Authentik website screenshot

Authentik

Authentik is an open source identity provider with a comprehensive REST API for managing users, groups, flows, providers, sources, policies, and outposts. It supports OAuth2, OIDC, SAML, LDAP, SCIM, and RADIUS protocols with official client SDKs in TypeScript, Python, Go, Rust, Kotlin, and Swift.

Authentik publishes 10 APIs on the APIs.io network, including Core API, Crypto API, Events API, and 7 more. Tagged areas include Authentication, Authorization, Identity Provider, LDAP, and OAuth.

Authentik’s developer surface includes authentication, documentation, changelog, support, pricing, engineering blog, and 8 more developer resources.

41.8/100 thin ▬ flat Agent 31/100 agent aware Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessFreemiumSelf serve⚡ Free to try
10 APIs 7 Features 4 Use Cases
AuthenticationAuthorizationIdentity ProviderLDAPOAuthOpen SourceOpenID ConnectSAMLSCIMSelf-Hosted

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 41.8/100 · thin
Contract Quality 12.3 / 25
Developer Ergonomics 5.2 / 20
Commercial Clarity 10.0 / 20
Operational Transparency 6.8 / 13
Governance 0.0 / 12
Discoverability 7.4 / 10
Agent readiness — 31/100 · agent aware
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/authentik: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 10

Individual APIs this provider publishes, each with its own machine-readable definition.

Authentik Core API

Users, applications, groups and tokens.

Authentik Crypto API

Certificate-key pairs.

Authentik Events API

Audit and notification events.

Authentik Flows API

Authentication and enrollment flows.

Authentik Policies API

Policies and policy bindings.

Authentik Providers API

OAuth2/OIDC, SAML, LDAP, Proxy and other providers.

Authentik RBAC API

Role-based access control.

Authentik Schema API

Self-describing OpenAPI schema.

Authentik Sources API

External identity sources.

Authentik Stages API

Flow stages (identification, password, etc.).

Scroll for all 10

Open Collections 1

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

authentik API

OPEN COLLECTION

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Authentik Rate Limits

5 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Features 7

Notable capabilities this provider offers.

Comprehensive REST API

Full REST API covering all authentik features with built-in Swagger UI at /api/v3/ on every instance.

Multi-Protocol Support

Native support for OAuth2, OIDC, SAML, LDAP, SCIM, RADIUS, and SSTP protocols for broad integration coverage.

Flow Engine

Customizable authentication and enrollment flows with visual flow designer for configuring multi-step authentication processes.

Multi-Language SDKs

Official API client SDKs in TypeScript, Python, Go, Rust, Kotlin, and Swift auto-generated from the OpenAPI schema.

Terraform Provider

Official Terraform provider for infrastructure-as-code management of authentik resources.

Helm Deployment

Official Helm chart for Kubernetes deployment with configurable replicas, persistence, and external database support.

RBAC

Role-based access control for granular permission management across authentik resources and administrative functions.

Scroll for all 7

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Authentik Authentication

apiKey · 2 schemes

SECURITY

Authentik Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Authentik Vulnerability Disclosure

security.txt · contact published

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Authentik Agentic Access

27 operations · 8 acting

27 operations · 8 acting

AGENTIC

Use Cases 4

What developers build with this provider.

Self-Hosted Identity Provider

Deploy a complete identity provider on-premises or in private cloud with full data sovereignty.

SSO Gateway

Provide single sign-on for all internal applications using OIDC, SAML, or LDAP protocol support.

B2C Identity

Build customer-facing registration and authentication flows with customizable enrollment and recovery processes.

Zero Trust Access

Implement zero trust application access with forward auth proxy integration and per-application policies.

Integrations 5

Pre-built integrations with other platforms and tools.

Nginx/Traefik/Caddy

Forward auth integration with major reverse proxies for transparent application authentication.

Kubernetes

Native Kubernetes deployment via Helm chart with optional operator and RBAC integration.

LDAP Directory

LDAP outpost that exposes authentik users to LDAP-compatible applications without a directory server.

Grafana

Native OAuth2 integration with Grafana for unified authentication in monitoring stacks.

