[{"data":1,"prerenderedAt":226},["ShallowReactive",2],{"seo-verification":3,"blog-authentik-vs-authelia-sso-comparison-vps-en":6},{"google":4,"bing":5},"EycwPY2XMyTkVzas3n1ygeNJFGAH513qrMjfDljzsMQ","",{"key":7,"data":8},"blog-authentik-vs-authelia-sso-comparison-vps-en",{"id":9,"slug":10,"slugs":11,"title":15,"excerpt":16,"readTime":17,"views":18,"isPinned":19,"publishedAt":20,"updatedAt":21,"category":22,"categories":27,"featuredImage":29,"bgImage":30,"posterImage":31,"relatedSolution":32,"intro":35,"sections":36,"ctaTitle":162,"ctaBody":163,"ctaButton":164,"ctaUrl":165,"relatedPosts":166},423,"authentik-vs-authelia-sso-comparison-vps",{"fr":12,"en":10,"ar":13,"es":14},"authentik-vs-authelia-sso-self-hosted","authentik-مقابل-authelia-sso-مستضاف-ذاتيا-vps","authentik-vs-authelia-sso-comparativa-vps","Authentik vs Authelia: Which Self-Hosted SSO for Your VPS?","Authentik or Authelia for your self-hosted SSO? Technical comparison: OIDC\u002FSAML protocols, RAM footprint, architecture and use cases to help you decide.",9,0,false,"2026-10-08T00:00:00+00:00","2026-10-08T23:30:51+00:00",{"id":23,"name":24,"slug":25,"color":26,"icon":25},5,"Comparison","comparatif","bg-info\u002F10 text-info",[28],{"id":23,"name":24,"slug":25,"color":26,"icon":25},null,"\u002Fblog\u002Fcovers\u002Fbg.svg","\u002Fblog\u002Fcovers\u002Fauthentik-vs-authelia-sso-self-hosted-poster.svg",{"categorySlug":33,"appSlug":34},"cybersecurity-bastion","authentik","Authentik and Authelia appear side by side in almost every discussion about self-hosted SSO — but they do not answer the same question. Authentik is a full identity provider: OIDC, SAML, LDAP, provisioning, visual flows. Authelia is a lightweight authentication gateway that hooks into your reverse proxy and gates access to your applications. Choosing one over the other because it is 'more popular' is the most common mistake on this topic.",[37,41,89,92,101,109,112,115,134,152,156,159],{"type":38,"title":39,"body":40},"h2","Two philosophies, not two direct competitors","Authentik (version 2026.8.2 at the time of writing) is written in Python\u002FDjango with a TypeScript frontend. It runs on your VPS and acts as a fully fledged identity provider: your applications delegate their authentication to Authentik via OIDC or SAML, which manages sessions, groups, provisioning and account lifecycle. The model is that of Okta or Auth0, open source and on your infrastructure.\n\nAuthelia (v4.39.24 at the time of writing) is an authentication layer that sits in front of your reverse proxy — Traefik, nginx or Caddy — via the `auth_request` directive. It validates every HTTP request: if the user is not authenticated or does not have the right MFA level, Authelia returns a 401 and the reverse proxy blocks. Authelia does not issue OAuth2 tokens to applications, it protects URLs.\n\nThese two tools often coexist on the same infrastructure: Authelia for internal dashboards and tools without native OIDC support, Authentik for applications that speak OAuth2 or for LDAP provisioning to a home Active Directory.",{"type":42,"title":43,"headers":44,"rows":48},"comparison","Authentik vs Authelia comparison table",[45,46,47],"Criterion","Authentik 2026.8","Authelia v4.39",[49,53,56,60,64,67,69,73,77,81,85],[50,51,52],"Type","Identity Provider (IdP)","Authentication gateway",[54,55,55],"OIDC \u002F OAuth2","Yes — OpenID Certified™",[57,58,59],"SAML 2.0 (IdP)","Yes","No (roadmap, no timeline)",[61,62,63],"LDAP","Yes (provider + outpost)","No",[65,66,63],"SCIM provisioning","Yes (Enterprise)",[68,58,63],"Visual authentication flows",[70,71,72],"Minimum RAM (full stack)","~1 GB (worker + PostgreSQL)","\u003C 30 MB",[74,75,76],"Required database","PostgreSQL (Redis removed in 2025.10)","Redis + PostgreSQL (or SQLite)",[78,79,80],"Administration interface","Full (web UI)","YAML configuration file",[82,83,84],"License","MIT (Community) \u002F Enterprise","Apache 2.0",[86,87,88],"Server language","Python + Rust (since 2026.8)","Go",{"type":38,"title":90,"body":91},"Protocols: the criterion that settles 80% of cases","SAML support is the most common tipping point. If an application in your stack — an office suite, an ERP, an HR tool — only accepts SAML 2.0 as a federation mechanism, you have no choice: Authelia cannot act as a SAML IdP. SAML support is on Authelia's roadmap, in the 'planning' section (not yet 'active'), with no published date.