Authelia: Lightweight Authentication and SSO Gateway
Last updated on

Authelia: Lightweight Authentication and SSO Gateway

Authelia sits behind your reverse proxy and authenticates requests before they reach your applications, adding login and multi-factor to services that have neither.

Forward auth is the core idea

Your reverse proxy asks Authelia whether a request is authorized. If not, the user is redirected to a login page; once authenticated, the request passes through. This means an application with no authentication whatsoever, or with authentication you do not trust, can be protected without modifying it. Traefik, nginx, and Caddy all support this pattern.

Authelia also speaks OpenID Connect for applications that support proper SSO.

Configuration as a file

Authelia is configured with YAML rather than a web interface, and access rules are expressed as policies matching domains and paths: bypass for public paths, one-factor for internal tools, two-factor for anything sensitive. That model is precise and version-controllable, and it is the main philosophical difference from Authentik, which is UI-driven and more flexible at the cost of complexity.

Resource footprint

It is a small Go binary. Compared with Authentik or Keycloak, it uses a fraction of the memory, which is why it is common on modest homelab hardware.

Multi-factor options

TOTP, WebAuthn security keys and passkeys, and push notifications via Duo. Enforcing two-factor selectively by rule, so internal access is frictionless while external access is not, is a common and sensible configuration.

Operational caution

Everything behind it depends on it. Keep a way in that does not route through Authelia for the case where it fails, and back up its configuration and user database.

License

Authelia is released under the Apache License 2.0.