Nextcloud

OIDC or SAML integration with Nextcloud for unified login in self-hosted file storage.

Solutions 2

Packaged solutions this provider offers.

Self-Hosted IAM

Complete identity and access management platform deployable on any infrastructure with no vendor lock-in.

Application Gateway

Secure and authenticate any application using forward auth with optional MFA and per-user access policies.

Resources

Documentation 1

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Build 2

SDKs, sample code, and the tooling you integrate with

Access & Security 3

Authentication, authorization, and security posture

Operate 3

Status, limits, changes, and where to get help

Commercial 1

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: authentik
name: Authentik
description: 'Authentik is an open source identity provider with a comprehensive REST API for managing users, groups, flows,
  providers, sources, policies, and outposts. It supports OAuth2, OIDC, SAML, LDAP, SCIM, and RADIUS protocols with official
  client SDKs in TypeScript, Python, Go, Rust, Kotlin, and Swift.

  '
type: Index
accessModel:
  pricing: freemium
  onboarding: self-serve
  trial: false
  try_now: true
  public: false
  label: Freemium · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/authentik.png
tags:
- Authentication
- Authorization
- Identity Provider
- LDAP
- OAuth
- Open Source
- OpenID Connect
- SAML
- SCIM
- Self-Hosted
url: https://raw.githubusercontent.com/api-evangelist/authentik/refs/heads/main/apis.yml
created: '2026-03-25'
modified: '2026-04-19'
specificationVersion: '0.19'
apis:
- aid: authentik:authentik-core-api
  name: Authentik Core API
  description: Users, applications, groups and tokens.
  humanURL: https://api.goauthentik.io/
  baseURL: https://your-authentik-instance.example.com/api/v3
  tags:
  - Core
  properties:
  - type: OpenAPI
    url: openapi/authentik-core-api-openapi.yml
  - type: Documentation
    url: https://docs.goauthentik.io/developer-docs/api/
  - type: APIReference
    url: https://api.goauthentik.io/
  - type: SDKs
    url: https://pypi.org/project/authentik-client/
  - type: SDKs
    url: https://www.npmjs.com/package/@goauthentik/api
  - type: GitHubRepository
    url: https://github.com/goauthentik/authentik
- aid: authentik:authentik-crypto-api
  name: Authentik Crypto API
  description: Certificate-key pairs.
  humanURL: https://api.goauthentik.io/
  baseURL: https://your-authentik-instance.example.com/api/v3
  tags:
  - Crypto
  properties:
  - type: OpenAPI
    url: openapi/authentik-crypto-api-openapi.yml
  - type: Documentation
    url: https://docs.goauthentik.io/developer-docs/api/
  - type: APIReference
    url: https://api.goauthentik.io/
  - type: SDKs
    url: https://pypi.org/project/authentik-client/
  - type: SDKs
    url: https://www.npmjs.com/package/@goauthentik/api
  - type: GitHubRepository
    url: https://github.com/goauthentik/authentik
- aid: authentik:authentik-events-api
  name: Authentik Events API
  description: Audit and notification events.
  humanURL: https://api.goauthentik.io/
  baseURL: https://your-authentik-instance.example.com/api/v3
  tags:
  - Events
  properties:
  - type: OpenAPI
    url: openapi/authentik-events-api-openapi.yml
  - type: Documentation
    url: https://docs.goauthentik.io/developer-docs/api/
  - type: APIReference
    url: https://api.goauthentik.io/
  - type: SDKs
    url: https://pypi.org/project/authentik-client/
  - type: SDKs
    url: https://www.npmjs.com/package/@goauthentik/api
  - type: GitHubRepository
    url: https://github.com/goauthentik/authentik
- aid: authentik:authentik-flows-api
  name: Authentik Flows API
  description: Authentication and enrollment flows.
  humanURL: https://api.goauthentik.io/
  baseURL: https://your-authentik-instance.example.com/api/v3
  tags:
  - Flows
  properties:
  - type: OpenAPI
    url: openapi/authentik-flows-api-openapi.yml
  - type: Documentation
    url: https://docs.goauthentik.io/developer-docs/api/
  - type: APIReference
