1"use strict";(self.webpackChunk_goauthentik_docs_topics=self.webpackChunk_goauthentik_docs_topics||[]).push([["1924"],{55226(e){e.exports=JSON.parse('{"version":{"pluginId":"default","version":"current","label":"Next","banner":null,"badge":false,"noIndex":false,"className":"docs-version-current","isLast":true,"docsSidebars":{"docs":[{"type":"link","href":"/","label":"Welcome to authentik","docId":"index","unlisted":false},{"type":"category","label":"Core Concepts","items":[{"type":"link","href":"/core/architecture","label":"Architecture","docId":"core/architecture","unlisted":false},{"type":"category","label":"Glossary","collapsible":true,"collapsed":true,"items":[{"type":"category","label":"terms","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/core/glossary/terms/access-token","label":"Access Token","customProps":{"termName":"Access Token","tags":["Tokens And Claims"],"shortDescription":"Bearer token used to access protected APIs.","longDescription":"Credential presented to resource servers to authorize requests. Often a JWT containing scopes, audience and expiry, but can be opaque and validated via introspection. Typically short-lived to reduce risk if leaked."},"docId":"core/glossary/terms/access-token","unlisted":false},{"type":"link","href":"/core/glossary/terms/acs","label":"Assertion Consumer Service (ACS)","customProps":{"termName":"Assertion Consumer Service (ACS)","tags":["SAML"],"shortDescription":"Service Provider endpoint that receives SAML assertions.","longDescription":"Configured SP endpoint where the IdP delivers the SAML Response (typically via HTTP-POST). The SP validates signatures, issuer, audience, and time conditions before creating a session."},"docId":"core/glossary/terms/acs","unlisted":false},{"type":"link","href":"/core/glossary/terms/application","label":"Application","customProps":{"termName":"Application","tags":["Core Concepts"],"shortDescription":"An application is what you authenticate into with authentik and is displayed on the \\"Application Dashboard\\" page in the User interface.","authentikSpecific":true,"longDescription":"An application is paired with a provider, and with defined policies and other configurations controls user access. It also holds information like UI name, icon, and more."},"docId":"core/glossary/terms/application","unlisted":false},{"type":"link","href":"/core/glossary/terms/audience","label":"Audience (aud)","customProps":{"termName":"Audience (aud)","tags":["Tokens And Claims"],"shortDescription":"Intended recipient of a token.","longDescription":"The \'aud\' claim limits where the token is valid, typically an API or application."},"docId":"core/glossary/terms/audience","unlisted":false},{"type":"link","href":"/core/glossary/terms/authorization-code","label":"Authorization code","customProps":{"termName":"Authorization code","tags":["OAuth2/OIDC"],"shortDescription":"Short-lived code exchanged for tokens.","longDescription":"Returned to the client after user authorization and redeemed at the token endpoint for access, refresh, and optionally ID tokens."},"docId":"core/glossary/terms/authorization-code","unlisted":false},{"type":"link","href":"/core/glossary/terms/authorization-endpoint","label":"Authorization endpoint","customProps":{"termName":"Authorization endpoint","tags":["Endpoints"],"shortDescription":"Endpoint where users authenticate and consent.","longDescription":"Start of OAuth/OIDC flows; returns codes or tokens depending on the response type and client configuration."},"docId":"core/glossary/terms/authorization-endpoint","unlisted":false},{"type":"link","href":"/core/glossary/terms/authorization-server","label":"Authorization Server (AS)","customProps":{"termName":"Authorization Server (AS)","tags":["OAuth2/OIDC"],"shortDescription":"OAuth2 role that issues tokens and hosts authorization endpoints.","longDescription":"Server that authenticates resource owners, obtains consent, and issues access/refresh (and in OIDC, ID) tokens to clients. Provides authorization, token, introspection, revocation, and metadata (discovery) endpoints. In OIDC, the Authorization Server is called the OpenID Provider (OP)."},"docId":"core/glossary/terms/authorization-server","unlisted":false},{"type":"link","href":"/core/glossary/terms/back-channel-logout","label":"Back-channel logout","customProps":{"termName":"Back-channel logout","tags":["Protocols"],"shortDe
