# goauthentik/authentik

The authentication glue you need.

Repository: https://github.com/goauthentik/authentik
Canonical: https://ross.abutalabs.com/products/authentik
Homepage: https://goauthentik.io
Language: Python
License: NOASSERTION
License Family: other
Topics: saml, saml-idp, saml-sp, oauth2, oauth2-server, oauth2-client, oidc, oidc-provider, oidc-client, sso, proxy, reverse-proxy, authentication, authorization, authentik, kubernetes, security
Last push: 2026-08-27T00:14:44+00:00

## Health v2 (maintenance only)
Score: 95/100 (v2, computed 2026-09-03T02:39:23.370411+00:00)
- activity 99, release rhythm 86, longevity 100
- inputs: {"age_days": 2438, "days_push": 7, "days_rel": 15, "gap_med": 8, "n_releases_24m": 68}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 25178, forks 1963 (observed 2026-08-28T04:11:38.047550+00:00)

## What it is
authentik is an open-source Identity Provider (IdP) and Single Sign-On (SSO) platform supporting SAML, OAuth2/OIDC, LDAP, SCIM, RADIUS, and proxy-based authentication. It is designed for self-hosting via Docker Compose or Kubernetes, with customizable authentication flows, MFA, passkeys, and policy-based conditional access.

## Use cases
- self-host single sign-on for all my apps
- replace Okta or Auth0 with an open-source identity provider
- add SAML or OIDC login to legacy applications
- centralize multi-factor authentication across systems
- manage customer identities for a SaaS product
- enforce zero-trust conditional access policies
- add authentication to apps behind a reverse proxy

## When to choose
- you want full control over identity data by self-hosting your IdP
- you need broad protocol support (SAML, OAuth2/OIDC, LDAP, SCIM, RADIUS) in one platform
- you need customizable authentication flows, MFA, and passkeys
- you want to protect legacy apps that lack native SSO via a proxy provider
- you run Kubernetes or Docker and want infrastructure-as-code friendly identity management

## When to avoid
- you want a fully managed, zero-operations hosted identity service
- you need a minimal lightweight auth library embedded directly in a single application
- you require enterprise features like PAM, Entra ID integration, or FIPS compliance without a paid subscription
- you lack the capacity to operate and secure a self-hosted identity service

## Facets
- artifact type: service
- maturity: active
- function: auth, authorization, security, proxy, self-hosted, api-gateway
- domain: security, self-hosted, developer-tools, web-development
- platform: self-hosted, cloud, python
- tags: identity-provider, sso, saml, oauth2, oidc, ldap, scim, mfa, passkeys, single-sign-on, idp, zero-trust, docker, kubernetes, linux

## Member repositories
- goauthentik/authentik (main) score 95

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:11:38.047550+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T16:56:05.456350+00:00, confidence not recorded.
  - readme: https://github.com/goauthentik/authentik (fetched 2026-08-28T04:11:38.047550+00:00, sha 94f4292a49a2)
  - homepage: https://goauthentik.io (fetched 2026-08-29T07:53:08.908694+00:00, sha 007f9ca8492f)
  - site_page: https://goauthentik.io/features (fetched 2026-08-29T07:53:08.918268+00:00, sha 493dc940d067)
  - site_page: https://docs.goauthentik.io (fetched 2026-08-29T07:53:08.922289+00:00, sha 8aeb7261b676)
  - site_page: https://docs.goauthentik.io/install-config (fetched 2026-08-29T07:53:08.925674+00:00, sha dba50e32b0ad)
  - site_page: https://docs.goauthentik.io/developer-docs (fetched 2026-08-29T07:53:08.927192+00:00, sha ed61586c367d)
  - site_page: https://integrations.goauthentik.io (fetched 2026-08-29T07:53:08.920569+00:00, sha c36048d0850e)
  - site_page: https://goauthentik.io/pricing (fetched 2026-08-29T07:53:08.923967+00:00, sha 9d8c0c95c5b6)
- Data as of 2026-08-30T08:39:29.467469+00:00.
