Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
authelia — The Single Sign-On Multi-Factor portal for web apps. OpenID Certified™ and Post-Quantum Cryptography Ready. | Kitploit
Tools/GitHubGitHub/authelia/authelia
Authentication & AuthorizationIdentity ManagementNetwork Access ControlWeb SecurityIdentity & Access Management (IAM)AuthenticationTop in Authentication #4Top in Authentication & Authorization #7Top in Identity & Access Management (IAM) #7
28.5k1.5k1064h 48m agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Top in Identity Management #7
Top in Network Access Control #14
GitHubauthelia/authelia

authelia

The Single Sign-On Multi-Factor portal for web apps. OpenID Certified™ and Post-Quantum Cryptography Ready.

View RepositoryWebsite

Build Codecov OpenSSF Best Practices OpenSSF Scorecard SLSA 3 License Sponsor

GitHub Release Docker Tag Docker Size Docker Pulls AUR source version AUR binary version AUR development version

Discord Matrix

Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for your applications via a web portal. It acts as a companion for reverse proxies by allowing, denying, or redirecting requests.

Documentation is available at https://www.authelia.com/.

The following is a simple diagram of the architecture:

Authelia can be installed as a standalone service from the AUR, APT, FreeBSD Ports, or using a static binary, .deb package, as a container on Docker or Kubernetes.

Deployment can be orchestrated via the Helm Chart (beta) leveraging ingress controllers and ingress configurations.

Here is what Authelia's portal looks like:

Features summary

This is a list of the key features of Authelia:

  • OpenID Connect 1.0 / OAuth 2.0
  • Post-Quantum Cryptography
  • Several second factor methods:
    • Security Keys that support FIDO2 WebAuthn with devices like a YubiKey.
    • Time-based One-Time password with compatible authenticator applications.
    • Mobile Push Notifications with Duo.
  • Passwordless Authentication via WebAuthn (Passkeys)
  • Password reset with identity verification using email confirmation.
  • Access restriction after too many invalid authentication attempts.
  • Fine-grained access control using rules which match criteria like subdomain, user, user group membership, request uri, request method, and network.
  • Choice between one-factor and two-factor policies per-rule.
  • Support of basic authentication for endpoints protected by the one-factor policy.
  • Highly available using a remote database and Redis as a highly available KV store.
  • Compatible with Traefik out of the box using the ForwardAuth middleware.
  • Curated configuration from LinuxServer via their SWAG container as well as a guide.
  • Compatible with Caddy using the forward_auth directive.
  • Kubernetes Support:
    • Compatible with several Kubernetes Ingress Controllers and Gateways:

For more details take a look at the Overview.

If you want to know more about the roadmap, follow Roadmap.

OpenID Connect 1.0 / OAuth 2.0

Authelia is OpenID Certified™ to the Basic OP / Implicit OP / Hybrid OP / Form Post OP / Config OP profiles of the OpenID Connect™ protocol. While this offering is still effectively on the roadmap as a beta it's very comprehensive and well implemented already, also allowing us comprehensive certification. Read more about the OpenID Certified™ status of Authelia in the OpenID Connect 1.0 Integration Guide.

Proxy support

Authelia works in combination with nginx, Traefik, Caddy, Skipper, Envoy, or HAProxy.

Getting Started

See the Get Started Guide or one of the curated examples below.

docker compose

The docker compose bundles act as a starting point for anyone wanting to see Authelia in action. You will have to customize them to your needs as they come with self-signed certificates.

Local

The Local compose bundle is intended to test Authelia without worrying about configuration. It's meant to be used for scenarios where the server is not be exposed to the internet. Domains will be defined in the local hosts file and self-signed certificates will be utilized.

Lite

The Lite compose bundle is intended for scenarios where the server will be exposed to the internet, domains and DNS will need to be setup accordingly and certificates will be generated through LetsEncrypt. The Lite element refers to minimal external dependencies; File based user storage, SQLite based configuration storage. In this configuration, the service will not scale well.

Deployment

Now that you have tested Authelia and you want to try it out in your own infrastructure, you can learn how to deploy and use it with Deployment. This guide will show you how to deploy it on bare metal as well as on Kubernetes.

Security

Authelia takes security very seriously. If you discover a vulnerability in Authelia, please see our Security Policy.

For more information about security related matters, please read the documentation.

Contact Options

Several contact options exist for our community, the primary one being Matrix. These are in addition to GitHub issues for creating a new issue.

Matrix

Community members are invited to join the Matrix Space which includes both the Support Room and the Contributing Room.

  • The core team members are identified as administrators in the Space and individual Rooms.
  • All channels are linked to Discord.

Discord

Community members are invited to join the Discord Server.