1scription":"Server-to-server logout notification.","longDescription":"Provider notifies clients directly without the user agent, offering more reliable session termination than front-channel logout."},"docId":"core/glossary/terms/back-channel-logout","unlisted":false},{"type":"link","href":"/core/glossary/terms/back-channel","label":"Back-channel","customProps":{"termName":"Back-channel","tags":["Protocols"],"shortDescription":"Direct server-to-server communication.","longDescription":"Server-to-server interactions without user-agent involvement, e.g., token exchange at the token endpoint, introspection, revocation, or back-channel logout. More reliable for session coordination and avoids browser constraints."},"docId":"core/glossary/terms/back-channel","unlisted":false},{"type":"link","href":"/core/glossary/terms/blueprints","label":"Blueprints","customProps":{"termName":"Blueprints","tags":["Configuration"],"shortDescription":"Declarative files to template and reconcile authentik config.","authentikSpecific":true,"longDescription":"YAML-based configuration files that are used to create and update objects (flows, providers, policies, etc.) as code. Blueprints can be applied from the filesystem, database, or OCI registries, support meta models for dependencies, and are reconciled periodically or on change."},"docId":"core/glossary/terms/blueprints","unlisted":false},{"type":"link","href":"/core/glossary/terms/brand","label":"Brand","customProps":{"termName":"Brand","tags":["Customization"],"shortDescription":"Per-domain settings for UI, default flows, and behavior.","authentikSpecific":true,"longDescription":"A Brand applies visual identity and behavior to your authentik instance. Branding settings control title, logo, favicon, theme, default flows (authentication, logout, recovery, user settings, device code), default application redirects, and global attributes like locale."},"docId":"core/glossary/terms/brand","unlisted":false},{"type":"link","href":"/core/glossary/terms/claim","label":"Claim","customProps":{"termName":"Claim","tags":["Tokens And Claims"],"shortDescription":"A piece of information about a subject.","longDescription":"Name-value pairs in tokens such as \'email\', \'sub\', or custom application attributes."},"docId":"core/glossary/terms/claim","unlisted":false},{"type":"link","href":"/core/glossary/terms/dynamic-in-memory-stage","label":"Dynamic in-memory stage","customProps":{"termName":"Dynamic in-memory stage","tags":["Flows"],"shortDescription":"Ephemeral stage appended at runtime; exists only in memory.","authentikSpecific":true,"longDescription":"Special stage added by authentik in specific contexts to alter control flow without persisting configuration. For example, the Source stage appends a dynamic in-memory stage to the source\'s flow to suspend the current flow, run the source\'s authentication or enrollment, and then resume. If a User login stage is bound in the source\'s flow, it will directly authenticate the pending user instead of resuming the original flow. Not configurable by administrators."},"docId":"core/glossary/terms/dynamic-in-memory-stage","unlisted":false},{"type":"link","href":"/core/glossary/terms/entity-id","label":"Entity ID","customProps":{"termName":"Entity ID","tags":["SAML"],"shortDescription":"Unique identifier for an IdP or Service Provider.","longDescription":"A URI/URL used in SAML metadata to uniquely identify a party in the federation."},"docId":"core/glossary/terms/entity-id","unlisted":false},{"type":"link","href":"/core/glossary/terms/flow","label":"Flow","customProps":{"termName":"Flow","tags":["Flows"],"shortDescription":"An ordered sequence of stages.","authentikSpecific":true,"longDescription":"Flows are an ordered sequence of stages, potentially with policies bound to them. They define how a user authenticates, enrolls, and more."},"docId":"core/glossary/terms/flow","unlisted":false},{"type":"link","href":"/core/glossary/terms/front-channel-logout","label":"Front-channel logout","customProps":{"termName":"Front-channel logout","tags":["Protocols"],"shortDe
