Two philosophies, not two direct competitors
Authentik (version 2026.8.2 at the time of writing) is written in Python/Django with a TypeScript frontend. It runs on your VPS and acts as a fully fledged identity provider: your applications delegate their authentication to Authentik via OIDC or SAML, which manages sessions, groups, provisioning and account lifecycle. The model is that of Okta or Auth0, open source and on your infrastructure.
Authelia (v4.39.24 at the time of writing) is an authentication layer that sits in front of your reverse proxy — Traefik, nginx or Caddy — via the auth_request directive. It validates every HTTP request: if the user is not authenticated or does not have the right MFA level, Authelia returns a 401 and the reverse proxy blocks. Authelia does not issue OAuth2 tokens to applications, it protects URLs.
These two tools often coexist on the same infrastructure: Authelia for internal dashboards and tools without native OIDC support, Authentik for applications that speak OAuth2 or for LDAP provisioning to a home Active Directory.
Authentik vs Authelia comparison table
Scroll the table
| Criterion | Authentik 2026.8 | Authelia v4.39 |
|---|---|---|
| Type | Identity Provider (IdP) | Authentication gateway |
| OIDC / OAuth2 | Yes — OpenID Certified™ | Yes — OpenID Certified™ |
| SAML 2.0 (IdP) | Yes | No (roadmap, no timeline) |
| LDAP | Yes (provider + outpost) | No |
| SCIM provisioning | Yes (Enterprise) | No |
| Visual authentication flows | Yes | No |
| Minimum RAM (full stack) | ~1 GB (worker + PostgreSQL) | < 30 MB |
| Required database | PostgreSQL (Redis removed in 2025.10) | Redis + PostgreSQL (or SQLite) |
| Administration interface | Full (web UI) | YAML configuration file |
| License | MIT (Community) / Enterprise | Apache 2.0 |
| Server language | Python + Rust (since 2026.8) | Go |
Protocols: the criterion that settles 80% of cases
SAML support is the most common tipping point. If an application in your stack — an office suite, an ERP, an HR tool — only accepts SAML 2.0 as a federation mechanism, you have no choice: Authelia cannot act as a SAML IdP. SAML support is on Authelia's roadmap, in the 'planning' section (not yet 'active'), with no published date.
For OIDC/OAuth2, both tools are now OpenID Certified™. Authelia obtained this certification, validating the implementation against the Basic OP, Implicit OP, Hybrid OP, Form Post OP and Config OP profiles. Authentik is also certified since version 2026.8, with additional support for logout profiles (RP-Initiated, Front-Channel, Back-Channel).
For a stack of 100% modern web applications that speak OIDC — Nextcloud, Gitea, Grafana, Mattermost, Jellyfin — Authelia is sufficient and considerably lighter. As soon as an application requires SAML, automatic account provisioning or fine-grained entitlement management, Authentik is the only one of the two that can deliver.
Choose Authelia if
- You protect internal services without native OIDC support (dashboards, DevOps tools) via your reverse proxy
- Your VPS has less than 2 GB of RAM or runs several services in parallel
- You prefer declarative YAML configuration, versioned in Git, without a web interface
- Your stack is exclusively OIDC/OAuth2 (no SAML, no LDAP)
- You want a minimal attack surface: the Go binary weighs less than 20 MB
Choose Authentik if
- At least one application requires SAML 2.0 — Authentik is the only one of the two to implement it
- You manage user accounts: lifecycle, SCIM provisioning, LDAP synchronization
- You need custom authentication flows (onboarding, email verification, account recovery)
- Your technical team prefers a graphical interface to a configuration file
- You centralise identity for multiple teams or multiple products
Resource footprint: the difference is an order of magnitude
Authelia stays under 30 MB of RAM under normal conditions. Its Docker container weighs less than 20 MB. For a complete installation with Redis and PostgreSQL, count 150 to 200 MB total — the footprint of one service among others on a shared VPS.
Authentik is in a different category. The full stack — Python worker, Rust server (since 2026.8, the frontend was rewritten from Go to Rust) and PostgreSQL — requires a minimum of 1 GB of usable RAM, and rather 2 GB on a server dedicated to Authentik if you count several hundred users. The project simplified the stack in 2025.10 by removing Redis: all caching operations, background tasks and WebSocket connections now go through PostgreSQL. The number of connections to the database increased in return.
On a 2 GB RAM VPS already running Gitea, Grafana and a reverse proxy, Authentik will consume half the available resources. Authelia, in the same context, will be practically undetectable.
Prerequisites for deploying both
For Authelia: a VPS with 1 GB of RAM is sufficient, a reverse proxy already in place (Traefik, nginx or Caddy), a domain pointed to your server, Docker and Docker Compose installed. Authelia needs session storage — SQLite for testing, PostgreSQL or MySQL in production, Redis for cache (optional from v4.38 if you enable in-memory).
