authentik
SecurityA self-hosted identity provider that offers SSO with OIDC, SAML, LDAP, SCIM, RADIUS and a reverse proxy.

What the free edition leaves out
The free edition is genuinely usable, but some team or enterprise features need a paid plan. “Not confirmed” means the official pages we read did not say, so we do not guess.
| Feature | Free edition | Details | Source |
|---|---|---|---|
| SSO / SAML | Free | The pricing page lists OIDC, SAML, LDAP, SCIM, RADIUS, Kerberos and Proxy under the free Open Source plan. | Source ↗ |
| Role-based access control | Not confirmed | Not described for the free edition on the pricing page. | Source ↗ |
| Audit logs | Not confirmed | The pricing page lists enhanced audit logging under Enterprise; basic audit logging in the free edition is not described. | Source ↗ |
| Multi-user / teams | Not confirmed | – | – |
| Backups and restore | Not confirmed | – | – |
| API access | Free | The developer docs describe authentik as fully API-driven, with an OpenAPI schema. | Source ↗ |
| Support SLA | Paid | The pricing page lists no support on the Open Source plan, ticket-based support on Enterprise (subscriptions over $1k) and dedicated support and SLAs on Enterprise Plus. | Source ↗ |
Best for
Teams that want self-hosted SSO with a flexible, flow-based login setup and support for SAML, OIDC, LDAP and proxy-based protection of apps.
Why choose it over Auth0
The core is MIT licensed and the free plan includes OIDC, SAML, LDAP, SCIM, RADIUS, Kerberos and proxy support. You run it on your own PostgreSQL-backed server with no per-user fee from the project. Paid Enterprise plans add support and extra features if you need them later.
Where it falls short
The authentik/enterprise/ folder is source-visible but needs a paid subscription for production use. The pricing page lists enhanced audit logging, privileged access management, mTLS client certificates and support or SLAs only in paid plans, and gives the free plan no support beyond the community Discord. You run upgrades, the database and backups yourself.
Open-source alternative to
- Auth0 — authentik handles login, user sources and OAuth/OIDC providers for applications, so it can replace Auth0 when you want to host it yourself. This is a replacement use, not an official claim by the project.
- Okta — authentik is a self-hosted identity provider with SSO, SAML and OIDC, so it can replace Okta for login and user management. This is a replacement use, not an official claim by the project.
Category
SecurityTopics
Tech stack
Languages as reported by GitHub for the repository.