authentik

Deploy authentik for self-managed single sign-on and application authentication using protocols such as OAuth2/OIDC, SAML, and LDAP.

On this page

Scope and fit

authentik is an identity provider and single sign-on platform with a flexible flow and provider model. It can connect applications to centrally managed authentication while allowing teams to keep the identity service in infrastructure they operate.

Connect applications through providers

In authentik, a provider defines how an application communicates with the identity service. Supported provider types include OAuth2/OpenID Connect, SAML, LDAP, and proxy-based authentication; each integration still needs to be matched to the application's capabilities.

Bring existing services into one login flow

Teams can use authentik to add a consistent sign-in experience to compatible applications and to place authentication in front of services that lack a native integration. Plan user sources, enrollment, recovery, MFA, and the support path for login issues as part of the rollout.

Treat the identity provider as critical infrastructure

A production setup needs protected administrative access, reliable storage, correctly configured proxy headers, outbound email where required, and a tested backup plan. Validate high availability and upgrade behavior against the deployment method and version you run.

Decisions and tradeoffs

Use this table as a working review record. Replace assumptions with evidence from the target environment.

Decision areaWorking guidance
Connect applications through providersIn authentik, a provider defines how an application communicates with the identity service. Supported provider types include OAuth2/OpenID Connect, SAML, LDAP, and proxy-based authentication; each integration still needs to be matched to the application's capabilities.
Bring existing services into one login flowTeams can use authentik to add a consistent sign-in experience to compatible applications and to place authentication in front of services that lack a native integration. Plan user sources, enrollment, recovery, MFA, and the support path for login issues as part of the rollout.
Treat the identity provider as critical infrastructureA production setup needs protected administrative access, reliable storage, correctly configured proxy headers, outbound email where required, and a tested backup plan. Validate high availability and upgrade behavior against the deployment method and version you run.

Implementation questions

What should the team decide about connect applications through providers?

In authentik, a provider defines how an application communicates with the identity service. Supported provider types include OAuth2/OpenID Connect, SAML, LDAP, and proxy-based authentication; each integration still needs to be matched to the application's capabilities. Use a named owner and a written acceptance check so this decision can be reviewed after deployment.

What should the team decide about bring existing services into one login flow?

Teams can use authentik to add a consistent sign-in experience to compatible applications and to place authentication in front of services that lack a native integration. Plan user sources, enrollment, recovery, MFA, and the support path for login issues as part of the rollout. Use a named owner and a written acceptance check so this decision can be reviewed after deployment.

What should the team decide about treat the identity provider as critical infrastructure?

A production setup needs protected administrative access, reliable storage, correctly configured proxy headers, outbound email where required, and a tested backup plan. Validate high availability and upgrade behavior against the deployment method and version you run. Use a named owner and a written acceptance check so this decision can be reviewed after deployment.

Plan, build, verify, operate

Connect applications through providers: In authentik, a provider defines how an application communicates with the identity service. Supported provider types include OAuth2/OpenID Connect, SAML, LDAP, and proxy-based authentication; each integration still needs to be matched to the application's capabilities. Record the result and the next owner before changing the next boundary.

Deployment checks

Turn the page into a reviewable handover by assigning each check to a person and retaining its result.

Central application and provider management

Connect applications through providers: Central application and provider management. Confirm the owner, input, evidence, and acceptance check before this work moves into production.

Configurable authentication flows

Connect applications through providers: Configurable authentication flows. Confirm the owner, input, evidence, and acceptance check before this work moves into production.

User, group, and policy administration

Connect applications through providers: User, group, and policy administration. Confirm the owner, input, evidence, and acceptance check before this work moves into production.

Integrate web applications and internal services

Bring existing services into one login flow: Integrate web applications and internal services. Confirm the owner, input, evidence, and acceptance check before this work moves into production.

Choose protocol per application

Bring existing services into one login flow: Choose protocol per application. Confirm the owner, input, evidence, and acceptance check before this work moves into production.

Define access and recovery policies

Bring existing services into one login flow: Define access and recovery policies. Confirm the owner, input, evidence, and acceptance check before this work moves into production.

Flows, providers, and proxy boundaries

authentik connects applications through providers. An OAuth2/OpenID Connect, SAML, LDAP, or proxy provider should be selected because the target application supports that integration, not because one provider type is familiar. Maintain an application register that pairs each external URL with its provider, launch URL, owner, required group or policy, and test account.

Authentication and enrolment flows define a user's path through sign-in, recovery, and multi-factor checks. Keep these flows understandable enough that a support person can tell why access failed. Test a normal user, a user who meets an MFA rule, a user who is denied by policy, a locked-out user, and an administrator. Recovery is part of the service design, especially when the identity source or mail route is unavailable.

Proxy integrations depend on correct external URLs and headers. The reverse proxy has to pass the information authentik expects, and the application must not remain directly reachable on a route that bypasses the proxy. Check this from outside the trusted network as well as inside it. A login page that looks correct does not demonstrate that the protected service rejects direct access.

A self-hosted setup has server, worker, database, cache, media, outbound email, and proxy dependencies according to its deployment method. Monitor each dependency and keep secrets outside source control. Before an upgrade, back up data, record the version, and run a sign-in and application-access check in a representative environment. Restore testing should include actual identities and provider configuration, not an empty installation.

The operating pack should list providers, flows, policies, groups, upstream directories, mail settings, admin access, and break-glass steps. Assign one team to the platform and an owner to every protected application. That boundary prevents an application outage from becoming an unanswered identity ticket.

Handover and ownership

Before handover, name the system owner, support path, access boundary, backup or recovery responsibility, and the condition that pauses a change.

Keep a short record of what was tested, what remains outside scope, and when the review should happen again.

Sources and further reading

Talk to our team.

Tell us what you're working on, whether it's a deployment, an audit, a security test or a cyber range. You'll speak with an engineer who can help you scope it.

  • 30-minute call: free, with no obligation.
  • NDA on request: we can sign before you share details.
  • Clear next steps: a scope and plan after the call.