↓ Skip to main content
  1. Posts/
  2. IAM and IdP Solutions/

Authentik vs Authelia vs Keycloak vs Zitadel: SSO Compared

··1300 words·7 mins· loading · loading · ·
Stilicho2011
Author
Stilicho2011
Writing about homelab, self-hosting, automation and open-source solutions
Table of Contents
IAM-решения - This article is part of a series.
Part : This Article

Comparing Authelia, Authentik, Keycloak, and ZITADEL
#

If you enjoyed this article, you can support the author by becoming a sponsor on Boosty (link in the contacts section).

Introduction
#

Today we’re putting four of the big names in SSO and auth head to head - or in plain terms, four servers that handle authentication and authorization for you: Authelia, Authentik, Keycloak, and Zitadel. If you’re building out your own infrastructure, at home or even at work, and can’t decide which one to pick - this article (and the video) is for you.

The question comes up the moment you’re running more than a couple of services - especially ones facing the outside world, like Nextcloud or Plex or really anything: how do you manage logins, passwords, and access rights from one place instead of juggling five different systems? That’s what SSO - Single Sign-On - solves: log in once, get access everywhere. On top of that you get two-factor auth, LDAP, OAuth2, role separation, and access policies, all centralized. If you want the details on how TOTP, WebAuthn, and passwordless login actually differ and which one to pick, I’ve got a separate article on that.

Authelia vs Authentik vs Keycloak vs ZITADEL - which one should you actually pick?
#

If you’re building your own infrastructure and looking to implement centralized authentication, two-factor protection, and SSO, chances are you’ve already bumped into Authelia, Authentik, Keycloak, and ZITADEL. They’re all solving the same problem - access management - just in very different ways, aimed at very different use cases.

In this article I’ll walk through all four in detail and point you toward whichever fits your situation best, from a bare-bones self-hosted setup all the way up to corporate or cloud deployments.

We’re covering 4 open-source tools here. I lined them up alphabetically, and oddly enough that split also happens to match a split in built-in functionality - the first two share something the second two don’t have.


  1. Authelia - simple and strict,
  2. Authentik - good-looking and flexible,
  3. Keycloak - powerful, strict, and thoroughly corporate,
  4. Zitadel - cloud-native, with a modern API.

Authelia
#

Authelia is a self-hosted reverse proxy companion built to protect web apps with two-factor authentication and access control. It sits alongside NGINX, Traefik, or HAProxy, bolting on security and SSO without replacing anything you’re already running.

Really, Authelia is more of a reverse-proxy guard than a full identity provider. It’s reasonably painless to install, and the config lives in YAML. It sits as a middle layer between the user and your services, with no real UI for managing users - everything happens in the config file. It’s a good fit if you’ve got 5-10 services and like keeping things as config-as-code.

I walked through installing and setting up Authelia in Docker step by step in a separate article.

Key characteristics of Authelia
#

CharacteristicDescription
LanguageGo, React
SSO supportOIDC as a client only (not a full-fledged IdP)
2FATOTP, WebAuthn, Duo (including push notifications)
UILimited (has a web login page, but admin configuration is via YAML)
LDAP/ADYes, for authorization and groups
Reverse-proxy supportFull: Traefik, NGINX, HAProxy
ScalabilityYes, supports Redis, MariaDB/Postgres
Target audienceSelf-hosted homelab environments and small offices

Authentik
#

Authentik is a modern open-source IdP written in Python (Django), with full support for OIDC, SAML, SCIM, a real UI, and some genuinely powerful access policies. It works equally well for home labs and corporate setups.

Authentik is modular, flexible, and honestly just nice to look at. It installs easily via Docker and the docs are excellent. It supports OAuth2, SAML, LDAP, and a long list of other providers, and you can build your own custom policies, UI flows, and login page templates.

I go deeper into Authentik’s architecture and capabilities in a separate article, and cover hands-on installation, proxy/OIDC providers, and specific scenarios - invitations, password recovery, 2FA, email notifications, Cloudflare Turnstile - across a series of articles in the SSO category.

