aicoolies logo
Authentik logo
Authentik logo

Authentik

Open-source identity provider for self-hosted SSO and access management

open sourceupdated Aug 16, 2026

Authentik is an open-source Identity Provider supporting SAML, OAuth2/OIDC, LDAP, RADIUS, and SCIM for self-hosted single sign-on. It provides customizable authentication flows, multi-factor authentication, user management, and proxy-based SSO for applications without native support. Positioned as a modern Keycloak alternative with 22K+ GitHub stars, free Open Source use, and paid Enterprise/Enterprise Plus plans.

Read our Authentik review

A detailed review by the aicoolies team — click to read

Authentik has emerged as the leading modern alternative to Keycloak for organizations that want self-hosted identity management without the operational complexity of enterprise Java applications. Built in Python with a React frontend, Authentik provides a cleaner developer experience while supporting the same breadth of authentication protocols including SAML 2.0, OAuth2, OpenID Connect, LDAP, RADIUS, and SCIM for user provisioning. The customizable flow system allows administrators to define exact authentication journeys including login, registration, recovery, and multi-factor verification steps.

The platform excels at centralizing identity across diverse application landscapes. Modern web applications connect through OAuth2 or OIDC, legacy enterprise systems integrate via LDAP, and applications without native SSO support gain authentication through Authentik's proxy provider that intercepts requests at the reverse proxy layer. This protocol versatility means organizations can unify authentication across their entire stack without requiring every application to support the same identity standard.

Authentik Security, the public benefit company behind the project, offers paid Enterprise and Enterprise Plus plans; the current pricing page lists Enterprise at $5/user/month plus $0.02/external user/month pricing, while the repository license keeps most non-enterprise code MIT and separates enterprise-directory terms. The project has grown to 22K+ GitHub stars, with docs currently tracking the 2026.5 release line and a community contributing integrations, themes, and deployment guides. Deployment options span Docker Compose for small setups through Kubernetes Helm charts for production clusters, with Terraform support and AWS CloudFormation templates for infrastructure-as-code workflows.

Pricing

Open Source free; Enterprise $5/user/month + $0.02/external user/month; Enterprise Plus custom

Platforms

Docker, Kubernetes, self-hosted, any Linux server

Categories

Tags

Use Cases

Related Tools

computed discovery: shared active categories · kept separate from editor-verified Alternatives

KTransformers parent kvcache-ai logo

KTransformers

Heterogeneous CPU-GPU inference and SFT for large MoE models

Open-source framework for running and fine-tuning large Mixture-of-Experts models with heterogeneous CPU-GPU execution, optimized kernels, limited VRAM and SGLang or LLaMA-Factory integrations.

Open Source
vLLM Production Stack parent vLLM logo

vLLM Production Stack

Official Kubernetes and Helm reference stack built on the vLLM inference engine

Official vLLM reference implementation for scaling the existing inference engine on Kubernetes with Helm, request routing, KV-cache offload, autoscaling and Prometheus/Grafana observability.

Open Source
Dynamo logo

NVIDIA Dynamo

Distributed inference orchestration above vLLM, SGLang and TensorRT-LLM

Open-source, datacenter-scale orchestration layer that coordinates vLLM, SGLang and TensorRT-LLM across nodes with disaggregated serving, KV-aware routing, multi-tier cache management and automatic scaling.

Open Source
GPUStack logo

GPUStack

Open-source GPU control plane for scalable AI model serving

Open-source GPU cluster manager that configures vLLM, SGLang, TensorRT-LLM or custom engines, serves models through compatible APIs, and provisions SSH-accessible GPU instances across on-premises, Kubernetes and cloud environments.

Open Source
Mooncake logo

Mooncake

Disaggregated KV cache storage and transfer for LLM serving

Open-source infrastructure for disaggregated LLM serving that pools KV caches across prefill and decode workers, with high-performance transfer, distributed storage and integrations for vLLM and SGLang.

Open Source
LMCache logo

LMCache

Reusable KV cache infrastructure for scalable LLM inference

Open-source KV cache management layer that persists, offloads and reuses model key-value caches across requests and serving engines to reduce repeated prefill work and improve inference throughput.

Open Source

Used in Stacks

Comparisons

Authentik vs Keycloak — Modern Python IdP vs Established Java Identity Platform

Authentik and Keycloak both provide self-hosted open-source identity management but represent different generations of IdP architecture. Authentik is a modern Python-based platform with a cleaner UI and simpler operational model, positioning itself as the accessible alternative. Keycloak is the established Java-based enterprise IdP with the broadest feature set and deepest protocol support, backed by Red Hat.

AuthentikKeycloak

FAQ

What is Authentik?

Authentik is an open-source Identity Provider supporting SAML, OAuth2/OIDC, LDAP, RADIUS, and SCIM for self-hosted single sign-on. It provides customizable authentication flows, multi-factor authentication, user management, and proxy-based SSO for applications without native support. Positioned as a modern Keycloak alternative with 22K+ GitHub stars, free Open Source use, and paid Enterprise/Enterprise Plus plans.

Is Authentik free?

Yes — Authentik is open source and free to use. Open Source free; Enterprise $5/user/month + $0.02/external user/month; Enterprise Plus custom

Is Authentik open source?

Yes — Authentik is open source.

What are the best Authentik alternatives?

The top editor-verified Authentik alternatives are Ory, Keycloak.

How does Authentik score in our review?

Our hands-on review scores Authentik 87/100 overall, based on speed, privacy, and developer-experience testing.