\n\nFor OIDC\u002FOAuth2, both tools are now OpenID Certified™. Authelia obtained this certification, validating the implementation against the Basic OP, Implicit OP, Hybrid OP, Form Post OP and Config OP profiles. Authentik is also certified since version 2026.8, with additional support for logout profiles (RP-Initiated, Front-Channel, Back-Channel).\n\nFor a stack of 100% modern web applications that speak OIDC — Nextcloud, Gitea, Grafana, Mattermost, Jellyfin — Authelia is sufficient and considerably lighter. As soon as an application requires SAML, automatic account provisioning or fine-grained entitlement management, Authentik is the only one of the two that can deliver.",{"type":93,"title":94,"items":95},"ul","Choose Authelia if",[96,97,98,99,100],"You protect internal services without native OIDC support (dashboards, DevOps tools) via your reverse proxy","Your VPS has less than 2 GB of RAM or runs several services in parallel","You prefer declarative YAML configuration, versioned in Git, without a web interface","Your stack is exclusively OIDC\u002FOAuth2 (no SAML, no LDAP)","You want a minimal attack surface: the Go binary weighs less than 20 MB",{"type":93,"title":102,"items":103},"Choose Authentik if",[104,105,106,107,108],"At least one application requires SAML 2.0 — Authentik is the only one of the two to implement it","You manage user accounts: lifecycle, SCIM provisioning, LDAP synchronization","You need custom authentication flows (onboarding, email verification, account recovery)","Your technical team prefers a graphical interface to a configuration file","You centralise identity for multiple teams or multiple products",{"type":38,"title":110,"body":111},"Resource footprint: the difference is an order of magnitude","Authelia stays under 30 MB of RAM under normal conditions. Its Docker container weighs less than 20 MB. For a complete installation with Redis and PostgreSQL, count 150 to 200 MB total — the footprint of one service among others on a shared VPS.\n\nAuthentik is in a different category. The full stack — Python worker, Rust server (since 2026.8, the frontend was rewritten from Go to Rust) and PostgreSQL — requires a minimum of 1 GB of usable RAM, and rather 2 GB on a server dedicated to Authentik if you count several hundred users. The project simplified the stack in 2025.10 by removing Redis: all caching operations, background tasks and WebSocket connections now go through PostgreSQL. The number of connections to the database increased in return.\n\nOn a 2 GB RAM VPS already running Gitea, Grafana and a reverse proxy, Authentik will consume half the available resources. Authelia, in the same context, will be practically undetectable.",{"type":38,"title":113,"body":114},"Prerequisites for deploying both","For **Authelia**: a VPS with 1 GB of RAM is sufficient, a reverse proxy already in place (Traefik, nginx or Caddy), a domain pointed to your server, Docker and Docker Compose installed. Authelia needs session storage — SQLite for testing, PostgreSQL or MySQL in production, Redis for cache (optional from v4.38 if you enable in-memory).\n\nFor **Authentik**: plan for a VPS with at least 2 GB of RAM dedicated to Authentik, ideally 4 GB if other services run in parallel. PostgreSQL is mandatory (Redis removed since 2025.10). You need Docker, Docker Compose, a domain, and ports 80 and 443 open. Installation via the official docker-compose starts PostgreSQL, the worker and the Authentik server in a single command.",{"type":116,"title":117,"steps":118},"steps","Deploy Authelia with Docker Compose",[119,122,125,128,131],{"title":120,"body":121},"Create the directory structure","Create a working directory and the necessary subdirectories:\n```bash\nmkdir -p \u002Fopt\u002Fauthelia\u002F{config,data}\ncd \u002Fopt\u002Fauthelia\n```",{"title":123,"body":124},"Create the configuration file","Authelia is configured in YAML. Create `\u002Fopt\u002Fauthelia\u002Fconfig\u002Fconfiguration.yml` with the `server`, `log`, `authentication_backend`, `access_control`, `session`, `storage` and `notifier` blocks. Set the root `domain` (`auth.yourdomain.com`), the session duration and the storage backend (SQLite to start, PostgreSQL in production).",{"title":126,"body":127},"Create the docker-compose.yml","```bash\nservices:\n  authelia:\n    image: authelia\u002Fauthelia:latest\n    container_name: authelia\n    volumes:\n      - .