# Authentik

**Canonical:** https://apis.io/providers/authentik/  
**Website:** https://goauthentik.io  
**APIs profiled:** 10

Authentik is an open source identity provider with a comprehensive REST API for managing users, groups, flows, providers, sources, policies, and outposts. It supports OAuth2, OIDC, SAML, LDAP, SCIM, and RADIUS protocols with official client SDKs in TypeScript, Python, Go, Rust, Kotlin, and Swift.

## Kin Score — 35.7 / 100 (thin)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 35.7).

| Facet | Score |
|---|---|
| Discoverability | 74.1 |
| Contract Quality | 50.0 |
| Governance | 0.0 |
| Contract Governance | 0.0 |
| Operational Transparency | 36.8 |
| Developer Ergonomics | 28.6 |
| Commercial Clarity | 26.3 |
| Access Clarity | 26.3 |

## Agent readiness — 29.1 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Freemium · Self-serve signup — onboarding: self-serve, pricing: freemium, trial: no (confidence: high).

## APIs (10)

- **Authentik Core API** — Users, applications, groups and tokens.
- **Authentik Crypto API** — Certificate-key pairs.
- **Authentik Events API** — Audit and notification events.
- **Authentik Flows API** — Authentication and enrollment flows.
- **Authentik Policies API** — Policies and policy bindings.
- **Authentik Providers API** — OAuth2/OIDC, SAML, LDAP, Proxy and other providers.
- **Authentik RBAC API** — Role-based access control.
- **Authentik Schema API** — Self-describing OpenAPI schema.
- **Authentik Sources API** — External identity sources.
- **Authentik Stages API** — Flow stages (identification, password, etc.).

## Agentic access (1)

- **Authentik Agentic Access** — 27 operations · 8 acting

## Security (3)

- **Authentik Authentication** — apiKey · 2 schemes
- **Authentik Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC
- **Authentik Vulnerability Disclosure** — security.txt · contact published

## Plans (1)

- **Authentik Plans Pricing**

## Use cases (4)

- **Self-Hosted Identity Provider** — Deploy a complete identity provider on-premises or in private cloud with full data sovereignty.
- **SSO Gateway** — Provide single sign-on for all internal applications using OIDC, SAML, or LDAP protocol support.
- **B2C Identity** — Build customer-facing registration and authentication flows with customizable enrollment and recovery processes.
- **Zero Trust Access** — Implement zero trust application access with forward auth proxy integration and per-application policies.

## Tags

Authentication, Authorization, Identity Provider, LDAP, Open-Source, OpenID Connect, SAML, SCIM, Self-Hosted

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/authentik/). Scores are computed from the provider's own public artifacts under a published rubric.
