Admin Overview Dashboard
System status, outpost health, recent events, and login activity at a glance.
Self-hosted identity provider for single sign-on, MFA and LDAP across your apps.
System status, outpost health, recent events, and login activity at a glance.
Applications configured to use authentik as their identity provider.
OAuth2/OIDC, SAML, LDAP, and other providers backing each application.
The Directory view listing local users and service accounts.
The embedded outpost handling authentication traffic, shown healthy.
The built-in authentication, authorization, and enrollment flows.
Audit trail of logins, model changes, and other system events.
Authentik is a self-hosted identity provider that centralises sign-in across your self-hosted apps. It supports SSO over OIDC, OAuth2 and SAML, acts as an LDAP server for apps that only speak that protocol, and can sit in front of anything else as a forward-auth proxy. Multi-factor authentication and role-based access control are built in, not bolted on. People who choose Authentik point to control. Running your own identity provider means you're not exposed to a vendor's outages, forced upgrades, or a sudden pricing change. It also costs the same regardless of how many people use it, unlike SaaS identity providers that price by active user or login volume. Core access control also ships free, with RBAC, audit logging, and unlimited users included at no cost. Google Workspace and Microsoft Entra ID directory sync, the Shared Signals Framework, mTLS client-certificate authentication, and enhanced audit logging with before/after change detail all require the Enterprise tier; everything else is free.
GitHub
goauthentik/authentik25.3k stars
2.0k forks
Commit activity
commits / monthAs of last sync (about 24 hours ago)
Funding
Technology stack
Custom
Custom or non-standard license
Licensed under the MIT License, free to use and self-host — except the authentik/enterprise/ directory (per the root LICENSE file's own carve-out), which is licensed under a separate proprietary "authentik Enterprise Edition (EE) License". That code implements Enterprise-tier features (e.g. enhanced audit logging, Google Workspace/Microsoft Entra ID sync, Shared Signals Framework, mTLS client-certificate auth) and may only be used in production with a valid paid Enterprise subscription; it may still be freely modified and used for development/testing without one. Client-side assets (images, fonts, CSS, compiled JavaScript) remain MIT-licensed even where compiled alongside EE code.
Bitflake is not affiliated with or the creator of this project. App names, logos, and trademarks are property of their respective owners. Data shown (including GitHub stats) is updated once per day and may be inaccurate or out of date. Spotted an issue? Let us know at contact@bitflake.com.