\u002Fconfig:\u002Fconfig\n      - .\u002Fdata:\u002Fdata\n    ports:\n      - \"9091:9091\"\n    restart: unless-stopped\n    environment:\n      - TZ=Europe\u002FParis\n```",{"title":129,"body":130},"Configure the reverse proxy","In nginx, add a `location` block that delegates validation to Authelia via `auth_request`. Every request to your internal services first goes through `http:\u002F\u002Fauthelia:9091\u002Fapi\u002Fverify` — Authelia returns 200 if the user is authenticated, 401 otherwise. Traefik has an equivalent `ForwardAuth` middleware.",{"title":132,"body":133},"Start and verify","```bash\ndocker compose up -d\ndocker compose logs -f authelia\n```\nOpen `https:\u002F\u002Fauth.yourdomain.com`. Authelia displays its login portal. Create a first user in the `users_database.yml` file and test access to a protected service.",{"type":116,"title":135,"steps":136},"Deploy Authentik with Docker Compose",[137,140,143,146,149],{"title":138,"body":139},"Fetch the official compose","```bash\nmkdir -p \u002Fopt\u002Fauthentik && cd \u002Fopt\u002Fauthentik\ncurl -O https:\u002F\u002Fgoauthentik.io\u002Fdocker-compose.yml\n```\nThis file defines the worker, the server and PostgreSQL. Since version 2025.10, Redis is no longer in the default compose.",{"title":141,"body":142},"Create the .env file","Generate the necessary secrets:\n```bash\necho \"PG_PASS=$(openssl rand -base64 36 | tr -d '\\n')\" >> .env\necho \"AUTHENTIK_SECRET_KEY=$(openssl rand -base64 60 | tr -d '\\n')\" >> .env\necho \"AUTHENTIK_ERROR_REPORTING__ENABLED=false\" >> .env\n```\nAdjust `AUTHENTIK_EMAIL__*` if you want email notifications.",{"title":144,"body":145},"Start the stack","```bash\ndocker compose pull\ndocker compose up -d\n```\nThe first start applies PostgreSQL migrations and may take one to two minutes. Follow the logs with `docker compose logs -f worker`.",{"title":147,"body":148},"Access the administration interface","Open `http:\u002F\u002F\u003Cvps-ip>:9000\u002Fif\u002Fflow\u002Finitial-setup\u002F` to create the initial administrator account. Then point your domain (`sso.yourdomain.com`) to the server and configure the reverse proxy to terminate TLS.",{"title":150,"body":151},"Create your first OIDC application","In the administration interface, go to **Applications → Create** then **Providers → OAuth2\u002FOpenID**. Fill in the redirect URL of your client application, copy the generated `Client ID` and `Client Secret`, and configure your application with Authentik's OIDC endpoints (`\u002Fapplication\u002Fo\u002F\u003Cslug>\u002F.well-known\u002Fopenid-configuration`).",{"type":153,"title":154,"body":155},"tip","Using both in parallel","The most common combination on a well-loaded VPS: Authelia protects internal tools without OIDC support (legacy Grafana, Portainer, home dashboards) via the reverse proxy, and Authentik plays the OIDC IdP role for applications that delegate their authentication. Both can coexist on the same server and share the same PostgreSQL if the databases are isolated. Authelia can even be configured to delegate authentication to Authentik via OIDC — you thus get Authelia's lightness as a gateway and Authentik's richness as an identity source.",{"type":38,"title":157,"body":158},"Security and attack surface","Authelia's attack surface is structurally smaller: less code, no exposed administration interface (configuration is a local file), no SAML support, no LDAP. Authelia's historical CVE record is consequently shorter than Authentik's.\n\nAuthentik exposes more: a full web interface, a flow engine, several authentication protocols, a REST API and outposts. Each additional surface is a surface to maintain and monitor. Authentik's support policy covers the current version and the previous one — beyond that, security fixes are not backported.\n\nIn both cases, best practices are the same: do not expose the administration port directly on the internet, use a valid TLS certificate on the authentication subdomain, enable MFA for all administration accounts, and keep Docker images up to date by tracking releases. Authentik publishes releases approximately every three months; Authelia publishes fixes more frequently (biweekly cadence in 2026).",{"type":38,"title":160,"body":161},"Which VPS for each tool","For **Authelia alone**, a VPS with 1 to 2 GB of RAM is more than sufficient, even if you run several other services in parallel. Authelia does not justify a dedicated server.