  • The core team members are identified by the CORE TEAM role in Discord.
  • The #support and #contributing channels are linked to Matrix.

Email

You can contact the core team by email via [email protected]. Please note the [email protected] is also available but is strictly reserved for security related matters.

Breaking changes

Since Authelia is still under active development, it is subject to breaking changes. It's recommended to pin a version tag instead of using the latest tag and reading the release notes before upgrading. This is where you will find information about breaking changes and what you should do to overcome said changes.

Why Open Source?

You might wonder why Authelia is open source while it adds a great deal of security and user experience to your infrastructure at zero cost. It is open source because we firmly believe that security should be available for all to benefit in the face of the battlefield which is the Internet, with near zero effort.

Additionally, keeping the code open source is a way to leave it auditable by anyone who is willing to contribute. This way, you can be confident that the product remains secure and does not act maliciously.

It's important to keep in mind Authelia is not directly exposed on the Internet (your reverse proxies are) however, it's still the control plane for your internal security so take care of it!

Contribute

If you want to contribute to Authelia, please read our contribution guidelines.

Authelia exists thanks to all the people who contribute so don't be shy, come chat with us on either Matrix or Discord and start contributing too.

Thanks goes to these 96 wonderful people (emoji key)

Clément Michaud Amir Zarrinkafsh James Elliott Antoine Favre BankaiNoJutsu Callan Bryant Ian FrozenDragoon vdot0x23 Sohalt Stoica Tedy Dylan Smith

📖 Documentation Overlords
and these 226 wonderful people who keep the documentation worth reading

Philipp Rintz somebody-somewhere-over-the-rainbow Lukas Klass James Hodgkinson Chris Smith Mihály Bereczki Silver Bullet Timo Andrew Kliskey Kristof Mattei

This project follows the all-contributors specification. Contributions of any kind welcome!

Sponsors

Help Wanted: We are actively looking for sponsorship to obtain either a code security audit, penetration testing, or other audits related to improving the security of Authelia.

Any company can become a sponsor by donating or providing any benefit to the project or the team helping improve Authelia.

JetBrains

Thank you to JetBrains JetBrains for providing us with free licenses to their great tools.

  • IDEA IDEA
  • GoLand GoLand
  • WebStorm WebStorm

Buildkite

Our pipeline agents rely on the Buildkite CI platform. This is an amazing product which allows us to use our own infrastructure to orchestrate complex and secure pipelines.

Open Collective

Backers

Thank you to all our backers! 🙏 Become a backer and help us sustain our community. The money we currently receive is dedicated to fund a security audit, and potentially in the future introducing a bug bounty program to give us as many eyes as we can to detect potential vulnerabilities.

Sponsorship

Companies contributing to Authelia via Open Collective will have a special mention below. Become a sponsor.

License

Authelia is licensed under the Apache 2.0 license. The terms of the license are detailed in LICENSE.

