authelia: Add SSO and Multi-Factor Authentication to Web Apps

Summary
Authelia is a self-hosted authentication and authorization server that protects web applications through reverse proxies. It provides SSO, configurable access rules, and multiple second-factor and passwordless authentication methods.
At a glance
- Language
- Go
- License
- Apache-2.0
- Stars
- 29.2k
- Forks
- 1.5k
- Added to OSRepos
- February 9, 2026
- Last analyzed
- October 3, 2026
Topics
Click on any tag to explore related repositories
Use at your own risk
OSRepos shares public repositories for knowledge and discovery only. Any installation, execution, configuration, or use of code from these repositories is the user's own responsibility. Always review the repository, source code, dependencies, licenses, and security implications before running or installing anything. OSRepos is not responsible for issues, damages, or losses resulting from third-party repositories.
Overview
Authelia is an authentication and authorization service for applications behind a reverse proxy. It gives users a central portal for signing in and lets administrators control which requests require authentication, while the proxy uses Authelia to allow, deny, or redirect access.
It is aimed at people operating their own web services, especially in Docker or Kubernetes environments. It can also provide OpenID Connect and OAuth 2.0 identity-provider capabilities. Authelia is not a reverse proxy itself, and deployment requires configuring it alongside a supported proxy and identity or user-storage setup.
Key Features
- Single sign-on and multi-factor authentication through a web portal.
- Second factors include WebAuthn security keys, time-based one-time passwords, and Duo push notifications.
- Passwordless authentication using WebAuthn passkeys.
- Fine-grained access rules based on criteria such as users, groups, subdomains, request paths, methods, and networks.
- OpenID Connect 1.0 and OAuth 2.0 identity-provider support. The project describes this offering as beta on its roadmap.
- Integrations with nginx, Traefik, Caddy, Skipper, Envoy, and HAProxy.
- Deployment options include containers, Kubernetes, packages, and static binaries.
Use Cases
- Home-lab operators can add a shared login and second-factor checks to self-hosted services behind a reverse proxy.
- Small infrastructure teams can apply different authentication policies to internal applications and endpoints.
- Kubernetes administrators can protect ingress-routed applications using supported ingress controllers or gateways.
- Application developers can use its OpenID Connect provider when they need an identity service for their applications, while accounting for its beta status.
Project Facts
- Language: Go
- License: Apache-2.0
- Stars: 29.2k
- Forks: 1.5k
- Topics: 2fa, authentication, docker, golang, kubernetes, ldap, mfa, multifactor, oauth2, openid-connect, passkeys, pqc, push-notifications, security, sso, sso-authentication, totp, two-factor, two-factor-authentication, webauthn
- Archived: No
Getting Started
Start with the Get Started Guide and the deployment documentation. Docker Compose examples are provided as starting points, but require customization before use. See the README for installation options and project details.
Alternatives
- docker-tinyauth: Tinyauth is a lightweight authentication middleware for reverse proxies, while Authelia offers broader SSO, access policies, and second-factor options.
Considerations
- Authelia works alongside a reverse proxy; it does not replace one. Proxy integration and application routing must be configured.
- It is security-sensitive infrastructure and should be protected and maintained carefully, even though the README says it is not directly exposed to the internet.
- The project warns that breaking changes may occur during active development. Pin a release version and review release notes before upgrading.
- OpenID Connect support is described as beta on the project roadmap.
- The lightweight Docker Compose example uses file-based user storage and SQLite, and the README cautions that this setup will not scale well.
Source repository
Open the original repository on GitHub.
17 counted GitHub visits
Related repositories
Similar repositories that may be relevant next.

e2a: Email API for Applications and AI Agents
September 29, 2026
e2a provides an email API and relay for applications and AI agents. It supports transactional sending, inbound mailboxes, and agent replies, with optional human review and hosted or Docker-based deployment.

router: Route AI Requests to the Best Model
September 28, 2026
weave-os/router is a Go proxy that routes AI requests across configured model providers, while accepting Anthropic, OpenAI, and Gemini API formats. It suits developers who want model choice and routing behind one endpoint, including agent and coding-tool users.

ksail: Create and Operate Kubernetes Clusters
September 27, 2026
KSail is a Go-based toolkit for creating and operating Kubernetes clusters across local, nested, and cloud providers. It brings provisioning, GitOps, secrets, cluster operations, and AI interfaces into one tool, for developers and platform teams who want a unified workflow.

Memoh: Give AI Agents Dedicated Cloud Computers
September 26, 2026
Memoh is a multi-agent platform that gives each agent an isolated, always-on workspace with a desktop, browser, network access, and long-term memory. Use your own API keys or host agents such as Claude Code and Codex, either in Memoh Cloud or on your own infrastructure.