\n\nFor **Authentik**, the reasonable minimum in production is 2 GB of RAM dedicated to the Authentik stack (worker + PostgreSQL). If Authentik shares the VPS with other applications, plan for 4 GB minimum. For deployments with several hundred active users, the required resources increase proportionally with database usage.\n\nA ServOrbit VPS with 2 vCPU and 4 GB of RAM comfortably covers Authentik in production, with headroom for the applications it protects. The **Authentik** Marketplace template on Dolibarr, n8n, Nextcloud, Open WebUI, WooCommerce, WordPress configures the Docker stack with PostgreSQL, environment variables and the nginx reverse proxy in a single command.","Deploy your self-hosted SSO on a dedicated VPS","A ServOrbit VPS with root access, dedicated IPv4 and pre-configured Docker gives you the foundation to run Authentik or Authelia in production. Choose the resources suited to your stack and scale vertically on demand.","See Cloud VPS","\u002Fvps-cloud",[167,190,207],{"id":168,"slug":169,"slugs":170,"title":174,"excerpt":175,"readTime":176,"views":177,"isPinned":19,"publishedAt":178,"updatedAt":179,"category":180,"categories":186,"featuredImage":29,"bgImage":30,"posterImage":188,"relatedSolution":189},272,"authentik-authelia-or-keycloak-choosing-your-sso-on-vps",{"fr":171,"en":169,"ar":172,"es":173},"authentik-vs-authelia-keycloak-sso-vps-2026","authentik-أو-authelia-أو-keycloak-اختيار-sso-على-vps","authentik-authelia-o-keycloak-elegir-sso-en-vps","Authentik, Authelia or Keycloak: Choosing Your SSO on VPS","Authentik, Authelia or Keycloak on VPS: compare real memory footprint, covered protocols and Keycloak 26.7.1 CVEs to choose the right self-hosted SSO.",6,1,"2026-08-16T00:00:00+00:00","2026-09-07T11:26:10+00:00",{"id":181,"name":182,"slug":183,"color":184,"icon":185},8,"Security & Monitoring","securite-monitoring","bg-rose-500\u002F10 text-rose-400","security",[187],{"id":181,"name":182,"slug":183,"color":184,"icon":185},"\u002Fblog\u002Fcovers\u002Fauthentik-vs-authelia-keycloak-sso-vps-2026-poster.svg",{"categorySlug":33,"appSlug":34},{"id":191,"slug":192,"slugs":193,"title":197,"excerpt":198,"readTime":199,"views":18,"isPinned":19,"publishedAt":200,"updatedAt":201,"category":202,"categories":203,"featuredImage":29,"bgImage":30,"posterImage":205,"relatedSolution":206},192,"self-host-authentik-on-a-vps-open-source-auth0-alternative",{"fr":194,"en":192,"ar":195,"es":196},"self-host-authentik-vps","استضافة-authentik-على-vps-بديل-auth0-مفتوح-المصدر","alojar-authentik-en-un-vps","Self-Host Authentik on a VPS: Open-Source Auth0 Alternative","Deploy Authentik on a ServOrbit VPS for a full IdP (OIDC, SAML 2.0, passkeys, visual flows) to unify authentication across your entire self-hosted stack.",4,"2026-07-26T00:00:00+00:00","2026-09-11T11:34:11+00:00",{"id":181,"name":182,"slug":183,"color":184,"icon":185},[204],{"id":181,"name":182,"slug":183,"color":184,"icon":185},"\u002Fblog\u002Fcovers\u002Fself-host-authentik-vps-poster.svg",{"categorySlug":185,"appSlug":34},{"id":208,"slug":209,"slugs":210,"title":214,"excerpt":215,"readTime":216,"views":217,"isPinned":19,"publishedAt":218,"updatedAt":219,"category":220,"categories":221,"featuredImage":29,"bgImage":30,"posterImage":223,"relatedSolution":224},162,"self-host-authelia-on-a-vps-mfa-and-sso-for-your-whole-stack",{"fr":211,"en":209,"ar":212,"es":213},"self-host-authelia-vps","استضافة-authelia-على-vps-مصادقة-ثنائية-ودخول-موحد-لمنظومتك","alojar-authelia-en-un-vps","Self-hosting Authelia on a VPS: MFA and SSO for your entire stack","Deploy Authelia on a VPS with Docker Compose: TOTP, WebAuthn\u002Fpasskey, OIDC, LLDAP migration, Prometheus monitoring, and comparison with Authentik.",10,3,"2026-07-04T00:00:00+00:00","2026-09-24T12:27:51+00:00",{"id":181,"name":182,"slug":183,"color":184,"icon":185},[222],{"id":181,"name":182,"slug":183,"color":184,"icon":185},"\u002Fblog\u002Fcovers\u002Fself-host-authelia-vps-poster.svg",{"categorySlug":185,"appSlug":225},"authelia",1791502566976]