Comparing Authelia, Authentik, Keycloak, and ZITADEL#
If you enjoyed this article, you can support the author by becoming a sponsor on Boosty (link in the contacts section).
Introduction#
Today we’re putting four of the big names in SSO and auth head to head - or in plain terms, four servers that handle authentication and authorization for you: Authelia, Authentik, Keycloak, and Zitadel. If you’re building out your own infrastructure, at home or even at work, and can’t decide which one to pick - this article (and the video) is for you.
The question comes up the moment you’re running more than a couple of services - especially ones facing the outside world, like Nextcloud or Plex or really anything: how do you manage logins, passwords, and access rights from one place instead of juggling five different systems? That’s what SSO - Single Sign-On - solves: log in once, get access everywhere. On top of that you get two-factor auth, LDAP, OAuth2, role separation, and access policies, all centralized. If you want the details on how TOTP, WebAuthn, and passwordless login actually differ and which one to pick, I’ve got a separate article on that.
Authelia vs Authentik vs Keycloak vs ZITADEL - which one should you actually pick?#
If you’re building your own infrastructure and looking to implement centralized authentication, two-factor protection, and SSO, chances are you’ve already bumped into Authelia, Authentik, Keycloak, and ZITADEL. They’re all solving the same problem - access management - just in very different ways, aimed at very different use cases.
In this article I’ll walk through all four in detail and point you toward whichever fits your situation best, from a bare-bones self-hosted setup all the way up to corporate or cloud deployments.
We’re covering 4 open-source tools here. I lined them up alphabetically, and oddly enough that split also happens to match a split in built-in functionality - the first two share something the second two don’t have.
- Authelia - simple and strict,
- Authentik - good-looking and flexible,
- Keycloak - powerful, strict, and thoroughly corporate,
- Zitadel - cloud-native, with a modern API.
Authelia#
Authelia is a self-hosted reverse proxy companion built to protect web apps with two-factor authentication and access control. It sits alongside NGINX, Traefik, or HAProxy, bolting on security and SSO without replacing anything you’re already running.
Really, Authelia is more of a reverse-proxy guard than a full identity provider. It’s reasonably painless to install, and the config lives in YAML. It sits as a middle layer between the user and your services, with no real UI for managing users - everything happens in the config file. It’s a good fit if you’ve got 5-10 services and like keeping things as config-as-code.
I walked through installing and setting up Authelia in Docker step by step in a separate article.
Key characteristics of Authelia#
| Characteristic | Description |
|---|---|
| Language | Go, React |
| SSO support | OIDC as a client only (not a full-fledged IdP) |
| 2FA | TOTP, WebAuthn, Duo (including push notifications) |
| UI | Limited (has a web login page, but admin configuration is via YAML) |
| LDAP/AD | Yes, for authorization and groups |
| Reverse-proxy support | Full: Traefik, NGINX, HAProxy |
| Scalability | Yes, supports Redis, MariaDB/Postgres |
| Target audience | Self-hosted homelab environments and small offices |
Authentik#
Authentik is a modern open-source IdP written in Python (Django), with full support for OIDC, SAML, SCIM, a real UI, and some genuinely powerful access policies. It works equally well for home labs and corporate setups.
Authentik is modular, flexible, and honestly just nice to look at. It installs easily via Docker and the docs are excellent. It supports OAuth2, SAML, LDAP, and a long list of other providers, and you can build your own custom policies, UI flows, and login page templates.
I go deeper into Authentik’s architecture and capabilities in a separate article, and cover hands-on installation, proxy/OIDC providers, and specific scenarios - invitations, password recovery, 2FA, email notifications, Cloudflare Turnstile - across a series of articles in the SSO category.
Key characteristics of Authentik#
| Characteristic | Description |
|---|---|
| Language | Python (Django) |
| SSO support | OIDC, SAML (as IdP and SP) |
| 2FA | TOTP, WebAuthn, Email OTP, Duo, Push, Social Login |
| UI | Modern interface |
| LDAP/AD | Yes (as a user source) |
| Workflow / Policies | Yes, visual flows, policies, and more |
| Scalability | Yes (Docker, Kubernetes, Redis, PostgreSQL support) |
| Target audience | Self-hosted, SMB (small and medium business), DevOps |
What Authelia and Authentik get right#
Both of these come with a built-in web proxy layer. That means they slot in seamlessly in front of a reverse proxy and can protect apps that have no OIDC support of their own, or that only offer basic HTTP auth.