FOSSA Status

Download Tool
  • ingress-nginx
  • Traefik Kubernetes CRD
  • Traefik Kubernetes Ingress
  • Istio
  • Envoy Gateway
  • Beta support for installing via Helm using our Charts.
  • Philipp Staiger
    Paul Williams
    akusei
    Dustin Sweigart
    Shawn Haggard
    SootySec
    Valentin Höbel
    Mike Kusold
    TheCatLady
    Lauri Võsandi
    Kennard Vermeiren
    ThinkChaos
    Hasan
    Marcel Marquardt
    Jon B.
    Alex Gustafsson
    Arsenović Arsen
    dakriy
    Dave
    yossbg
    Justin Sievenpiper
    Andrew Moore
    Manuel Nuñez
    protvis74
    Jamie (Bear) Murphy
    Robin van Boven
    alphabet5
    Robert Meredith
    Adrian Gąsior
    James White
    Auzborn123
    SvanGlan
    andreas-berg
    Michał Mieszczak
    Stephen Kent
    levkoburburas
    Josh Gordon
    silasfrancisco
    Ricardo Pesqueira
    Brynn Crowley
    Hendrik Sievers
    Wang Weixuan
    Pierre Kisters
    peter
    Nick O'Connor
    Nikita Pedorich
    Andre Toerien
    erusc
    Kevin Cox
    Br1an
    deprrous
    Ricardo Rivera
    RDW
    Justin
    Mike
    Dominik Schmidt
    Shihta Kuan
    Toshaan Bharvani
    haowei
    Eng Zer Jun
    MBM
    Paul Calabro
    guoguangwu
    Webysther Sperandio
    Jacquet Corentin
    Michael Stapelberg
    fbird
    Dan
    curlwget
    DCsunset
    Jonas Geiler
    oliverpool
    tcx4c70
    feinedsquirrel
    GeistFighter
    GuiPoM
    Michel Heusschen
    bishtawi
    billcarsoon
    rowanarts
    Christian Franzl
    Yaroslav Halchenko
    Riccardo Padovani
    TowyTowy
    ZMiguel Valdiviesso
    Daniel Miller
    Kevyn Bruyere
    Max
    Victor
    Chris Whisker
    nasatome
    Begley Brothers (Development)
    Dimitris Zervas
    David Chidell
    Ian Gallagher
    Wu Han
    lavih
    Nicolas Reymundo
    polandy
    Michael Campbell
    Aram Akhavan
    Shadow
    Patrick Ruckstuhl
    Dennis Gaida
    Alestrix
    bgh-github
    Zhao Xiang Lim
    HannesJo0139
    Clément Radenac
    boomam
    Northguy
    Brennan Kinney
    Astrocephale
    Ohelig
    Dinh Bao Dang
    tiuub
    Harold
    Budiman Jojo
    Marcus Georgi
    samos667
    0xsysr3ll
    Dan
    Eyal Benaroche
    Dani
    Auston Pramodh Barboza
    Thomas Steinbach
    Steve-Brule
    Tom
    Andreas Brett
    FO
    Roman Krasilnikov
    tomaszduda23
    Louison SARLIN--MAGNUS
    AlexViridi
    Xabi
    Caio Silva
    jess
    Ikko Eltociear Ashimine
    Frederic Hemberger
    Georg Lauterbach
    contrun
    Dylan Drost
    shamoon
    Biel Frontera
    Karlos
    Lorenz Schmid
    Helvio Pedreschi
    otbutz
    Kieran
    Konstantin
    Andreas Brenk
    EDIflyer
    Will Scargill
    Jerry
    Garrett Webb
    Hugo
    Stanislas
    Constantin Kraft
    Philipp
    matvey00z
    Jacob Gee-Clarke
    Jonas Lewin
    Austin Alvarado
    Chris D
    electrofloat
    Krasimir Nedelchev
    James Hillyerd
    tetricky
    Trung Le
    Gelven
    Nico
    A. Stadler
    StephenRoille
    Lenard Hess
    Aamir Azad
    Hobbabobba
    NunoHiggs
    Marco Emilio "sphakka" Poleggi
    felixilgatto
    Edward Betts
    owine
    Erik
    Bob Du
    Kitof
    Alexander Henderson
    Clay Rosenthal
    Bence Csik
    jeblove
    noantiq
    Tchoupinax
    Florian Gebhardt
    Ludovic
    Felix Stein
    Jérémy Viès
    John Nicholls
    thielj
    Carlos Eduardo Magalhães
    Sam
    Chris Paganon
    krair
    cuiweiyuan
    andoks
    m4rc3l-h3
    showipintbri
    TheRedCyclops
    Alex
    Clément Bourgeois
    deanrock
    Laurent Desgrange
    Roman
    jfoxwoosh
    Loe
    Roi Gabay
    svartoyg
    axel simon
    Robert Deppe
    Mad Scientist
    Karl Woditsch
    Bram
    Emmanuel Ferdman
    Mark Adkins
    Maximilian Brueckl
    Sylvain CECCHETTO
    Matt Tyree
    Lee
    npondel
    Jasper Wiegratz
    Diogo Correia
    pizzapim
    AbelLykens
    David Pertiller
    gensyn
    rm76
    Allen
    Florian Kretschmer
    Minei3oat
    Euler Alves
    Mattias
    Stein Petter Tokvam
    Tomasz Rzymyszkiewicz
    Ganesh Bhambarkar
    Lucas Dooms
    polgarc
    Keunes
    Mohamed
    Christoph Schug
    yieldhog
    Callum Parkinson
    Fredrik Ekre
    arcoast
    Jim Angel
    Maximilian Homann
    Viki
    timbretimber
    grasshide
    Matt Moriarity
    Yash Garg
    Christian Koepp
    Wobak
    f0sh
    Scott
    thesyntaxslinger
    Peter Teixeira
    Lenz Filipski
    Gene Wood
    Allexio
    Rachel
    sohnemann
    James
    mayswind
    Mateusz P-K
    Arnaud Lemaire
    Michał R
    spomata
    Sander Lambrechts
    moedtm
    Kiara
    Ell
    Gyula Kerezsi
    Matt Norton
    Ishan Jain
    Bradley Wong
    Nicolas Mémeint
    Tanguy BAUDRIN
    turtleinarock
    Andrew Rylatt
    dubwoc
    Samuel-BF
    Matt Van Horn
    James Parkhurst
    Lil PhyziX
    Alvinwylim
    Denny Schäfer
    mrrudy
    Samuele
    David
    Eugene
    Christoph Wagner
    Helge Klein
    Dennis