Key characteristics of Authentik
#

CharacteristicDescription
LanguagePython (Django)
SSO supportOIDC, SAML (as IdP and SP)
2FATOTP, WebAuthn, Email OTP, Duo, Push, Social Login
UIModern interface
LDAP/ADYes (as a user source)
Workflow / PoliciesYes, visual flows, policies, and more
ScalabilityYes (Docker, Kubernetes, Redis, PostgreSQL support)
Target audienceSelf-hosted, SMB (small and medium business), DevOps

What Authelia and Authentik get right
#

Both of these come with a built-in web proxy layer. That means they slot in seamlessly in front of a reverse proxy and can protect apps that have no OIDC support of their own, or that only offer basic HTTP auth.


Keycloak
#

Keycloak is Red Hat’s enterprise open-source offering for centralized authentication and authorization. It’s one of the most powerful, most flexible IdPs out there, with support for OIDC, SAML, Kerberos, LDAP, you name it.

Keycloak is a genuine beast. It supports pretty much every protocol and scenario you could ask for. It’s an enterprise-project staple, but it demands real expertise to run well. Configuration can get unwieldy and the UI feels cluttered, but this thing really does have everything - like the old saying about Greece.

I covered the step-by-step install, docker-compose setup, and first boot with realm creation in a separate article.

Key characteristics of Keycloak
#

CharacteristicDescription
LanguageJava (Quarkus, previously WildFly)
SSO supportOIDC, SAML, Kerberos, Social Login
2FATOTP, SMS, Email OTP, WebAuthn
UIPowerful, but some may find it overloaded and confusing
LDAP/ADYes (broad support)
ExtensibilityYes, via SPI, extensions, and the REST API
ScalabilityExcellent, especially for enterprise
Target audienceLarge enterprise, government institutions

Zitadel
#

ZITADEL is a modern, open-source, cloud-native Identity & Access Management platform built in Switzerland, with a heavy focus on security, developers, DevOps, and multi-tenancy. It ships both as a cloud platform and as a self-hosted option.

Zitadel is the newest of the bunch, but it’s already surprisingly mature. There’s a cloud version and an open-source one you can run in Docker. The UI is clean and minimal, the API and SDK feel genuinely modern and dev-first, and the docs are solid, if not quite perfect yet. Adoption is already picking up fast.

More on ZITADEL’s setup and architecture in a separate article.

Key characteristics of ZITADEL
#

CharacteristicDescription
LanguageGo
SSO supportOIDC, SAML, SCIM
2FAWebAuthn, TOTP, SMS, Email
UIModern, minimalist, logical, and pleasant
LDAP/ADOnly with the enterprise subscription (see documentation)
Multi-tenant supportYes (one of its main features)
ScalabilityVery high, cloud-first solution
Target audienceSaaS platforms, DevOps, developers

Overall comparison table
#

CharacteristicAutheliaAuthentikKeycloakZITADEL
Development languageGoPython (Django)Java (Quarkus/WildFly)Go
Installation methodDocker, Kubernetes, BinaryDocker, Kubernetes, BinaryDocker, Kubernetes, ZIP distributionDocker, Kubernetes, Cloud
SSO support (OIDC/SAML)OIDC (as client)OIDC, SAML (IdP and SP)OIDC, SAML, KerberosOIDC, SAML, SCIM
Web UILimitedYes (modern UI)Yes (rich, but complex)Yes (minimalist UI)
2FA / MFA supportTOTP, WebAuthn, DuoTOTP, WebAuthn, Email OTPTOTP, WebAuthn, Email, SMSTOTP, WebAuthn, SMS, Email
LDAP / AD integrationAuthorization via LDAPYes (as a user source)YesEnterprise only
RBAC / ABACVia YAML and policyYes (flow-based)Yes (groups, roles, policies)Yes (RBAC + conditions)
ScalabilityMediumGoodExcellentExcellent
Cloud-readyNoNoPartialYes
Open sourceYes (Apache 2.0)Yes (MIT)Yes (Apache 2.0)Yes (GNU Affero GPL v3.0)

The takeaway
#

Authelia isn’t a full-fledged IdP - think of it more as an authentication layer sitting between your users and your apps.

Authentik is actively developed, has a genuinely good UI, and is a comfortable fit for self-hosted setups.

Keycloak is powerful but heavy - built for corporate use, and it shows.

ZITADEL leans cloud-first but comes with a solid self-hosted option, aimed squarely at developers and security-conscious teams.

IAM-решения - This article is part of a series.
Part : This Article

Related