Keycloak#
Keycloak is Red Hat’s enterprise open-source offering for centralized authentication and authorization. It’s one of the most powerful, most flexible IdPs out there, with support for OIDC, SAML, Kerberos, LDAP, you name it.
Keycloak is a genuine beast. It supports pretty much every protocol and scenario you could ask for. It’s an enterprise-project staple, but it demands real expertise to run well. Configuration can get unwieldy and the UI feels cluttered, but this thing really does have everything - like the old saying about Greece.
I covered the step-by-step install, docker-compose setup, and first boot with realm creation in a separate article.
Key characteristics of Keycloak#
| Characteristic | Description |
|---|---|
| Language | Java (Quarkus, previously WildFly) |
| SSO support | OIDC, SAML, Kerberos, Social Login |
| 2FA | TOTP, SMS, Email OTP, WebAuthn |
| UI | Powerful, but some may find it overloaded and confusing |
| LDAP/AD | Yes (broad support) |
| Extensibility | Yes, via SPI, extensions, and the REST API |
| Scalability | Excellent, especially for enterprise |
| Target audience | Large enterprise, government institutions |
Zitadel#
ZITADEL is a modern, open-source, cloud-native Identity & Access Management platform built in Switzerland, with a heavy focus on security, developers, DevOps, and multi-tenancy. It ships both as a cloud platform and as a self-hosted option.
Zitadel is the newest of the bunch, but it’s already surprisingly mature. There’s a cloud version and an open-source one you can run in Docker. The UI is clean and minimal, the API and SDK feel genuinely modern and dev-first, and the docs are solid, if not quite perfect yet. Adoption is already picking up fast.
More on ZITADEL’s setup and architecture in a separate article.
Key characteristics of ZITADEL#
| Characteristic | Description |
|---|---|
| Language | Go |
| SSO support | OIDC, SAML, SCIM |
| 2FA | WebAuthn, TOTP, SMS, Email |
| UI | Modern, minimalist, logical, and pleasant |
| LDAP/AD | Only with the enterprise subscription (see documentation) |
| Multi-tenant support | Yes (one of its main features) |
| Scalability | Very high, cloud-first solution |
| Target audience | SaaS platforms, DevOps, developers |
Overall comparison table#
| Characteristic | Authelia | Authentik | Keycloak | ZITADEL |
|---|---|---|---|---|
| Development language | Go | Python (Django) | Java (Quarkus/WildFly) | Go |
| Installation method | Docker, Kubernetes, Binary | Docker, Kubernetes, Binary | Docker, Kubernetes, ZIP distribution | Docker, Kubernetes, Cloud |
| SSO support (OIDC/SAML) | OIDC (as client) | OIDC, SAML (IdP and SP) | OIDC, SAML, Kerberos | OIDC, SAML, SCIM |
| Web UI | Limited | Yes (modern UI) | Yes (rich, but complex) | Yes (minimalist UI) |
| 2FA / MFA support | TOTP, WebAuthn, Duo | TOTP, WebAuthn, Email OTP | TOTP, WebAuthn, Email, SMS | TOTP, WebAuthn, SMS, Email |
| LDAP / AD integration | Authorization via LDAP | Yes (as a user source) | Yes | Enterprise only |
| RBAC / ABAC | Via YAML and policy | Yes (flow-based) | Yes (groups, roles, policies) | Yes (RBAC + conditions) |
| Scalability | Medium | Good | Excellent | Excellent |
| Cloud-ready | No | No | Partial | Yes |
| Open source | Yes (Apache 2.0) | Yes (MIT) | Yes (Apache 2.0) | Yes (GNU Affero GPL v3.0) |
The takeaway#
Authelia isn’t a full-fledged IdP - think of it more as an authentication layer sitting between your users and your apps.
Authentik is actively developed, has a genuinely good UI, and is a comfortable fit for self-hosted setups.
Keycloak is powerful but heavy - built for corporate use, and it shows.
ZITADEL leans cloud-first but comes with a solid self-hosted option, aimed squarely at developers and security-conscious teams.




