Harden infrastructure security.

Authentik

Self-hosted Auth0 alternative — full IdP with OIDC, SAML, LDAP, passkeys and a visual flow editor.

1 GB (2 GB recommended) RAM 1 vCPU Port 9000 Available

Tech stack

DockerPythonPostgreSQL 16
Minimum RAM1 GB (2 GB recommended)
Minimum CPU1 vCPU
Default port9000
Compatible OSChoice of Linux distributions

Authentik is a full-stack, open-source Identity Provider (IdP) built in Python/Go (Apache 2.0, ~22 k GitHub stars, v2026.5). It gives you everything a modern identity platform needs: user management with a self-serve portal, OIDC/OAuth2, SAML 2.0, LDAP proxy, RADIUS, passkeys/WebAuthn, and a unique visual flow editor that lets you design any authentication journey without writing code.

Deployed on a ServOrbit VPS, Authentik replaces cloud-hosted services like Auth0, Okta and Azure AD for small teams and developers who want full sovereignty over their user data. The stack is intentionally lean: since v2025.10 it runs without Redis — just a PostgreSQL 16 database alongside two lightweight Python containers (server and worker). The admin console lets you create applications, define OIDC/SAML integrations, manage groups and permissions, and monitor every login event from one place.

With Authentik as your IdP, you can wire up Single Sign-On across your entire self-hosted stack — Gitea, Nextcloud, Mattermost, Grafana, Docmost — using OIDC in a few clicks. One login, one user directory, all your apps.

Key features

OIDC/OAuth2 provider — add SSO to any OIDC-compatible app in your stack with a single integration
SAML 2.0 IdP — integrate enterprise SaaS apps that require SAML without a paid identity vendor
LDAP proxy — expose your user directory via LDAP so legacy apps can authenticate against Authentik
Passkeys & WebAuthn — offer Touch ID, Face ID and FIDO2 hardware keys as second factor
Visual flow editor — design multi-step auth flows (MFA prompts, email verification, captcha) with a drag-and-drop canvas
Self-serve user portal — users manage their own password, MFA devices and social connections
Lean stack — PostgreSQL 16 + server + worker, no Redis since v2025.10, under 512 MB RAM at idle

When to use this solution?

1

Centralise logins across a self-hosted stack

Configure Authentik as an OIDC provider once and connect Gitea, Nextcloud, Mattermost, Docmost and Grafana. Users log in once and are automatically authenticated in every connected app. Revoke access for a departing team member in one place — no app-by-app cleanup.

2

Replace Auth0 or Okta in a SaaS product

Embed Authentik as the IdP behind your product's login flow using OIDC. You control the user database, the token lifetimes and the MFA policies. No per-MAU pricing, no vendor lock-in, no data leaving your infrastructure.

3

Add SSO and MFA to internal tools

Put Authentik in front of Grafana dashboards, Dockge admin panels or any internal web app. Define access policies per group, enforce passkey MFA for sensitive tools, and get a full audit log of every login and token event.

Deploy Authentik on your VPS

Guide optimized for ServOrbit Cloud VPS.

01

Order a ServOrbit VPS

A 2 GB RAM VPS on Ubuntu 24.04 is the recommended minimum. Authentik's server and worker idle under 400 MB, but PostgreSQL adds another 200 MB and the admin UI can spike during heavy use. A domain name is required — OIDC callbacks and session cookies need HTTPS with a valid FQDN.

02

Point your subdomain

Create an A record pointing your chosen subdomain (e.g. auth.yourdomain.com) to the VPS IP. The ServOrbit reverse proxy handles TLS automatically with Let's Encrypt via DNS-01.

03

Deploy Authentik from the marketplace

Select Authentik in the ServOrbit Marketplace. The provisioning job deploys the Compose stack (PostgreSQL 16 + server + worker), generates the secret key and admin password, and starts the service. The admin console is available at https://auth.yourdomain.com/if/admin/ within 60–90 seconds.

04

Log in and create your first application

Sign in as akadmin with the password set during deployment. Go to **Applications → Providers** and create an OIDC provider for your first app (Gitea, Nextcloud, etc.). Copy the Client ID and Secret to the app's OAuth settings, set the redirect URI, and save. SSO is live.

05

Enrol MFA and invite users

In **Directory → Users**, create accounts for your team or configure an LDAP/SCIM import. Under **Flows → Enrollment**, design your MFA flow: add a WebAuthn stage for passkeys or a TOTP stage for authenticator apps. Users complete enrolment through the self-serve portal on their first login.

Frequently asked questions

Authelia is a lightweight forward-auth proxy that sits in front of your apps and adds MFA without touching them — it has no user management console and stores sessions in Redis. Authentik is a full Identity Provider with its own user directory, admin console, OIDC/SAML/LDAP support and a visual flow editor. Use Authelia to quickly add MFA to existing apps; use Authentik when you need a proper IdP with user lifecycle management and SSO.

Harden infrastructure security.

Activate Authentik on your infrastructure.

Dedicated Cloud VPS — IPv4 included, European datacenter, support included. Your data never leaves your server.

Recommended configuration: 1 GB (2 GB recommended) RAM · 1 vCPU

Need help?

Browse our help center and FAQ, or write to our team — support in French, English and Arabic.