Overview
authentik is an open-source identity provider for teams that want to own their SSO. One deployment speaks OAuth2/OIDC, SAML2, SCIM, LDAP, RADIUS and Kerberos, and it can act as a proxy in front of apps that have no login support at all. It is OpenID Certified, supports passkeys, conditional access and GeoIP checks, and even offers web-based RDP, VNC and SSH access.
The open-source edition has no user limit and covers both B2B and B2C use cases, but support is community-only through Discord and GitHub. The company states that it will not move open-source features into the paid edition.
Enterprise adds privileged access management, agent accounts for non-human identities, Microsoft Entra ID and Google Workspace integration, client certificate auth, enhanced audit logging and scheduled offboarding. External users (customers and partners) cost $0.02 each per month. There is no hosted version, so you run it on your own infrastructure; deployment templates exist for Docker Compose, Kubernetes, Terraform and AWS CloudFormation.
Pricing and plans
checked 28 Sept 2026Free tier · no card
Open-source edition is free to self-host with no user limit: OIDC, SAML, LDAP, SCIM, RADIUS, Kerberos and proxy, MFA, remote access; community Discord only, no support
| Plan | Price | What you get |
|---|---|---|
| Open Source | Free | All core protocols, community support |
| Enterprise | $0.02/external user/mo | PAM, agent accounts, Entra ID and Google Workspace sync, mTLS; ticket support over $1k |
| Enterprise Plus | Custom | Invoice billing, custom SLAs, FIPS compliance, volume discounts |
What it does
- Many protocols
- OIDC, SAML2, SCIM, LDAP, RADIUS, Kerberos and an authenticating proxy in one server.
- Flows and policies
- Configurable templates and policies for enrollment, authentication and recovery steps.
- Remote access
- Browser-based RDP, VNC and SSH to internal machines behind SSO.
- Application proxy
- Puts login in front of apps that do not support OIDC or SAML.
- Enterprise directory sync
- Microsoft Entra ID and Google Workspace integrations on Enterprise.
- Infrastructure as code
- Blueprints, APIs and Terraform support for automated configuration.
Strengths and limitations
Strengths
- Free and open source with no user cap
- Very wide protocol coverage, including LDAP and RADIUS
- Commitment not to move open-source features behind the paywall
- Cheap per-external-user Enterprise pricing
Limitations
- No hosted version; you must run and update it
- No support without an Enterprise subscription over $1,000
- Aimed at SSO for apps and workforce, not drop-in UI for a consumer app
- Internal-user Enterprise pricing is not visible on the pricing page
Who it suits
Good for
- Homelabs and self-hosted app collections
- Companies wanting self-hosted workforce SSO
- Protecting internal tools that lack login via the proxy
Look elsewhere if
- Developers who want a hosted auth API with front-end SDKs
- Teams without capacity to operate an identity server
Alternatives to authentik
| Tool | From | Free option | Stages |
|---|---|---|---|
| Amazon Cognito Cloud user directory and auth service | Usage-based | Free tier | |
| Asgardeo Hosted CIAM (with open-source self-hosted option) | $20/mo | Free tier | |
| Auth0 Hosted customer identity (CIAM) | $35/mo | Free tier | |
| Authgear Open-source CIAM (cloud, VPC or one-time self-host licence) | $50/mo | Free tier | |
| Descope No-code CIAM with visual flows | $249/mo | Free tier | |
| Firebase Backend platform with document and realtime databases | Usage-based | Free tier |
Questions
Is authentik free?
Yes. The open-source edition is free to self-host with no user limit; Enterprise features are paid.
Does authentik have a cloud version?
No. authentik states it does not currently provide a hosted version.
authentik vs Authelia: what's the difference?
authentik is a full identity provider with SAML, LDAP, SCIM and RADIUS; Authelia focuses on forward-auth for reverse proxies plus OIDC.
How much is authentik Enterprise?
$0.02 per external user per month; internal users are priced separately.
Sources read for this page