Bitflake logo

Authentik

Self-hosted identity provider for single sign-on, MFA and LDAP across your apps.

1 / 7
  • Admin Overview Dashboard

    System status, outpost health, recent events, and login activity at a glance.

  • Applications

    Applications configured to use authentik as their identity provider.

  • Providers

    OAuth2/OIDC, SAML, LDAP, and other providers backing each application.

  • Users

    The Directory view listing local users and service accounts.

  • Outposts

    The embedded outpost handling authentication traffic, shown healthy.

  • Flows

    The built-in authentication, authorization, and enrollment flows.

  • Event Log

    Audit trail of logins, model changes, and other system events.

About this app

Authentik is a self-hosted identity provider that centralises sign-in across your self-hosted apps. It supports SSO over OIDC, OAuth2 and SAML, acts as an LDAP server for apps that only speak that protocol, and can sit in front of anything else as a forward-auth proxy. Multi-factor authentication and role-based access control are built in, not bolted on. People who choose Authentik point to control. Running your own identity provider means you're not exposed to a vendor's outages, forced upgrades, or a sudden pricing change. It also costs the same regardless of how many people use it, unlike SaaS identity providers that price by active user or login volume. Core access control also ships free, with RBAC, audit logging, and unlimited users included at no cost. Google Workspace and Microsoft Entra ID directory sync, the Shared Signals Framework, mTLS client-certificate authentication, and enhanced audit logging with before/after change detail all require the Enterprise tier; everything else is free.

  • Authentication:
    API KeysLDAP / ADMFAOIDC SSOPassword AuthSAML SSOSocial LoginForward Auth / Proxy ProviderLDAP Server ProvidermTLS Client-Certificate AuthenticationSelf-service Password ResetSocial Login Sources
  • Access Control:
    RBACTeams
  • Data:
    Audit LogData ExportEnhanced Audit Logging
  • Integrations:
    REST APIWebhooksGoogle Workspace SyncMicrosoft Entra ID SyncShared Signals Framework (SSF)
  • UI:
    Custom BrandingDark Mode
  • Infrastructure:

25.3k stars

2.0k forks

Last releaseRelease 2026.8.1(4 days ago*)Last activity1 day ago*Project age6 years (2019)Contributors500+

Commit activity

commits / month
Lifetime296
Past year439
Past month420

As of last sync (about 24 hours ago)

Funding

Premium Features

Free core with paid add-ons

Company-backed

Backed by a commercial company

Other

Other or unknown funding sources

Technology stack

  • Dockerfile
  • HTML
  • Python
  • CSS
  • JavaScript
  • Shell
  • Makefile
  • Go
  • TypeScript
  • PHP

License

Custom

Custom or non-standard license

Licensed under the MIT License, free to use and self-host — except the authentik/enterprise/ directory (per the root LICENSE file's own carve-out), which is licensed under a separate proprietary "authentik Enterprise Edition (EE) License". That code implements Enterprise-tier features (e.g. enhanced audit logging, Google Workspace/Microsoft Entra ID sync, Shared Signals Framework, mTLS client-certificate auth) and may only be used in production with a valid paid Enterprise subscription; it may still be freely modified and used for development/testing without one. Client-side assets (images, fonts, CSS, compiled JavaScript) remain MIT-licensed even where compiled alongside EE code.

View License

Bitflake is not affiliated with or the creator of this project. App names, logos, and trademarks are property of their respective owners. Data shown (including GitHub stats) is updated once per day and may be inaccurate or out of date. Spotted an issue? Let us know at contact@bitflake.com.