# authelia/authelia

The Single Sign-On Multi-Factor portal for web apps, now OpenID Certified™

Repository: https://github.com/authelia/authelia
Canonical: https://ross.abutalabs.com/products/authelia
Homepage: https://www.authelia.com
Language: Go
License: Apache-2.0
License Family: permissive
Topics: totp, ldap, sso-authentication, yubikey, two-factor-authentication, docker, kubernetes, sso, multifactor, push-notifications, mfa, two-factor, authentication, security, golang, 2fa, oauth2, openid-connect, webauthn, passkeys
Last push: 2026-08-26T23:18:24+00:00

## Health v2 (maintenance only)
Score: 95/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 86, longevity 100
- inputs: {"age_days": 3557, "days_push": 7, "days_rel": 99, "gap_med": 13, "n_releases_24m": 30}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 28712, forks 1473 (observed 2026-08-28T04:11:52.765732+00:00)

## What it is
Authelia is an open-source authentication and authorization server and portal providing single sign-on (SSO) and multi-factor authentication (MFA) for web applications. It acts as an OpenID Connect 1.0 Provider (OpenID Certified) and integrates with common reverse proxies to protect apps behind them.

## Use cases
- add single sign-on to self-hosted web apps behind a reverse proxy
- require two-factor authentication before accessing internal applications
- serve as an OpenID Connect provider for my apps
- protect services with LDAP-backed user authentication
- enforce per-user and per-group authorization policies
- prevent brute-force login attempts on my portal
- let users reset passwords via email validation

## When to choose
- you self-host multiple web apps and want one login portal in front of them
- you need a lightweight, self-hosted IAM with MFA (TOTP, WebAuthn, YubiKey, push notifications)
- you use reverse proxies like Traefik, nginx, or Caddy and want forward-auth integration
- you want an OpenID Certified OIDC provider without commercial licensing

## When to avoid
- you need a full enterprise IAM with user provisioning, SCIM, or SAML-heavy ecosystems
- you prefer a managed cloud identity provider rather than self-hosting
- your stack cannot run a small Go service or container
- you need deep directory-sync features of commercial products like Okta or Keycloak's full admin console

## Facets
- artifact type: service
- maturity: active
- function: auth, authorization, security, middleware, http-server
- domain: security, self-hosted, web-development, developer-tools
- platform: go, self-hosted, cross-platform
- tags: sso, mfa, openid-connect, oauth2, webauthn, passkeys, totp, ldap, reverse-proxy, iam, two-factor-authentication, yubikey, docker, kubernetes, linux

## Member repositories
- authelia/authelia (main) score 95

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:11:52.765732+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T16:54:20.366892+00:00, confidence not recorded.
  - readme: https://github.com/authelia/authelia (fetched 2026-08-28T04:11:52.765732+00:00, sha 103850b0238c)
  - homepage: https://www.authelia.com (fetched 2026-08-29T07:50:40.326240+00:00, sha eaf77d94234b)
  - site_page: https://www.authelia.com/information/about (fetched 2026-08-29T07:50:40.335647+00:00, sha 1d8806b2ae15)
- Data as of 2026-08-30T08:39:29.467469+00:00.