    url: https://api.goauthentik.io/
  - type: SDKs
    url: https://pypi.org/project/authentik-client/
  - type: SDKs
    url: https://www.npmjs.com/package/@goauthentik/api
  - type: GitHubRepository
    url: https://github.com/goauthentik/authentik
- aid: authentik:authentik-policies-api
  name: Authentik Policies API
  description: Policies and policy bindings.
  humanURL: https://api.goauthentik.io/
  baseURL: https://your-authentik-instance.example.com/api/v3
  tags:
  - Policies
  properties:
  - type: OpenAPI
    url: openapi/authentik-policies-api-openapi.yml
  - type: Documentation
    url: https://docs.goauthentik.io/developer-docs/api/
  - type: APIReference
    url: https://api.goauthentik.io/
  - type: SDKs
    url: https://pypi.org/project/authentik-client/
  - type: SDKs
    url: https://www.npmjs.com/package/@goauthentik/api
  - type: GitHubRepository
    url: https://github.com/goauthentik/authentik
- aid: authentik:authentik-providers-api
  name: Authentik Providers API
  description: OAuth2/OIDC, SAML, LDAP, Proxy and other providers.
  humanURL: https://api.goauthentik.io/
  baseURL: https://your-authentik-instance.example.com/api/v3
  tags:
  - Providers
  properties:
  - type: OpenAPI
    url: openapi/authentik-providers-api-openapi.yml
  - type: Documentation
    url: https://docs.goauthentik.io/developer-docs/api/
  - type: APIReference
    url: https://api.goauthentik.io/
  - type: SDKs
    url: https://pypi.org/project/authentik-client/
  - type: SDKs
    url: https://www.npmjs.com/package/@goauthentik/api
  - type: GitHubRepository
    url: https://github.com/goauthentik/authentik
- aid: authentik:authentik-rbac-api
  name: Authentik RBAC API
  description: Role-based access control.
  humanURL: https://api.goauthentik.io/
  baseURL: https://your-authentik-instance.example.com/api/v3
  tags:
  - RBAC
  properties:
  - type: OpenAPI
    url: openapi/authentik-rbac-api-openapi.yml
  - type: Documentation
    url: https://docs.goauthentik.io/developer-docs/api/
  - type: APIReference
    url: https://api.goauthentik.io/
  - type: SDKs
    url: https://pypi.org/project/authentik-client/
  - type: SDKs
    url: https://www.npmjs.com/package/@goauthentik/api
  - type: GitHubRepository
    url: https://github.com/goauthentik/authentik
- aid: authentik:authentik-schema-api
  name: Authentik Schema API
  description: Self-describing OpenAPI schema.
  humanURL: https://api.goauthentik.io/
  baseURL: https://your-authentik-instance.example.com/api/v3
  tags:
  - Schema
  properties:
  - type: OpenAPI
    url: openapi/authentik-schema-api-openapi.yml
  - type: Documentation
    url: https://docs.goauthentik.io/developer-docs/api/
  - type: APIReference
    url: https://api.goauthentik.io/
  - type: SDKs
    url: https://pypi.org/project/authentik-client/
  - type: SDKs
    url: https://www.npmjs.com/package/@goauthentik/api
  - type: GitHubRepository
    url: https://github.com/goauthentik/authentik
- aid: authentik:authentik-sources-api
  name: Authentik Sources API
  description: External identity sources.
  humanURL: https://api.goauthentik.io/
  baseURL: https://your-authentik-instance.example.com/api/v3
  tags:
  - Sources
  properties:
  - type: OpenAPI
    url: openapi/authentik-sources-api-openapi.yml
  - type: Documentation
    url: https://docs.goauthentik.io/developer-docs/api/
  - type: APIReference
    url: https://api.goauthentik.io/
  - type: SDKs
    url: https://pypi.org/project/authentik-client/
  - type: SDKs
    url: https://www.npmjs.com/package/@goauthentik/api
  - type: GitHubRepository
    url: https://github.com/goauthentik/authentik
- aid: authentik:authentik-stages-api
  name: Authentik Stages API
  description: Flow stages (identification, password, etc.).
  humanURL: https://api.goauthentik.io/
  baseURL: https://your-authentik-instance.example.com/api/v3
  tags:
  - Stages
  properties:
  - type: OpenAPI
    url: openapi/authentik-stages-api-openapi.yml
  - type: Documentation
    url: https://docs.goauthentik.io/developer-docs/api/
