Authentik: Self-Hosted Identity Provider and SSO
Last updated on

Authentik: Self-Hosted Identity Provider and SSO

Authentik is an identity provider: it holds your user accounts and authenticates them on behalf of every other application, so one login covers everything.

The problem it solves

A dozen self-hosted services means a dozen account systems of wildly varying quality, several with no two-factor support and one or two with authentication you would rather not inspect closely. An identity provider centralizes that: users exist once, multi-factor is enforced in one place, and revoking access means disabling one account rather than remembering every service someone touched.

Protocol coverage

Authentik speaks OAuth2 and OIDC, SAML, LDAP (both as provider and source), SCIM for provisioning, and proxy or forward authentication for applications that support no protocol at all. That last mode is what makes it practical in a homelab: an application with no SSO support can still be protected by putting Authentik in front of it via Traefik or nginx.

Flows are the distinguishing feature

Authentik models login, enrollment, recovery, and consent as configurable flows built from stages. You can require multi-factor only from outside the network, add a captcha for password recovery, or auto-enrol users on first login. That flexibility is genuinely powerful and is also why the learning curve is steeper than the alternatives.

Versus Authelia and Keycloak

Authelia is lighter and configuration-file driven, excellent for forward auth and less capable as a full IdP. Keycloak is the enterprise-grade Red Hat option, more mature and heavier. Authentik sits between them with the friendliest interface of the three.

Operational warning

Once your services depend on it, Authentik becoming unavailable locks you out of everything. Keep an emergency admin path, back up the database, and think carefully before putting your monitoring behind it.

License

Authentik is released under the MIT License.