1scription":"Logout via browser redirects or iframes.","longDescription":"Relies on the user agent to propagate logout to clients or SPs; may be affected by third-party cookie and iframe restrictions."},"docId":"core/glossary/terms/front-channel-logout","unlisted":false},{"type":"link","href":"/core/glossary/terms/front-channel","label":"Front-channel","customProps":{"termName":"Front-channel","tags":["Protocols"],"shortDescription":"Browser-mediated communication via the user\'s agent.","longDescription":"Interactions where data transits the user\'s browser, e.g., OAuth/OIDC authorization redirects and SAML HTTP-Redirect/POST bindings. Useful for user interaction and consent, but subject to browser policies, URL length/visibility, and referrer leakage if not carefully designed."},"docId":"core/glossary/terms/front-channel","unlisted":false},{"type":"link","href":"/core/glossary/terms/grant-type","label":"Grant type","customProps":{"termName":"Grant type","tags":["OAuth2/OIDC"],"shortDescription":"OAuth2 mechanism for obtaining tokens.","longDescription":"Examples include `authorization_code`, `client_credentials`, and `refresh_token`; PKCE strengthens `authorization_code` for public clients."},"docId":"core/glossary/terms/grant-type","unlisted":false},{"type":"link","href":"/core/glossary/terms/id-token","label":"ID token","customProps":{"termName":"ID token","tags":["Tokens And Claims"],"shortDescription":"OIDC token describing the authenticated user.","longDescription":"JWT issued by the OpenID Provider describing the authentication event and the end-user (subject). RPs (Relying Party) validate issuer, audience, signature, expiry and the nonce; not intended for API authorization."},"docId":"core/glossary/terms/id-token","unlisted":false},{"type":"link","href":"/core/glossary/terms/identity-provider","label":"Identity Provider (IdP)","customProps":{"termName":"Identity Provider (IdP)","tags":["Core Concepts"],"shortDescription":"Authority that authenticates users and issues assertions/tokens.","longDescription":"In SAML, the IdP issues assertions. In OIDC, this role is fulfilled by the OpenID Provider (OP), which is also the Authorization Server (AS) in OAuth2 terms; it authenticates users, obtains consent, and issues tokens."},"docId":"core/glossary/terms/identity-provider","unlisted":false},{"type":"link","href":"/core/glossary/terms/idp-initiated-sso","label":"IdP-initiated SSO","customProps":{"termName":"IdP-initiated SSO","tags":["SAML"],"shortDescription":"SSO flow started at the Identity Provider.","longDescription":"User launches from the IdP without an SP AuthnRequest. The IdP posts a response directly to the SP\'s ACS; simpler to start but offers fewer request-bound security guarantees."},"docId":"core/glossary/terms/idp-initiated-sso","unlisted":false},{"type":"link","href":"/core/glossary/terms/introspection-endpoint","label":"Introspection endpoint","customProps":{"termName":"Introspection endpoint","tags":["OAuth2/OIDC"],"shortDescription":"Endpoint to validate opaque tokens.","longDescription":"RFC 7662 endpoint that returns whether a token is active along with subject, scopes, audience, and expiry. Typically requires client authentication and is used when tokens are opaque."},"docId":"core/glossary/terms/introspection-endpoint","unlisted":false},{"type":"link","href":"/core/glossary/terms/issuer","label":"Issuer (iss)","customProps":{"termName":"Issuer (iss)","tags":["Tokens And Claims"],"shortDescription":"Entity that issued the token.","longDescription":"The \'iss\' claim identifies the authorization server or identity provider that created the token; RPs and APIs must verify it matches the expected issuer URL."},"docId":"core/glossary/terms/issuer","unlisted":false},{"type":"link","href":"/core/glossary/terms/jwk","label":"JWK","customProps":{"termName":"JWK","tags":["Keys And Crypto"],"shortDescription":"JSON representation of a cryptographic key.","longDescription":"Describes key material and parameters for signing or encryption; individual entries make up a JWKS."},"docId":"core/glossary/terms/jwk","unlisted":false},{"type":"link","href":"/core/glossary/terms/jwks","label":"JWKS","customProps":{"termName":"JWKS","tags":["Keys And Crypto"],"shortDe
