Authelia
Authelia is an open source authentication and authorization server providing multi-factor authentication and single sign-on for applications behind a reverse proxy. It supports OpenID Connect 1.0, OAuth 2.0, TOTP, WebAuthn, and Duo Push as authentication methods. Authelia exposes a REST API documented with an OpenAPI specification and integrates with nginx, Traefik, Caddy, and other reverse proxies.
Authelia publishes 2 APIs on the APIs.io network: Discovery API and OIDC API. Tagged areas include Authentication, Authorization, LDAP, MFA, and Open Source.
Authelia’s developer surface includes authentication, documentation, changelog, support, and 7 more developer resources.
Kin Score
APIs 3
Individual APIs this provider publishes, each with its own machine-readable definition.
Authelia OpenID Connect 1.0 Provider
Authelia acts as an OpenID Certified OpenID Connect 1.0 Provider supporting Authorization Code, Implicit, and Hybrid flows with PKCE, PAR, and various token endpoint authenticat...
Authelia Discovery API
Well-known discovery endpoints.
Authelia OIDC API
OpenID Connect 1.0 / OAuth 2.0 provider endpoints.
Open Collections 1
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
Authelia OpenID Connect 1.0 Endpoints
OPEN COLLECTIONPricing Plans 1
Published pricing tiers and plan structures.
Rate Limits 1
Documented rate limits and quota policies.
Authelia Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Authelia Finops
FINOPSFeatures 7
Notable capabilities this provider offers.
Multi-Factor Authentication
Supports TOTP, WebAuthn/FIDO2, Duo Push, and mobile authenticator apps as second factors.
OpenID Connect 1.0 Provider
OpenID Certified identity provider supporting Authorization Code, Implicit, and Hybrid flows.
Single Sign-On
Session-based SSO across all applications behind the reverse proxy with configurable session lifetime.
LDAP/Active Directory Integration
User authentication against LDAP, Active Directory, and OpenLDAP directories with group-based access control.
Access Control Rules
Fine-grained access control policies based on domain, path, user, group, and network for precise authorization.
Reverse Proxy Integration
Native integration with nginx, Traefik, Caddy, HAProxy, Envoy, and Skipper via forward-auth and ExtAuthz endpoints.
Passwordless Authentication
Support for WebAuthn/FIDO2 passwordless login using hardware security keys and platform authenticators.
Scroll for all 7
Security Posture 2
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Scopes 1
OAuth scopes governing access to this provider's APIs.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Use Cases 4
What developers build with this provider.
Self-Hosted SSO
Deploy a self-hosted SSO solution for internal web applications and services without relying on cloud identity providers.
Homelab Security
Protect self-hosted homelab applications with MFA and access control without exposing them to the internet unprotected.
Small Business Identity
Provide centralized authentication for small business web applications using LDAP and access control policies.
OIDC Provider
Act as an OpenID Connect provider for applications requiring OAuth 2.0 and OIDC-based authentication flows.
Integrations 5
Pre-built integrations with other platforms and tools.
Nginx
Integration with nginx-based proxies including nginx, nginx-proxy-manager, and Swag via auth_request module.
Traefik
Native Traefik middleware integration via ForwardAuth for seamless authentication in Docker and Kubernetes environments.
Caddy
Caddy forward-auth integration for protecting applications behind the Caddy web server.
LDAP/Active Directory
User directory integration with LDAP, Active Directory, and FreeIPA for enterprise user management.
Helm
Official Helm chart available at the authelia/chartrepo GitHub repository for Kubernetes deployment.
Solutions 2
Packaged solutions this provider offers.
Self-Hosted Identity
Complete self-hosted identity and access management solution for privacy-conscious deployments.
Zero Trust Security
Enforce zero trust network access policies for internal applications with per-request authentication verification.
Resources
Documentation 1
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Build 2
SDKs, sample code, and the tooling you integrate with
Access & Security 3
Authentication, authorization, and security posture
Operate 3
Status, limits, changes, and where to get help
Company 1
The organization behind the API