For Authentik: plan for a VPS with at least 2 GB of RAM dedicated to Authentik, ideally 4 GB if other services run in parallel. PostgreSQL is mandatory (Redis removed since 2025.10). You need Docker, Docker Compose, a domain, and ports 80 and 443 open. Installation via the official docker-compose starts PostgreSQL, the worker and the Authentik server in a single command.
Deploy Authelia with Docker Compose
Create the directory structure
Create a working directory and the necessary subdirectories:
mkdir -p /opt/authelia/{config,data} cd /opt/autheliaCreate the configuration file
Authelia is configured in YAML. Create
/opt/authelia/config/configuration.ymlwith theserver,log,authentication_backend,access_control,session,storageandnotifierblocks. Set the rootdomain(auth.yourdomain.com), the session duration and the storage backend (SQLite to start, PostgreSQL in production).Create the docker-compose.yml
services: authelia: image: authelia/authelia:latest container_name: authelia volumes: - ./config:/config - ./data:/data ports: - "9091:9091" restart: unless-stopped environment: - TZ=Europe/ParisConfigure the reverse proxy
In nginx, add a
locationblock that delegates validation to Authelia viaauth_request. Every request to your internal services first goes throughhttp://authelia:9091/api/verify— Authelia returns 200 if the user is authenticated, 401 otherwise. Traefik has an equivalentForwardAuthmiddleware.Start and verify
docker compose up -d docker compose logs -f autheliaOpen
https://auth.yourdomain.com. Authelia displays its login portal. Create a first user in theusers_database.ymlfile and test access to a protected service.
Deploy Authentik with Docker Compose
Fetch the official compose
mkdir -p /opt/authentik && cd /opt/authentik curl -O https://goauthentik.io/docker-compose.ymlThis file defines the worker, the server and PostgreSQL. Since version 2025.10, Redis is no longer in the default compose.
Create the .env file
Generate the necessary secrets:
echo "PG_PASS=$(openssl rand -base64 36 | tr -d '\n')" >> .env echo "AUTHENTIK_SECRET_KEY=$(openssl rand -base64 60 | tr -d '\n')" >> .env echo "AUTHENTIK_ERROR_REPORTING__ENABLED=false" >> .envAdjust
AUTHENTIK_EMAIL__*if you want email notifications.Start the stack
docker compose pull docker compose up -dThe first start applies PostgreSQL migrations and may take one to two minutes. Follow the logs with
docker compose logs -f worker.Access the administration interface
Open
http://<vps-ip>:9000/if/flow/initial-setup/to create the initial administrator account. Then point your domain (sso.yourdomain.com) to the server and configure the reverse proxy to terminate TLS.Create your first OIDC application
In the administration interface, go to Applications → Create then Providers → OAuth2/OpenID. Fill in the redirect URL of your client application, copy the generated
Client IDandClient Secret, and configure your application with Authentik's OIDC endpoints (/application/o/<slug>/.well-known/openid-configuration).
Using both in parallel
The most common combination on a well-loaded VPS: Authelia protects internal tools without OIDC support (legacy Grafana, Portainer, home dashboards) via the reverse proxy, and Authentik plays the OIDC IdP role for applications that delegate their authentication. Both can coexist on the same server and share the same PostgreSQL if the databases are isolated. Authelia can even be configured to delegate authentication to Authentik via OIDC — you thus get Authelia's lightness as a gateway and Authentik's richness as an identity source.
Security and attack surface
Authelia's attack surface is structurally smaller: less code, no exposed administration interface (configuration is a local file), no SAML support, no LDAP. Authelia's historical CVE record is consequently shorter than Authentik's.
Authentik exposes more: a full web interface, a flow engine, several authentication protocols, a REST API and outposts. Each additional surface is a surface to maintain and monitor. Authentik's support policy covers the current version and the previous one — beyond that, security fixes are not backported.
In both cases, best practices are the same: do not expose the administration port directly on the internet, use a valid TLS certificate on the authentication subdomain, enable MFA for all administration accounts, and keep Docker images up to date by tracking releases. Authentik publishes releases approximately every three months; Authelia publishes fixes more frequently (biweekly cadence in 2026).
Which VPS for each tool
For Authelia alone, a VPS with 1 to 2 GB of RAM is more than sufficient, even if you run several other services in parallel. Authelia does not justify a dedicated server.
For Authentik, the reasonable minimum in production is 2 GB of RAM dedicated to the Authentik stack (worker + PostgreSQL). If Authentik shares the VPS with other applications, plan for 4 GB minimum. For deployments with several hundred active users, the required resources increase proportionally with database usage.
A ServOrbit VPS with 2 vCPU and 4 GB of RAM comfortably covers Authentik in production, with headroom for the applications it protects. The Authentik Marketplace template on Dolibarr, n8n, Nextcloud, Open WebUI, WooCommerce, WordPress configures the Docker stack with PostgreSQL, environment variables and the nginx reverse proxy in a single command.