1scription":"JSON Web Key Set used to verify JWTs.","longDescription":"Set of public keys exposed by the provider so clients and resource servers can verify JWT signatures. Keys are identified by \'kid\' and support rotation without downtime."},"docId":"core/glossary/terms/jwks","unlisted":false},{"type":"link","href":"/core/glossary/terms/jwt","label":"JWT","customProps":{"termName":"JWT","tags":["Tokens And Claims"],"shortDescription":"Compact, signed JSON token format.","longDescription":"Compact token with header, payload, and signature. Usually a JWS (signed) and optionally a JWE (encrypted); includes claims such as `iss`, `sub`, `aud`, `exp`, `iat`, and custom fields."},"docId":"core/glossary/terms/jwt","unlisted":false},{"type":"link","href":"/core/glossary/terms/ldap-base-dn","label":"Base DN","customProps":{"termName":"Base DN","tags":["Directory"],"shortDescription":"Root DN (Distinguished Name) under which LDAP searches occur.","longDescription":"Starting point for LDAP queries and sync operations, typically the domain components such as `dc=example,dc=com` or an organizational unit."},"docId":"core/glossary/terms/ldap-base-dn","unlisted":false},{"type":"link","href":"/core/glossary/terms/ldap-bind-dn","label":"Bind DN","customProps":{"termName":"Bind DN","tags":["Directory"],"shortDescription":"Account DN (Distinguished Name) used to authenticate to LDAP.","longDescription":"The DN of the service account used to perform searches or updates. Often paired with a bind password; may require least-privilege read access only."},"docId":"core/glossary/terms/ldap-bind-dn","unlisted":false},{"type":"link","href":"/core/glossary/terms/ldap-dn","label":"Distinguished Name (DN)","customProps":{"termName":"Distinguished Name (DN)","tags":["Directory"],"shortDescription":"Unique path identifying an entry in LDAP.","longDescription":"Hierarchical identifier built from Relative Distinguished Names (RDNs), e.g., `uid=jane,ou=People,dc=example,dc=com`. Used to reference and bind to entries."},"docId":"core/glossary/terms/ldap-dn","unlisted":false},{"type":"link","href":"/core/glossary/terms/ldap-filter","label":"LDAP search f
1ilter","customProps":{"termName":"LDAP search filter","tags":["Directory"],"shortDescription":"Expression selecting entries to return.","longDescription":"RFC 4515 filter syntax like `(objectClass=person)` or `(&(objectClass=user)(memberOf=...))` used to constrain LDAP queries."},"docId":"core/glossary/terms/ldap-filter","unlisted":false},{"type":"link","href":"/core/glossary/terms/ldap-objectclass","label":"ObjectClass","customProps":{"termName":"ObjectClass","tags":["Directory"],"shortDescription":"Schema class that defines required/allowed attributes.","longDescription":"LDAP entries declare one or more `objectClass` values (e.g., `inetOrgPerson`, `posixAccount`) that determine which attributes are valid."},"docId":"core/glossary/terms/ldap-objectclass","unlisted":false},{"type":"link","href":"/core/glossary/terms/ldap","label":"LDAP","customProps":{"termName":"LDAP","tags":["Directory"],"shortDescription":"Lightweight Directory Access Protocol for directory services.","longDescription":"Open protocol used to query and modify directory services like Active Directory or FreeIPA. Commonly used for user and group lookups and authentication binds."},"docId":"core/glossary/terms/ldap","unlisted":false},{"type":"link","href":"/core/glossary/terms/nameid","label":"NameID","customProps":{"termName":"NameID","tags":["SAML"],"shortDescription":"Primary identifier for a user in SAML.","longDescription":"Subject identifier in SAML Assertions. Common formats include `EmailAddress`, `Persistent` (stable pseudonymous), and `Transient` (one-time); chosen per service provider requirements."},"docId":"core/glossary/terms/nameid","unlisted":false},{"type":"link","href":"/core/glossary/terms/notification-rule","label":"Notification rule","customProps":{"termName":"Notification rule","tags":["Events And Notifications"],"shortDescription":"Policy-filtered event triggers that send notifications via transports.","authentikSpecific":true,"longDescription":"Rules that evaluate events through the policy engine and, when matched, deliver notifications using a selected transport (local UI, email, webhook). Bind policies, groups, or users to scope recipients and control which events generate alerts."