Deployment guide

Authentik vs Authelia: Which Self-Hosted SSO for Your VPS?

Deploy on a VPS Cloud →

Authentik vs Authelia: Which Self-Hosted SSO for Your VPS?

Comparison9 min read10 steps

Authentik and Authelia appear side by side in almost every discussion about self-hosted SSO — but they do not answer the same question. Authentik is a full identity provider: OIDC, SAML, LDAP, provisioning, visual flows. Authelia is a lightweight authentication gateway that hooks into your reverse proxy and gates access to your applications. Choosing one over the other because it is 'more popular' is the most common mistake on this topic.

Contents· Two philosophies, not two direct competitors1/12
  1. 01Two philosophies, not two direct competitors
  2. 02Authentik vs Authelia comparison table
  3. 03Protocols: the criterion that settles 80% of cases
  4. 04Choose Authelia if
  5. 05Choose Authentik if
  6. 06Resource footprint: the difference is an order of magnitude
  7. 07Prerequisites for deploying both
  8. 08Deploy Authelia with Docker Compose
  9. 09Deploy Authentik with Docker Compose
  10. 10Using both in parallel
  11. 11Security and attack surface
  12. 12Which VPS for each tool

Two philosophies, not two direct competitors

Authentik (version 2026.8.2 at the time of writing) is written in Python/Django with a TypeScript frontend. It runs on your VPS and acts as a fully fledged identity provider: your applications delegate their authentication to Authentik via OIDC or SAML, which manages sessions, groups, provisioning and account lifecycle. The model is that of Okta or Auth0, open source and on your infrastructure.

Authelia (v4.39.24 at the time of writing) is an authentication layer that sits in front of your reverse proxy — Traefik, nginx or Caddy — via the auth_request directive. It validates every HTTP request: if the user is not authenticated or does not have the right MFA level, Authelia returns a 401 and the reverse proxy blocks. Authelia does not issue OAuth2 tokens to applications, it protects URLs.

These two tools often coexist on the same infrastructure: Authelia for internal dashboards and tools without native OIDC support, Authentik for applications that speak OAuth2 or for LDAP provisioning to a home Active Directory.

Authentik vs Authelia comparison table

Scroll the table

CriterionAuthentik 2026.8Authelia v4.39
TypeIdentity Provider (IdP)Authentication gateway
OIDC / OAuth2Yes — OpenID Certified™Yes — OpenID Certified™
SAML 2.0 (IdP)YesNo (roadmap, no timeline)
LDAPYes (provider + outpost)No
SCIM provisioningYes (Enterprise)No
Visual authentication flowsYesNo
Minimum RAM (full stack)~1 GB (worker + PostgreSQL)< 30 MB
Required databasePostgreSQL (Redis removed in 2025.10)Redis + PostgreSQL (or SQLite)
Administration interfaceFull (web UI)YAML configuration file
LicenseMIT (Community) / EnterpriseApache 2.0
Server languagePython + Rust (since 2026.8)Go

Protocols: the criterion that settles 80% of cases

SAML support is the most common tipping point. If an application in your stack — an office suite, an ERP, an HR tool — only accepts SAML 2.0 as a federation mechanism, you have no choice: Authelia cannot act as a SAML IdP. SAML support is on Authelia's roadmap, in the 'planning' section (not yet 'active'), with no published date.

For OIDC/OAuth2, both tools are now OpenID Certified™. Authelia obtained this certification, validating the implementation against the Basic OP, Implicit OP, Hybrid OP, Form Post OP and Config OP profiles. Authentik is also certified since version 2026.8, with additional support for logout profiles (RP-Initiated, Front-Channel, Back-Channel).

For a stack of 100% modern web applications that speak OIDC — Nextcloud, Gitea, Grafana, Mattermost, Jellyfin — Authelia is sufficient and considerably lighter. As soon as an application requires SAML, automatic account provisioning or fine-grained entitlement management, Authentik is the only one of the two that can deliver.

Choose Authelia if

  • You protect internal services without native OIDC support (dashboards, DevOps tools) via your reverse proxy
  • Your VPS has less than 2 GB of RAM or runs several services in parallel
  • You prefer declarative YAML configuration, versioned in Git, without a web interface
  • Your stack is exclusively OIDC/OAuth2 (no SAML, no LDAP)
  • You want a minimal attack surface: the Go binary weighs less than 20 MB

Choose Authentik if

  • At least one application requires SAML 2.0 — Authentik is the only one of the two to implement it
  • You manage user accounts: lifecycle, SCIM provisioning, LDAP synchronization
  • You need custom authentication flows (onboarding, email verification, account recovery)
  • Your technical team prefers a graphical interface to a configuration file
  • You centralise identity for multiple teams or multiple products

Resource footprint: the difference is an order of magnitude

Authelia stays under 30 MB of RAM under normal conditions. Its Docker container weighs less than 20 MB. For a complete installation with Redis and PostgreSQL, count 150 to 200 MB total — the footprint of one service among others on a shared VPS.

Authentik is in a different category. The full stack — Python worker, Rust server (since 2026.8, the frontend was rewritten from Go to Rust) and PostgreSQL — requires a minimum of 1 GB of usable RAM, and rather 2 GB on a server dedicated to Authentik if you count several hundred users. The project simplified the stack in 2025.10 by removing Redis: all caching operations, background tasks and WebSocket connections now go through PostgreSQL. The number of connections to the database increased in return.

On a 2 GB RAM VPS already running Gitea, Grafana and a reverse proxy, Authentik will consume half the available resources. Authelia, in the same context, will be practically undetectable.

