Overview
Authelia is an open-source authentication and authorization server that works as a companion to common reverse proxies. The proxy asks Authelia whether each request is allowed; Authelia shows its login portal when needed, enforces second factors and applies access policies by user, group, resource or domain. It is also an OpenID Certified OpenID Connect 1.0 provider, so apps with native OIDC support can log in through it directly.
It supports passkeys for passwordless login and second factors including one-time passwords, mobile push notifications and WebAuthn security keys. Users who have not set up a second factor must validate by email, passwords can be reset from the portal against LDAP or its internal user store, and brute-force regulation locks accounts after too many failed attempts.
The project is written in Go and React, ships as a container under 20 MB and usually uses under 30 MB of memory, and can run as multiple replicas on Kubernetes. It is free under the Apache 2.0 licence with community support. It is a tool for protecting self-hosted apps and internal services rather than a user sign-up system for a public product.
Pricing and plans
checked 28 Sept 2026Free tier · no card
Completely free and open source (Apache 2.0); no paid tiers
| Plan | Price | What you get |
|---|---|---|
| Authelia | Free | Apache 2.0, self-hosted |
What it does
- Forward auth
- Protects any web app behind a supported reverse proxy, even apps with no login of their own.
- OpenID Connect provider
- OpenID Certified OIDC 1.0 provider for apps with native OIDC support.
- Multi-factor and passkeys
- Passkeys, TOTP, mobile push and WebAuthn second factors.
- Access policies
- Granular rules by user, group, domain and resource.
- Login regulation
- Locks accounts for a period after repeated failed logins.
- Tiny footprint
- Container under 20 MB compressed, memory typically under 30 MB.
Strengths and limitations
Strengths
- Free and Apache-licensed
- Very small resource footprint
- Works with apps that have no login by using the reverse proxy
- OpenID Certified OIDC provider
Limitations
- Self-hosted only, with community support
- No SAML listed on the project pages read
- Not designed for public sign-up flows or B2B multi-tenancy
- No formal security accreditations yet; the project is raising funds for audits
Who it suits
Good for
- Homelabs protecting self-hosted apps
- Small teams putting 2FA in front of internal tools
- Low-resource servers
Look elsewhere if
- Customer-facing sign-up and user management in a product
- Enterprises needing SAML federation and vendor support
Alternatives to Authelia
| Tool | From | Free option | Stages |
|---|---|---|---|
| Amazon Cognito Cloud user directory and auth service | Usage-based | Free tier | |
| Appwrite Cloud Open-source backend-as-a-service (database, auth, storage, functions, hosting) | $25/mo | Free tier | |
| Asgardeo Hosted CIAM (with open-source self-hosted option) | $20/mo | Free tier | |
| Authgear Open-source CIAM (cloud, VPC or one-time self-host licence) | $50/mo | Free tier | |
| Better Auth Open-source TypeScript auth library | $20/mo | Free tier | |
| Casdoor Open-source IAM and SSO server with MCP gateway | — | Free tier |
Questions
Is Authelia free?
Yes. Authelia is open source under the Apache 2.0 licence with no paid tiers.
Does Authelia support OpenID Connect?
Yes. It is an OpenID Certified OpenID Connect 1.0 provider.
How does Authelia work with nginx or Traefik?
The reverse proxy forwards each request to Authelia to check authentication and policy before passing it to the app.
Does Authelia support passkeys?
Yes, for passwordless login, alongside TOTP, push and WebAuthn second factors.
Sources read for this page