},"docId":"core/glossary/terms/notification-rule","unlisted":false},{"type":"link","href":"/core/glossary/terms/oidc-discovery","label":"OIDC discovery document","customProps":{"termName":"OIDC discovery document","tags":["OAuth2/OIDC"],"shortDescription":"Provider metadata at the well-known URL.","longDescription":"JSON metadata at `/.well-known/openid-configuration` advertising issuer, endpoints (authorization, token, userinfo, jwks, end_session), supported scopes, response types, and algorithms for dynamic client configuration."},"docId":"core/glossary/terms/oidc-discovery","unlisted":false},{"type":"link","href":"/core/glossary/terms/openid-provider","label":"OpenID Provider (OP)","customProps":{"termName":"OpenID Provider (OP)","tags":["OAuth2/OIDC"],"shortDescription":"OIDC authority that authenticates users and issues tokens.","longDescription":"Authorization Server implementing OpenID Connect. Exposes discovery metadata, authorization, token, userinfo, JWKS, and end-session endpoints; authenticates users, issues ID/Access/Refresh tokens, and enforces consent and policy. In OAuth2 terminology, the OP is the Authorization Server (AS)."},"docId":"core/glossary/terms/openid-provider","unlisted":false},{"type":"link","href":"/core/glossary/terms/outpost","label":"Outpost","customProps":{"termName":"Outpost","tags":["Components"],"shortDescription":"Separate component providing services like reverse proxying, deployable anywhere.","authentikSpecific":true,"longDescription":"An outpost is a separate component of authentik, deployable anywhere regardless of the authentik deployment. It offers services not implemented directly in the core, such as reverse proxying."},"docId":"core/glossary/terms/outpost","unlisted":false},{"type":"link","href":"/core/glossary/terms/passkey","label":"Passkey","customProps":{"termName":"Passkey","tags":["Authentication"],"shortDe
1scription":"Discoverable FIDO2 credential, often synced across devices for passwordless login.","longDescription":"A user\u2011friendly form of WebAuthn credential stored by a platform or password manager and typically synced via cloud. Passkeys allow username\u2011less and passwordless flows by discovering credentials on the device. All passkeys are WebAuthn, but not all WebAuthn credentials are passkeys (e.g., non\u2011resident)."},"docId":"core/glossary/terms/passkey","unlisted":false},{"type":"link","href":"/core/glossary/terms/pkce","label":"PKCE","customProps":{"termName":"PKCE","tags":["OAuth2/OIDC"],"shortDescription":"Proof Key for Code Exchange hardens the code flow.","longDescription":"Binds the authorization request to the token exchange using a one-time code verifier and a code challenge (typically `S256`). Prevents intercepted codes from being redeemed by attackers."},"docId":"core/glossary/terms/pkce","unlisted":false},{"type":"link","href":"/core/glossary/terms/policy","label":"Policy","customProps":{"termName":"Policy","tags":["Core Concepts"],"shortDescription":"A yes/no gate evaluated by type and settings.","authentikSpecific":true,"longDescription":"At a base level, a policy is a yes/no gate. It evaluates to True or False depending on the policy kind and settings. For example, a Group Membership policy evaluates to True if the user is a member of the specified group and False if not. Policies can conditionally apply stages, grant or deny access, and support other custom logic."},"docId":"core/glossary/terms/policy","unlisted":false},{"type":"link","href":"/core/glossary/terms/property-mappings","label":"Property mappings","customProps":{"termName":"Property mappings","tags":["Configuration"],"shortDescription":"Define how data is exposed to apps and stored from sources.","authentikSpecific":true,"longDescription":"Property mappings allow you to make information available for external applications and to modify how information from sources is stored in authentik. For example, to log in to AWS you can set a user\'s roles in AWS based on their group memberships in authentik."