  - type: APIReference
    url: https://api.goauthentik.io/
  - type: SDKs
    url: https://pypi.org/project/authentik-client/
  - type: SDKs
    url: https://www.npmjs.com/package/@goauthentik/api
  - type: GitHubRepository
    url: https://github.com/goauthentik/authentik
common:
- type: AgenticAccess
  url: agentic-access/authentik-agentic-access.yml
- type: VulnerabilityDisclosure
  url: security/authentik-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/authentik-domain-security.yml
- type: Authentication
  url: authentication/authentik-authentication.yml
- type: LinkedIn
  url: https://www.linkedin.com/company/authentik-security
- type: Website
  url: https://goauthentik.io
- type: Documentation
  url: https://docs.goauthentik.io
- type: GitHubOrganization
  url: https://github.com/goauthentik
- type: GitHubRepository
  url: https://github.com/goauthentik/authentik
- type: ChangeLog
  url: https://github.com/goauthentik/authentik/releases
- type: Support
  url: https://github.com/goauthentik/authentik/discussions
- type: Community
  url: https://discord.gg/jg33eMhnj6
- type: Pricing
  url: https://goauthentik.io/pricing
- type: Blog
  url: https://goauthentik.io/blog/rss.xml
- type: Features
  data:
  - name: Comprehensive REST API
    description: Full REST API covering all authentik features with built-in Swagger UI at /api/v3/ on every instance.
  - name: Multi-Protocol Support
    description: Native support for OAuth2, OIDC, SAML, LDAP, SCIM, RADIUS, and SSTP protocols for broad integration coverage.
  - name: Flow Engine
    description: Customizable authentication and enrollment flows with visual flow designer for configuring multi-step authentication
      processes.
  - name: Multi-Language SDKs
    description: Official API client SDKs in TypeScript, Python, Go, Rust, Kotlin, and Swift auto-generated from the OpenAPI
      schema.
  - name: Terraform Provider
    description: Official Terraform provider for infrastructure-as-code management of authentik resources.
  - name: Helm Deployment
    description: Official Helm chart for Kubernetes deployment with configurable replicas, persistence, and external database
      support.
  - name: RBAC
    description: Role-based access control for granular permission management across authentik resources and administrative
      functions.
- type: UseCases
  data:
  - name: Self-Hosted Identity Provider
    description: Deploy a complete identity provider on-premises or in private cloud with full data sovereignty.
  - name: SSO Gateway
    description: Provide single sign-on for all internal applications using OIDC, SAML, or LDAP protocol support.
  - name: B2C Identity
    description: Build customer-facing registration and authentication flows with customizable enrollment and recovery processes.
  - name: Zero Trust Access
    description: Implement zero trust application access with forward auth proxy integration and per-application policies.
- type: Integrations
  data:
  - name: Nginx/Traefik/Caddy
    description: Forward auth integration with major reverse proxies for transparent application authentication.
  - name: Kubernetes
    description: Native Kubernetes deployment via Helm chart with optional operator and RBAC integration.
  - name: LDAP Directory
    description: LDAP outpost that exposes authentik users to LDAP-compatible applications without a directory server.
  - name: Grafana
    description: Native OAuth2 integration with Grafana for unified authentication in monitoring stacks.
  - name: Nextcloud
    description: OIDC or SAML integration with Nextcloud for unified login in self-hosted file storage.
- type: Solutions
  data:
  - name: Self-Hosted IAM
    description: Complete identity and access management platform deployable on any infrastructure with no vendor lock-in.
  - name: Application Gateway
    description: Secure and authenticate any application using forward auth with optional MFA and per-user access policies.
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com