Authelia
Apache-2.0 open-source authentication and authorization server that adds SSO, two-factor and passkey login and access-control rules in front of applications via reverse proxies, and acts as an OpenID Connect 1.0 provider.
Quick answer
What is Authelia?
Short answer
Authelia is "an open-source authentication and authorization server and portal fulfilling the identity and access management (IAM) role" that "acts as a companion for common reverse proxies": Traefik, NGINX, Caddy, HAProxy, Envoy, SWAG, NGINX Proxy Manager and Skipper. It provides single sign-on via a session cookie, second factors including one-time passwords, security keys and passkeys (WebAuthn) and Duo/mobile push, granular access-control policies, login regulation against brute force, and an OpenID Connect 1.0 provider. Users come from LDAP (OpenLDAP, OpenDJ, FreeIPA, Microsoft Active Directory) or a YAML file; storage supports PostgreSQL, MySQL and SQLite3. Written in Go and React, it targets a container under 20 MB and memory under 30 MB, and deploys on Docker, Kubernetes or bare metal in high-availability configurations. Licensed Apache 2.0 with about 29k GitHub stars; no commercial edition is offered.
- Best for
- Self-hosters, homelabs and small platform teams that want free SSO and 2FA in front of web apps behind an existing reverse proxy.
- When to choose
- You run apps behind a reverse proxy, want zero-cost SSO, 2FA and OIDC, and are comfortable operating it yourself.
- When not to choose
- You need commercial support, SCIM or lifecycle management, a managed service, or an IdP for thousands of workforce users.
- Related tools & categories
- OryZitadelRun the IAM Stack FinderReport: The State of AI Agent Identity 2026
Categories
Common use cases
- Adding 2FA and SSO to self-hosted web apps behind Traefik, NGINX or Caddy
- Acting as an OpenID Connect provider for internal services
- Enforcing per-domain and per-path access rules by user or group
- Protecting admin dashboards on homelab and small-business servers
Strengths
- Free, Apache-2.0 licensed with a large community (about 29k GitHub stars)
- Lightweight Go binary: sub-20 MB container and sub-30 MB typical memory
- Supports TOTP, WebAuthn passkeys and security keys, and Duo push as second factors
- Works with most popular reverse proxies and LDAP or Active Directory backends
Limitations & considerations
- No vendor, SLA or paid support; community-supported only
- Requires a reverse proxy and, for LDAP, an external directory; the only built-in user store is a YAML file
- No hosted or SaaS option; you operate the database, session store and SMTP notifier
- Narrow scope versus full IdPs: no user lifecycle, SCIM or admin UI for user management
Pricing model summary
Free and open source (Apache 2.0). No paid tiers, hosted edition or commercial support offering are listed by the project.
Integrations
Fit
Alternatives & comparisons
Open source identity, authorization and zero trust stack (Kratos, Hydra, Keto, Oathkeeper) available self-hosted or as Ory Network SaaS.
Compare Authelia vs Ory →Open source identity and access platform with built-in multi-tenancy, SSO, MFA and a managed Zitadel Cloud SaaS.
Compare Authelia vs Zitadel →FusionAuth is a comprehensive authentication and user management platform offering flexible deployment (self-hosted, private cloud, or FusionAuth Cloud), developer-friendly APIs, and broad feature coverage including SSO, MFA, SAML, OIDC, and multi-tenancy.
Compare Authelia vs FusionAuth →Keycloak is the most widely deployed open source IAM platform, providing enterprise-grade SSO, MFA, SAML, OIDC, LDAP, and Kerberos support in a self-hosted, Apache 2.0 licensed package maintained by Red Hat.
Compare Authelia vs Keycloak →Related glossary terms
Key identity & access terms relevant to Authelia.
Authelia and its logo are trademarks of their respective owner. IDSync is an independent buyer resource and does not imply endorsement unless explicitly stated.