},"docId":"core/glossary/terms/property-mappings","unlisted":false},{"type":"link","href":"/core/glossary/terms/provider","label":"Provider","customProps":{"termName":"Provider","tags":["Core Concepts"],"shortDescription":"A way for other applications to authenticate against authentik.","authentikSpecific":true,"longDescription":"A provider is a way for other applications to authenticate against authentik. Common providers in authentik are OpenID Connect (OIDC), OAuth2, SCIM, and SAML."},"docId":"core/glossary/terms/provider","unlisted":false},{"type":"link","href":"/core/glossary/terms/radius-auth-methods","label":"RADIUS auth methods","customProps":{"termName":"RADIUS auth methods","tags":["Protocols"],"shortDescription":"PAP, CHAP, MS\u2011CHAPv2, and EAP methods.","longDescription":"RADIUS transports credential exchanges such as PAP (plaintext password), CHAP/MS\u2011CHAPv2 (challenge\u2011response), or EAP methods (e.g., PEAP, EAP\u2011TLS) terminated on the NAS or server."},"docId":"core/glossary/terms/radius-auth-methods","unlisted":false},{"type":"link","href":"/core/glossary/terms/radius-messages","label":"RADIUS messages","customProps":{"termName":"RADIUS messages","tags":["Protocols"],"shortDescription":"Access\u2011Request/Accept/Reject and Accounting messages.","longDescription":"Core flow - NAS sends Access\u2011Request; server replies Access\u2011Accept (optionally with attributes) or Access\u2011Reject. Accounting\u2011Start/Stop records session usage."},"docId":"core/glossary/terms/radius-messages","unlisted":false},{"type":"link","href":"/core/glossary/terms/radius-nas","label":"Network Access Server (NAS)","customProps":{"termName":"Network Access Server (NAS)","tags":["Protocols"],"shortDescription":"Device that sends RADIUS requests to the server.","longDescription":"Examples include VPN concentrators, Wi\u2011Fi controllers, firewalls, or switches. The NAS acts as the RADIUS client initiating Access\u2011Request and Accounting messages."},"docId":"core/glossary/terms/radius-nas","unlisted":false},{"type":"link","href":"/core/glossary/terms/radius-shared-secret","label":"RADIUS shared secret","customProps":{"termName":"RADIUS shared secret","tags":["Protocols"],"shortDe
1scription":"Pre\u2011shared key between NAS and RADIUS server.","longDescription":"Used to compute request authenticators and validate responses. Must be unique per NAS and stored securely to prevent request forgery."},"docId":"core/glossary/terms/radius-shared-secret","unlisted":false},{"type":"link","href":"/core/glossary/terms/radius-vsa","label":"Vendor\u2011Specific Attribute (VSA)","customProps":{"termName":"Vendor\u2011Specific Attribute (VSA)","tags":["Protocols"],"shortDescription":"Attribute namespace for vendor extensions.","longDescription":"Allows vendors to convey proprietary settings (e.g., privilege levels, ACLs) beyond standard RADIUS attributes in Access\u2011Accept responses."},"docId":"core/glossary/terms/radius-vsa","unlisted":false},{"type":"link","href":"/core/glossary/terms/radius","label":"RADIUS","customProps":{"termName":"RADIUS","tags":["Protocols"],"shortDescription":"Remote Authentication Dial-In User Service protocol.","longDescription":"AAA protocol used by network devices (NAS) to authenticate and authorize users and to record accounting. Uses UDP and shared secrets for message integrity."},"docId":"core/glossary/terms/radius","unlisted":false},{"type":"link","href":"/core/glossary/terms/redirect-uri","label":"Redirect URI","customProps":{"termName":"Redirect URI","tags":["OAuth2/OIDC"],"shortDescription":"Callback URL the provider redirects to.","longDescription":"Registered callback URL where the OpenID Provider (OP) or Authorization Server (AS) returns the user after authorization. Must match exactly (including scheme and path), and pairs with `response_mode` (`query`, `fragment`, or `form_post`)."},"docId":"core/glossary/terms/redirect-uri","unlisted":false},{"type":"link","href":"/core/glossary/terms/refresh-token","label":"Refresh token","customProps":{"termName":"Refresh token","tags":["Tokens And Claims"],"shortDescription":"Long-lived credential to obtain new access tokens.","longDescription":"Longer-lived credential used to obtain new access tokens without user interaction. Must be kept confidential, is commonly rotated on use, and can be revoked when compromised or no longer needed."