Authelia
Authelia is an open source authentication and authorization server providing multi-factor authentication and single sign-on for applications behind a reverse proxy. It supports OpenID Connect 1.0, OAuth 2.0, TOTP, WebAuthn, and Duo Push as authentication methods. Authelia exposes a REST API documented with an OpenAPI specification and integrates with nginx, Traefik, Caddy, and other reverse proxies.
Authelia publishes 13 APIs on the APIs.io network, including Authentication API, Authorization API, First Factor API, and 10 more. Tagged areas include Authentication, Authorization, LDAP, MFA, and Open Source.
Authelia’s developer surface includes authentication, documentation, changelog, support, CLI, API reference, getting-started guide, and 38 more developer resources.
Kin Score
APIs 13
Individual APIs this provider publishes, each with its own machine-readable definition.
Authelia OpenID Connect 1.0 Provider
Authelia acts as an OpenID Certified OpenID Connect 1.0 Provider supporting Authorization Code, Implicit, and Hybrid flows with PKCE, PAR, and various token endpoint authenticat...
Authelia Authentication API
Authentication endpoints
Authelia Authorization API
Authorization endpoints
Authelia First Factor API
First Factor Authentication
Authelia OAuth 2.0 API
OAuth 2.0 Endpoints
Authelia OpenID Connect 1.0 API
OpenID Connect 1.0 Endpoints
Authelia Password Change API
Password change endpoint
Authelia Password Reset API
Password reset endpoints
Authelia Second Factor API
TOTP, WebAuthn and Duo endpoints
Authelia State API
Configuration, health and state endpoints
Authelia User Elevation API
User session elevation endpoints
Authelia User Information API
User configuration endpoints
Authelia Utilities API
General utilities used in several operations
Scroll for all 13
Open Collections 4
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
API Collection
OPEN COLLECTIONAuthelia OpenID Connect 1.0 Endpoints Discovery API
OPEN COLLECTIONAuthelia OpenID Connect 1.0 Endpoints Discovery OIDC API
OPEN COLLECTIONAuthelia OpenID Connect 1.0 Endpoints
OPEN COLLECTIONPricing Plans 1
Published pricing tiers and plan structures.
Rate Limits 1
Documented rate limits and quota policies.
Authelia Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Authelia Finops
FINOPSFeatures 7
Notable capabilities this provider offers.
Multi-Factor Authentication
Supports TOTP, WebAuthn/FIDO2, Duo Push, and mobile authenticator apps as second factors.
OpenID Connect 1.0 Provider
OpenID Certified identity provider supporting Authorization Code, Implicit, and Hybrid flows.
Single Sign-On
Session-based SSO across all applications behind the reverse proxy with configurable session lifetime.
LDAP/Active Directory Integration
User authentication against LDAP, Active Directory, and OpenLDAP directories with group-based access control.
Access Control Rules
Fine-grained access control policies based on domain, path, user, group, and network for precise authorization.
Reverse Proxy Integration
Native integration with nginx, Traefik, Caddy, HAProxy, Envoy, and Skipper via forward-auth and ExtAuthz endpoints.
Passwordless Authentication
Support for WebAuthn/FIDO2 passwordless login using hardware security keys and platform authenticators.
Scroll for all 7
JSON Schema 5
Standalone JSON Schema definitions for this provider's data models.
Authelia Configuration.Schema
JSON SCHEMAAuthelia Exports.Identifiers.Schema
JSON SCHEMAAuthelia Exports.Totp.Schema
JSON SCHEMAAuthelia Exports.Webauthn.Schema
JSON SCHEMAAuthelia User Database.Schema
JSON SCHEMASecurity Posture 3
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Scopes 1
OAuth scopes governing access to this provider's APIs.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Use Cases 4
What developers build with this provider.
Self-Hosted SSO
Deploy a self-hosted SSO solution for internal web applications and services without relying on cloud identity providers.
Homelab Security
Protect self-hosted homelab applications with MFA and access control without exposing them to the internet unprotected.
Small Business Identity
Provide centralized authentication for small business web applications using LDAP and access control policies.
OIDC Provider
Act as an OpenID Connect provider for applications requiring OAuth 2.0 and OIDC-based authentication flows.
Integrations 5
Pre-built integrations with other platforms and tools.
Nginx
Integration with nginx-based proxies including nginx, nginx-proxy-manager, and Swag via auth_request module.
Traefik
Native Traefik middleware integration via ForwardAuth for seamless authentication in Docker and Kubernetes environments.
Caddy
Caddy forward-auth integration for protecting applications behind the Caddy web server.
LDAP/Active Directory
User directory integration with LDAP, Active Directory, and FreeIPA for enterprise user management.
Helm
Official Helm chart available at the authelia/chartrepo GitHub repository for Kubernetes deployment.
Solutions 2
Packaged solutions this provider offers.
Self-Hosted Identity
Complete self-hosted identity and access management solution for privacy-conscious deployments.
Zero Trust Security
Enforce zero trust network access policies for internal applications with per-request authentication verification.
Resources
Get Started 1
Portal, sign-up, and the first successful call
Documentation 8
Reference material describing how the API behaves
Scroll for all 8
Agent Surfaces 4
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 6
Pagination, idempotency, versioning, errors, and events
Build 5
SDKs, sample code, and the tooling you integrate with
Access & Security 7
Authentication, authorization, and security posture
Scroll for all 7
Operate 8
Status, limits, changes, and where to get help
Scroll for all 8
Commercial 3
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API
Other 1
Properties that don't map to a standard resource type
Source (apis.yml)
Work with this as data
Every provider here is available over the APIs.io API and to AI agents over MCP.