Authelia
Open-source IAM platform and OpenID Certified OpenID Connect 1.0 provider. Modern, flexible authentication and authorization.
Overview
The Single Sign-On Multi-Factor portal for web apps, now OpenID Certified™ Authelia is a free and open-source IAM platform and OpenID Certified™ OpenID Connect 1.0 provider; providing modern, flexible authentication and authorization. The project has 27K+ GitHub stars and is licensed under Apache-2.0.
Key Features
Source: GitHub README
- OpenID Connect 1.0 / OAuth 2.0
- Several second factor methods:
- Security Keys that support
- Time-based One-Time password
- Mobile Push Notifications
- Passwordless Authentication via WebAuthn (Passkeys)
- Password reset with identity verification using email confirmation.
- Access restriction after too many invalid authentication attempts.
- Fine-grained access control using rules which match criteria like subdomain, user, user group membership, request uri,
- Choice between one-factor and two-factor policies per-rule.
Getting Started
Source: GitHub README
See the Get Started Guide or one of the curated examples below.
Normalized Features
Source: tool-features-normalized.json
docker, docker compose, helm, kubernetes, redis, sqlite, sso, two factor auth.
Deploy
Features
Authentication & Access
- Single Sign-On (SSO)
- Two-Factor Authentication
Replaces
Compare Authelia
Both are security tools. Authelia has 4 unique features, Casdoor has 2.
Both are security tools. Authelia has 4 unique features, Ory has 2.
Both are security tools. Authelia has 4 unique features, Teleport has 4.
Both are security tools. Authelia has 3 unique features, Authentik has 1.
Both are security tools. Authelia has 4 unique features, ORY has 2.
Both are security tools. Authelia has 5 unique features, Vaultwarden has 3.
Both are security tools. Authelia has 3 unique features, VoidAuth has 1.
Related Security & Authentication Tools
View all 159 →Ghidra
66KA free, open-source software reverse engineering framework created by the NSA — disassemble, decompile, and analyze compiled code on any platform.
PocketBase
58KOpen-source backend in a single 12 MB binary — realtime database, auth, file storage, and admin dashboard. No Docker, no Postgres, just run it.
Vaultwarden
57KLightweight, self-hosted Bitwarden-compatible password manager written in Rust. Uses 10x less RAM than the official server and works with all Bitwarden clients.
Zen Browser
41KZen Browser is a privacy-focused, beautifully designed Firefox fork with a unique sidebar tab layout, split views, and built-in content blocking — no telemetry, no tracking.
Vault
35KManage secrets and protect sensitive data. Securely store and control access to tokens, passwords, certificates, and encryption keys.
KeyCloak
33KOpen source identity and access management. Add authentication to applications and secure services with minimum effort.