Authelia
Single sign-on and two-factor portal for your own services
What is Authelia?
Authelia sits in front of your self-hosted apps and requires visitors to authenticate once, then lets them through to everything behind it. It supports one-time passwords, WebAuthn security keys and push approval, with per-rule policies so an internal dashboard can be wide open while an admin panel demands two factors. It integrates with common reverse proxies rather than replacing them.
Best for
Putting one login and second factor in front of many self-hosted apps
Why choose Authelia
Authelia solves the problem every self-hoster eventually hits: you have twenty small services, each with its own mediocre login, and you want one door with real two-factor authentication in front of all of them. It sits behind your reverse proxy and enforces a single sign-on portal, so services that never had proper auth — dashboards, admin panels, internal tools — become reachable only to people who have passed your rules. It is the difference between a hobby setup and something you can offer to your family without flinching.
Replaces
- Okta
- Auth0
- Google Workspace SSO
Key features
- Single sign-on across everything behind your reverse proxy
- TOTP, WebAuthn security keys and push-based second factors
- Fine-grained access rules per URL, user or group
- Works with Nginx, Traefik, Caddy and HAProxy
What to watch out for
This is infrastructure, and it has the failure mode infrastructure always has: if Authelia is down or misconfigured, everything behind it becomes unreachable, including the console you would use to fix it. The configuration is YAML-heavy and unforgiving about indentation and structure, and the learning curve for access rules is genuine. It also does not magically add authentication to applications — it gates access at the proxy layer, which means an app's own session handling can still surprise you.
How to deploy
- Docker
- Kubernetes
- Linux packages
Getting started
Read the entire example configuration before writing your own; copying a known-good file and editing three values beats composing YAML from the documentation. Configure the file-based user database first with one test account, get a single service behind it working end to end, and only then expand. Generate and store the encryption and session secrets properly — rotating them later logs everyone out. Most importantly, keep a bypass path: a direct route to the reverse proxy's admin interface, or physical access to the host, so a bad rule never locks you out of your own machine.
Typical setup
Authelia is nearly always deployed on the same machine as the reverse proxy it protects — Caddy, Traefik, Nginx or HAProxy — and configured as a forward-authentication endpoint or an access-control decision point. Redis backs the session state. A well-planned installation keeps one route deliberately outside the protection, usually the proxy's own admin interface or an SSH path, because the realistic failure mode of single sign-on is locking yourself out of the thing that fixes it.
Who should look elsewhere
Not suitable if you are the kind of user for whom any downtime is unacceptable and you have no appetite for YAML, because a misconfiguration here locks you out of everything at once. Teams that need enterprise identity features — directory sync, audit trails, a support contract — should look at commercial identity providers instead.
Project health
- GitHub stars: 29,150
- Last code push: 2026-10-01
- Open issues: 127
- Status: actively developed
Figures pulled from the GitHub API and refreshed periodically.