},"docId":"core/glossary/terms/refresh-token","unlisted":false},{"type":"link","href":"/core/glossary/terms/relying-party","label":"Relying Party (RP)","customProps":{"termName":"Relying Party (RP)","tags":["OAuth2/OIDC"],"shortDescription":"OIDC client that relies on the OP for identity.","longDescription":"Client application that registers redirect URIs, requests scopes, validates ID tokens (issuer, audience, signature, expiry, nonce), exchanges codes for tokens, and manages user sessions."},"docId":"core/glossary/terms/relying-party","unlisted":false},{"type":"link","href":"/core/glossary/terms/response-type","label":"Response type","customProps":{"termName":"Response type","tags":["OAuth2/OIDC"],"shortDescription":"OAuth/OIDC response expected from the authorization endpoint.","longDescription":"Examples include `code`, `token`, and `id_token`; modern apps should use `code` with PKCE."},"docId":"core/glossary/terms/response-type","unlisted":false},{"type":"link","href":"/core/glossary/terms/revocation-endpoint","label":"Revocation endpoint","customProps":{"termName":"Revocation endpoint","tags":["OAuth2/OIDC"],"shortDescription":"Endpoint to invalidate access or refresh tokens.","longDescription":"RFC 7009 endpoint that lets clients invalidate access or refresh tokens, immediately preventing further use."},"docId":"core/glossary/terms/revocation-endpoint","unlisted":false},{"type":"link","href":"/core/glossary/terms/saml-assertion","label":"SAML assertion","customProps":{"termName":"SAML assertion","tags":["SAML"],"shortDescription":"SAML statement with authentication and attribute data.","longDescription":"Delivered to the service provider, typically via POST/Redirect binding, and consumed at the ACS URL."},"docId":"core/glossary/terms/saml-assertion","unlisted":false},{"type":"link","href":"/core/glossary/terms/saml-binding","label":"SAML binding","customProps":{"termName":"SAML binding","tags":["SAML"],"shortDe
1scription":"Transport mechanism for SAML messages.","longDescription":"Defines how SAML messages are transported. Common bindings are HTTP-Redirect and HTTP-POST for SSO, and SOAP/Artifact for back-channel or large payloads."},"docId":"core/glossary/terms/saml-binding","unlisted":false},{"type":"link","href":"/core/glossary/terms/scim-endpoints","label":"SCIM endpoints (Users, Groups)","customProps":{"termName":"SCIM endpoints (Users, Groups)","tags":["Provisioning"],"shortDescription":"RESTful endpoints for provisioning operations.","longDescription":"Key endpoints include /Users and /Groups supporting CRUD, filtering, and pagination. Implementations may also support bulk and search."},"docId":"core/glossary/terms/scim-endpoints","unlisted":false},{"type":"link","href":"/core/glossary/terms/scim-externalid","label":"SCIM externalId","customProps":{"termName":"SCIM externalId","tags":["Provisioning"],"shortDescription":"Client-supplied stable identifier for correlation.","longDescription":"Optional, opaque identifier provided by the provisioning client to map SCIM resources to upstream records; distinct from server-generated \'id\'."},"docId":"core/glossary/terms/scim-externalid","unlisted":false},{"type":"link","href":"/core/glossary/terms/scim-lifecycle","label":"SCIM provisioning lifecycle","customProps":{"termName":"SCIM provisioning lifecycle","tags":["Provisioning"],"shortDescription":"Create, update, deactivate, and delete user records.","longDescription":"SCIM automates onboarding/offboarding by creating accounts, updating attributes and entitlements, and deactivating or deleting users and group memberships."},"docId":"core/glossary/terms/scim-lifecycle","unlisted":false},{"type":"link","href":"/core/glossary/terms/scim-patch","label":"SCIM PATCH","customProps":{"termName":"SCIM PATCH","tags":["Provisioning"],"shortDescription":"Standardized partial update operation.","longDescription":"Supports add, remove, and replace path operations on resource attributes. Enables efficient updates without resending the full resource."