Authelia logo

Authelia

Self-hosted authentication server with TOTP, WebAuthn, and SSO

23k Go Apache-2.0 1 month ago

Overview

Authelia is an open-source authentication and authorization server that acts as a companion to reverse proxies like Nginx or Traefik, providing two-factor authentication and single sign-on for self-hosted applications. While primarily an identity gateway rather than a password vault, it manages user credentials, TOTP secrets, and WebAuthn device registrations centrally. Teams use it as the authentication backbone that other self-hosted tools integrate with.

Where it falls short of 1Password

  • Not a password vault; does not store or generate passwords for websites
  • Requires a reverse proxy to function; no standalone mode
  • LDAP/AD integration configuration is complex for non-enterprise users

We list the gaps honestly so you can decide if the trade-off is worth owning your data.

Tags

2fa
sso
webauthn
reverse-proxy
Maintain Authelia?

Claim this listing to keep it accurate, add a deploy template, or feature it on relevant pages.

Show off your self-host difficulty score

Embed the Authelia difficulty badge in your README — it links back here.

Self-host difficulty badge← add this to your README
[![Self-host difficulty](https://openreplace.com/api/badge/authelia)](https://openreplace.com/authelia)

Similar open-source projects

Other self-hostable tools in the same space worth comparing.

Lightweight Bitwarden-compatible server written in Rust, perfect for self-hosting

63k Rust AGPL-3.0 22 days ago
2/5
Authelia vs Vaultwarden

Open-source secrets management platform for developers and teams

27k TypeScript MIT 5 days ago
3/5
Authelia vs Infisical

Encrypt files in Git with KMS/age/PGP — secrets management without a server

22k Go MPL-2.0 5 days ago
1/5
Authelia vs SOPS

Official open-source server for the Bitwarden password manager

19k C# AGPL-3.0 5 days ago
3/5
Authelia vs Bitwarden Server