[ ][Apache 2.0] Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for your applications via a web portal. It acts as a companion…









!Docker Pulls



![License][Apache 2.0]



Authelia is an open-source authentication and authorization server providing two-factor authentication and single
sign-on (SSO) for your applications via a web portal. It acts as a companion for [reverse proxies](#proxy-support) by
allowing, denying, or redirecting requests.
Documentation is available at https://www.authelia.com/.
The following is a simple diagram of the architecture:
Authelia can be installed as a standalone service from the AUR,
APT,
FreeBSD Ports, or using a
static binary,
.deb package, as a container on [Docker] or [Kubernetes].
Deployment can be orchestrated via the Helm Chart (beta) leveraging ingress controllers
and ingress configurations.
Here is what Authelia's portal looks like:
Features summary
This is a list of the key features of Authelia:
- [OpenID Connect 1.0 / OAuth 2.0](#openid-connect-10--oauth-20)
- Several second factor methods:
- Passwordless Authentication via WebAuthn (Passkeys)
- Password reset with identity verification using email confirmation.
- Access restriction after too many invalid authentication attempts.
- Fine-grained access control using rules which match criteria like subdomain, user, user group membership, request uri,
- Choice between one-factor and two-factor policies per-rule.
- Support of basic authentication for endpoints protected by the one-factor policy.
- Highly available using a remote database and Redis as a highly available KV store.
- Compatible with Traefik out of the box using the
- Curated configuration from LinuxServer via their
- Compatible with [Caddy] using the forward_auth
- Kubernetes Support:
For more details take a look at the Overview.
If you want to know more about the roadmap, follow Roadmap.
OpenID Connect 1.0 / OAuth 2.0
Authelia is [OpenID Certified™] to the Basic OP / Implicit OP / Hybrid OP / Form Post OP / Config OP profiles of the
[OpenID Connect™ protocol]. While this offering is still effectively
on the roadmap as a beta it's very comprehensive and well
implemented already, also allowing us comprehensive certification. Read more about the
[OpenID Certified™] status of Authelia in the
OpenID Connect 1.0 Integration Guide.
Proxy support
Authelia works in combination with [nginx], [Traefik], [Caddy], [Skipper], [Envoy], or [HAProxy].
Getting Started
See the Get Started Guide or one of the curated examples
below.
docker compose
The docker compose bundles act as a starting point for anyone wanting to see Authelia in action. You will have to
customize them to your needs as they come with self-signed certificates.
####
…
Members
-
authelia ★ PINNED
The Single Sign-On Multi-Factor portal for web apps, now OpenID Certified™
Go ★ 28k 1d agoExplain → -
chartrepo
Authelia Helm Charts
Go Template ★ 105 2mo agoExplain → -
oidc-tester-app
App implementing OpenID Connect used for testing purpose with Authelia
Go ★ 13 1d agoExplain → -
oauth2-provider
Authelia OAuth 2.0 Framework (Provider Role)
Go ★ 8 1d agoExplain → -
gox ⑂ ▣
A dead simple, no frills Go cross compile tool
Go ★ 6 11mo agoExplain → -
buildkite
No description.
Dockerfile ★ 5 19d agoExplain → -
pam
Authelia PAM (Pluggable Authentication Module)
Go ★ 3 2mo agoExplain → -
oauth2-client
Authelia OAuth 2.0 Framework (Client Role)
Go ★ 3 1y agoExplain → -
ac
Authelia CLI
Go ★ 3 1y agoExplain → -
crossbuild ⑂
:earth_africa: multiarch cross compiling environments
Dockerfile ★ 2 2mo agoExplain → -
otp ⑂
TOTP library for Go
Go ★ 1 1d agoExplain → -
baseimage
Authelia base glibc container
Shell ★ 1 19d agoExplain → -
session
Session implementation for fasthttp
Go ★ 1 2y agoExplain → -
apt
Authelia APT repository
★ 0 2mo agoExplain → -
test-flows
test
★ 0 6mo agoExplain → -
debpackager ▣
No description.
Shell ★ 0 1y agoExplain → -
aurpackager
No description.
Shell ★ 0 1y agoExplain → -
chart-releaser ⑂
Hosting Helm Charts via GitHub Pages and Releases
Go ★ 0 11mo agoExplain → -
zap ⑂
Blazing fast, structured, leveled logging in Go.
Go ★ 0 11mo agoExplain → -
jsonschema ⑂
Generate JSON Schemas from Go types
Go ★ 0 11mo agoExplain →
No repos match these filters.