for single sign-on that supports SAML, OAuth2 and OIDC, LDAP and RADIUS, built for self-hosting from home labs to large clusters.

goauthentik.io
Authentik homepage screenshot
GitHub stars
26k
Last commit
today
Repository age
6 years
Version
version/2026.8.3
Licence
Custom
Self-hosted
Yes

About Authentik

authentik is an open-source Identity Provider for modern single sign-on. It supports SAML, OAuth2 and OpenID Connect, LDAP, RADIUS and more, and is designed for self-hosting at any scale, from a small lab to production clusters. A reverse-proxy mode also lets it protect applications that lack native SSO support.

The project positions its enterprise offering as a way for organizations to replace incumbent identity providers (Okta, Auth0, Entra ID or Ping Identity) in large-scale identity management. For installation, Docker Compose is recommended for small and test setups, a Helm chart for Kubernetes suits larger setups, and official templates exist for AWS CloudFormation and a one-click DigitalOcean Marketplace app.

The codebase is mostly Python with Kubernetes tooling, and the license is listed as 'Other' on GitHub because it mixes open-source and enterprise components, so check which features fall under which terms. authentik is a common choice for self-hosters and companies who want to centralize logins across internal tools without paying per-user fees to a hosted identity vendor.

Key features

  • SAML and OAuth2/OIDC provider
  • LDAP and RADIUS support
  • Reverse-proxy authentication for apps
  • Docker Compose and Helm chart installs
  • AWS CloudFormation and DigitalOcean templates
  • Enterprise edition for large deployments

Good fit for

  • →Single sign-on across internal and self-hosted apps
  • →Replacing Auth0 or Okta with a self-hosted IdP
  • →Centralized user management in a homelab
Tags
sso
identity-provider
saml
oidc
oauth2
ldap
authentication
self-hosted
python

Authentik: questions and answers

What is Authentik used for?
Authentik is an open-source identity provider for single sign-on that supports SAML, OAuth2 and OIDC, LDAP and RADIUS, built for self-hosting from home labs to large clusters. It is a good fit for single sign-on across internal and self-hosted apps, replacing Auth0 or Okta with a self-hosted IdP, and centralized user management in a homelab.
Is Authentik open source?
Yes. Authentik is open source under a custom licence. Its source code is on GitHub at goauthentik/authentik and is written mainly in Python.
Is Authentik free?
Yes. Authentik is open source, so the software itself is free to use under the terms of its own licence. Paid plans are also available, starting at $5 per seat per month.
Can I self-host Authentik?
Yes. Authentik can be self-hosted on your own server or infrastructure.
What is Authentik an alternative to?
Authentik is an open-source alternative to Auth0, OneLogin, Microsoft Entra ID and JumpCloud. Other open-source alternatives to Auth0 include Keycloak, WSO2 Identity Server and Casdoor.
Is Authentik actively maintained?
Yes. The most recent commit to Authentik was on 2 October 2026. The project has 26k stars on GitHub.

Open-source alternatives to Authentik

See all

SaaS alternatives to Authentik

See all