Bitflake logo

Authentik

Flexible identity provider with SSO, MFA, LDAP and OAuth2 support.

1 / 7
  • Admin Overview Dashboard

    System status, outpost health, recent events, and login activity at a glance.

  • Applications

    Applications configured to use authentik as their identity provider.

  • Providers

    OAuth2/OIDC, SAML, LDAP, and other providers backing each application.

  • Users

    The Directory view listing local users and service accounts.

  • Outposts

    The embedded outpost handling authentication traffic, shown healthy.

  • Flows

    The built-in authentication, authorization, and enrollment flows.

  • Event Log

    Audit trail of logins, model changes, and other system events.

About this app

Authentik is a self-hosted identity provider and single sign-on solution that allows you to manage user authentication across all your self-hosted applications. It provides features such as SSO, MFA, LDAP, and OAuth2, all while keeping your identity data private and under your control.

  • Authentication:
    API KeysLDAP / ADMFAOIDC SSOPassword AuthSAML SSOSocial LoginForward Auth / Proxy ProviderLDAP Server ProvidermTLS Client-Certificate AuthenticationSelf-service Password ResetSocial Login Sources
  • Access Control:
    RBACTeamsUnlimited Users
  • Data:
    Audit LogEnhanced Audit Logging
  • Integrations:
    REST APIGoogle Workspace SyncMicrosoft Entra ID SyncShared Signals Framework (SSF)
  • UI:
    Custom Branding

Last release

Release 2026.5.5 (6 days ago*)

Last activity

about 7 hours ago*

22.4k stars

1.7k forks

Funding

Premium Features

Free core with paid add-ons

Company-backed

Backed by a commercial company

Other

Other or unknown funding sources

Technology stack

  • Dockerfile
  • HTML
  • Python
  • CSS
  • JavaScript
  • Shell
  • Makefile
  • Go
  • TypeScript
  • PHP

License

Custom

Custom or non-standard license

Licensed under the MIT License, free to use and self-host — except the authentik/enterprise/ directory (per the root LICENSE file's own carve-out), which is licensed under a separate proprietary "authentik Enterprise Edition (EE) License". That code implements Enterprise-tier features (e.g. enhanced audit logging, Google Workspace/Microsoft Entra ID sync, Shared Signals Framework, mTLS client-certificate auth) and may only be used in production with a valid paid Enterprise subscription; it may still be freely modified and used for development/testing without one. Client-side assets (images, fonts, CSS, compiled JavaScript) remain MIT-licensed even where compiled alongside EE code.

View License

Bitflake is not affiliated with or the creator of this project. App names, logos, and trademarks are property of their respective owners. Data shown (including GitHub stats) is updated once per day and may be inaccurate or out of date. Spotted an issue? Let us know at contact@bitflake.com.