Prerequisites for deploying both

For Authelia: a VPS with 1 GB of RAM is sufficient, a reverse proxy already in place (Traefik, nginx or Caddy), a domain pointed to your server, Docker and Docker Compose installed. Authelia needs session storage — SQLite for testing, PostgreSQL or MySQL in production, Redis for cache (optional from v4.38 if you enable in-memory).

For Authentik: plan for a VPS with at least 2 GB of RAM dedicated to Authentik, ideally 4 GB if other services run in parallel. PostgreSQL is mandatory (Redis removed since 2025.10). You need Docker, Docker Compose, a domain, and ports 80 and 443 open. Installation via the official docker-compose starts PostgreSQL, the worker and the Authentik server in a single command.

Deploy Authelia with Docker Compose

  1. Create the directory structure

    Create a working directory and the necessary subdirectories:

    mkdir -p /opt/authelia/{config,data}
    cd /opt/authelia
  2. Create the configuration file

    Authelia is configured in YAML. Create /opt/authelia/config/configuration.yml with the server, log, authentication_backend, access_control, session, storage and notifier blocks. Set the root domain (auth.yourdomain.com), the session duration and the storage backend (SQLite to start, PostgreSQL in production).

  3. Create the docker-compose.yml

    services:
      authelia:
        image: authelia/authelia:latest
        container_name: authelia
        volumes:
          - ./config:/config
          - ./data:/data
        ports:
          - "9091:9091"
        restart: unless-stopped
        environment:
          - TZ=Europe/Paris
  4. Configure the reverse proxy

    In nginx, add a location block that delegates validation to Authelia via auth_request. Every request to your internal services first goes through http://authelia:9091/api/verify — Authelia returns 200 if the user is authenticated, 401 otherwise. Traefik has an equivalent ForwardAuth middleware.

  5. Start and verify

    docker compose up -d
    docker compose logs -f authelia

    Open https://auth.yourdomain.com. Authelia displays its login portal. Create a first user in the users_database.yml file and test access to a protected service.

Deploy Authentik with Docker Compose

  1. Fetch the official compose

    mkdir -p /opt/authentik && cd /opt/authentik
    curl -O https://goauthentik.io/docker-compose.yml

    This file defines the worker, the server and PostgreSQL. Since version 2025.10, Redis is no longer in the default compose.

  2. Create the .env file

    Generate the necessary secrets:

    echo "PG_PASS=$(openssl rand -base64 36 | tr -d '\n')" >> .env
    echo "AUTHENTIK_SECRET_KEY=$(openssl rand -base64 60 | tr -d '\n')" >> .env
    echo "AUTHENTIK_ERROR_REPORTING__ENABLED=false" >> .env

    Adjust AUTHENTIK_EMAIL__* if you want email notifications.

  3. Start the stack

    docker compose pull
    docker compose up -d

    The first start applies PostgreSQL migrations and may take one to two minutes. Follow the logs with docker compose logs -f worker.

  4. Access the administration interface

    Open http://<vps-ip>:9000/if/flow/initial-setup/ to create the initial administrator account. Then point your domain (sso.yourdomain.com) to the server and configure the reverse proxy to terminate TLS.

  5. Create your first OIDC application

    In the administration interface, go to Applications → Create then Providers → OAuth2/OpenID. Fill in the redirect URL of your client application, copy the generated Client ID and Client Secret, and configure your application with Authentik's OIDC endpoints (/application/o/<slug>/.well-known/openid-configuration).

Using both in parallel

The most common combination on a well-loaded VPS: Authelia protects internal tools without OIDC support (legacy Grafana, Portainer, home dashboards) via the reverse proxy, and Authentik plays the OIDC IdP role for applications that delegate their authentication. Both can coexist on the same server and share the same PostgreSQL if the databases are isolated. Authelia can even be configured to delegate authentication to Authentik via OIDC — you thus get Authelia's lightness as a gateway and Authentik's richness as an identity source.

Security and attack surface

Authelia's attack surface is structurally smaller: less code, no exposed administration interface (configuration is a local file), no SAML support, no LDAP. Authelia's historical CVE record is consequently shorter than Authentik's.

Authentik exposes more: a full web interface, a flow engine, several authentication protocols, a REST API and outposts. Each additional surface is a surface to maintain and monitor. Authentik's support policy covers the current version and the previous one — beyond that, security fixes are not backported.

In both cases, best practices are the same: do not expose the administration port directly on the internet, use a valid TLS certificate on the authentication subdomain, enable MFA for all administration accounts, and keep Docker images up to date by tracking releases. Authentik publishes releases approximately every three months; Authelia publishes fixes more frequently (biweekly cadence in 2026).

Which VPS for each tool

For Authelia alone, a VPS with 1 to 2 GB of RAM is more than sufficient, even if you run several other services in parallel. Authelia does not justify a dedicated server.

For Authentik, the reasonable minimum in production is 2 GB of RAM dedicated to the Authentik stack (worker + PostgreSQL). If Authentik shares the VPS with other applications, plan for 4 GB minimum. For deployments with several hundred active users, the required resources increase proportionally with database usage.

A ServOrbit VPS with 2 vCPU and 4 GB of RAM comfortably covers Authentik in production, with headroom for the applications it protects. The Authentik Marketplace template on Dolibarr, n8n, Nextcloud, Open WebUI, WooCommerce, WordPress configures the Docker stack with PostgreSQL, environment variables and the nginx reverse proxy in a single command.

Deploy your self-hosted SSO on a dedicated VPS

A ServOrbit VPS with root access, dedicated IPv4 and pre-configured Docker gives you the foundation to run Authentik or Authelia in production. Choose the resources suited to your stack and scale vertically on demand.

Need help?

Browse our help center and FAQ, or reach our team — callback, WhatsApp or email. Support in French, English and Arabic.

Message us on WhatsAppopens in a new tab