Vibeleaderboard
Index / app
Visit github.com
Category
Developer Tools
Rank
No. 1986Tools index
Pricing
Open Source
Type
APP
Use case
Security & Identity
Latest release
version/2026.8.3
Date

About

authentik is an open-source identity provider for single sign-on, supporting SAML, OAuth2/OIDC, LDAP, and RADIUS. It is built for self-hosting at any scale, from small home labs to large production clusters, and ships an enterprise offering aimed at organizations replacing commercial IdPs such as Okta, Auth0, Entra ID, and Ping Identity. Deployment options include Docker Compose for small or test setups and Kubernetes for larger installations.

What it does

authentik sits between your users and your apps and handles the sign-in. Each app talks to it in whatever language that app already speaks (SAML, OpenID Connect, LDAP, RADIUS, SCIM provisioning), while authentik owns the users, groups, passwords and second factors behind them. Logins are assembled from configurable flows: an ordered chain of stages such as identify, password, one-time code, passkey, consent or invitation. A Rust front server accepts traffic and passes it to a Django application, and small Go companion services carry the LDAP and RADIUS protocols out to where they are needed.

Why it's ranked here

The case rests on breadth that is visible in the code, not just the marketing. The core is MIT licensed, the dependency list wires in RADIUS, LDAP, Kerberos, SCIM, WebAuthn, Duo, SMS and Microsoft Graph, and there are four supported install paths from a single-host Compose file to an AWS template. The repository carries end-to-end browser tests and an OpenID conformance test package. That is a self-hosted identity provider with the protocol coverage of commercial ones, and the main caveat is that some features sit under a separate enterprise license.

What's good

Protocol coverage is the headline: one install can front a web app over OpenID Connect, a legacy tool over LDAP and a VPN over RADIUS against the same user directory. The background task queue, websocket messaging and cache all run on Postgres through packages kept in the same repository, so there is no separate message broker named in the dependencies. The Rust layer turns on FIPS-validated cryptography and bans unsafe code. The AWS template is concrete, with a multi-zone Postgres database, encrypted shared storage and two server plus two worker containers by default.

Tradeoffs

This is three codebases in one: Python for the core, Rust for the front server, Go for the outposts, plus a TypeScript web interface. Contributing or debugging deep means knowing more than one of them. The Python side pins an exact interpreter series, 3.14, so older base images will not run it from source. Type checking is configured, yet nearly every core package is listed with type errors ignored. The enterprise code carries its own license separate from MIT, and the docs call that edition source available, so check which features you need before assuming they are free.

How to use it well

Pick it when you run several self-hosted apps and want one login for all of them, including the awkward ones that only speak LDAP or RADIUS. Start on Docker Compose to learn flows and stages, then move to Kubernetes or the AWS template once the configuration is settled. Deploy the LDAP or RADIUS outposts close to the systems that need them; the LDAP one takes only a host address and an API token. Keep the recovery-token path in your runbook, because an admin locked out by a misconfigured flow is the classic failure. Paid vendor support comes only with the enterprise tier.

Technical notes+

Process layout from src/main.rs: one Rust binary with subcommands allinone, server, worker, proxy and healthcheck, gated by the core and proxy Cargo features; core mode initializes an embedded Python interpreter through pyo3 before starting tokio. src/server/mod.rs spawns gunicorn bound to a Unix socket serving authentik.root.asgi:application, marks it ready on SIGUSR1 or a successful socket connect, checks liveness every 5 seconds, and routes each request to core or to the embedded proxy outpost by host in route_core_and_outpost, recording an authentik_main_request_duration histogram. cmd/ldap/main.go is a cobra entry point configured by AUTHENTIK_HOST, AUTHENTIK_TOKEN and AUTHENTIK_INSECURE. pyproject.toml declares requires-python ==3.14.*, Django 5.2, workspace packages django-dramatiq-postgres, django-channels-postgres and django-postgres-cache, and a mypy override with ignore_errors = true over almost every authentik module. Cargo.toml sets unsafe_code = deny and fips features on aws-lc-rs and rustls. lifecycle/aws/app.py builds a CDK stack: multi-AZ RDS Postgres (default m5.large, 17.1), two encrypted EFS file systems, Fargate server and worker tasks at 512 CPU units and 1024 MiB with desired count 2 each. authentik/recovery/lib.py issues expiring recovery tokens (create_recovery_token) and upserts a superuser admin group (create_admin_group).

Observed

License
MIT for the core, CC BY-SA 4.0 for the docs site, a separate enterprise license for the enterprise directory
Languages
Python (Django) core, Rust front server, Go outposts, TypeScript web tooling
Python requirement
Exactly the 3.14 series
Protocols in dependencies
SAML, OAuth2/OIDC, LDAP, RADIUS, SCIM, Kerberos, WebAuthn
Install paths
Docker Compose, Kubernetes Helm chart, AWS CloudFormation, DigitalOcean Marketplace
Backing services
Postgres for data, task queue, channel layer and cache
Cryptography
FIPS features enabled on the Rust TLS stack; unsafe Rust denied workspace-wide
Test suites
pytest unit tests, Selenium end-to-end tests, OpenID conformance package
Type checking
mypy configured, errors ignored for nearly all core modules

Read from README.md, pyproject.toml, package.json, Cargo.toml, go.mod, authentik/__init__.py, authentik/recovery/lib.py, src/main.rs, src/server/mod.rs, cmd/ldap/main.go, website/docs/index.mdx, lifecycle/aws/app.py.

Tags

authenticationssooauth2samlldapself-hosted

Tech Stack

Node.jsPythonRustGoTypeScript

Comments (0)

No comments yet

Editorially curated, with community endorsements as a secondary signal. Corrections welcome.