},"docId":"core/glossary/terms/scim-patch","unlisted":false},{"type":"link","href":"/core/glossary/terms/scim-resource","label":"SCIM resource","customProps":{"termName":"SCIM resource","tags":["Provisioning"],"shortDescription":"Typed object like User or Group managed via SCIM.","longDescription":"Resources conform to schemas (core and extension) and are exposed at endpoints such as /Users and /Groups with standard attributes and metadata."},"docId":"core/glossary/terms/scim-resource","unlisted":false},{"type":"link","href":"/core/glossary/terms/scim","label":"SCIM","customProps":{"termName":"SCIM","tags":["Provisioning"],"shortDescription":"System for Cross-domain Identity Management.","longDescription":"Open standard (RFC 7643/7644) for automating user and group provisioning across systems. Defines schemas, endpoints, and operations for lifecycle management."},"docId":"core/glossary/terms/scim","unlisted":false},{"type":"link","href":"/core/glossary/terms/scope","label":"Scope","customProps":{"termName":"Scope","tags":["OAuth2/OIDC"],"shortDescription":"Permission strings requested by a client.","longDescription":"Define the level of access or claims requested; examples include `openid`, `email`, and `profile`."},"docId":"core/glossary/terms/scope","unlisted":false},{"type":"link","href":"/core/glossary/terms/service-provider","label":"Service Provider (SP)","customProps":{"termName":"Service Provider (SP)","tags":["Core Concepts"],"shortDescription":"Application that relies on the IdP to authenticate users.","longDescription":"In SAML, the SP consumes assertions. In OIDC, this role is called the Relying Party or Client."},"docId":"core/glossary/terms/service-provider","unlisted":false},{"type":"link","href":"/core/glossary/terms/single-logout","label":"Single Logout (SLO)","customProps":{"termName":"Single Logout (SLO)","tags":["Protocols"],"shortDescription":"Terminates sessions across parties in a federation.","longDescription":"Coordinated logout that ends sessions at the Identity Provider (IdP) or OpenID Provider (OP) and participating Service Providers (SPs) or Relying Parties (RPs). Implemented via front-channel (browser) or back-channel (server) mechanisms depen
1ding on protocol support."},"docId":"core/glossary/terms/single-logout","unlisted":false},{"type":"link","href":"/core/glossary/terms/source","label":"Source","customProps":{"termName":"Source","tags":["Core Concepts"],"shortDescription":"Location from which users and their attributes can be accessed by authentik.","authentikSpecific":true,"longDescription":"Sources are locations from which user data can be accessed by authentik, and either pulled into authentik or synced with authentik. For example, an LDAP connection to import users from Active Directory, or an OAuth2 connection to allow social logins."},"docId":"core/glossary/terms/source","unlisted":false},{"type":"link","href":"/core/glossary/terms/sp-initiated-sso","label":"SP-initiated SSO","customProps":{"termName":"SP-initiated SSO","tags":["SAML"],"shortDescription":"SSO flow started at the Service Provider.","longDescription":"User starts at the SP, which sends an AuthnRequest (often via Redirect) to the IdP. After authentication, the IdP posts the Response to the SP\'s ACS, optionally preserving RelayState."},"docId":"core/glossary/terms/sp-initiated-sso","unlisted":false},{"type":"link","href":"/core/glossary/terms/stage","label":"Stage","customProps":{"termName":"Stage","tags":["Flows"],"shortDescription":"A single verification or logic step within a flow.","authentikSpecific":true,"longDescription":"A stage represents a single verification or logic step. Stages are used to authenticate users, enroll users, and more, and can optionally be bound to a flow via policies."},"docId":"core/glossary/terms/stage","unlisted":false},{"type":"link","href":"/core/glossary/terms/subject","label":"Subject (sub)","customProps":{"termName":"Subject (sub)","tags":["Tokens And Claims"],"shortDescription":"Unique identifier of the token\'s principal.","longDescription":"The \'sub\' claim identifies the principal (end-user or client) represented by the token. In OIDC, \'sub\' is stable per issuer and may be pairwise or public."},"docId":"core/glossary/terms/subject","unlisted":false},{"type":"link","href":"/core/glossary/terms/system-tasks","label":"System tasks","customProps":{"termName":"System tasks","tags":["Operations"],"shortDescription":"Longer-running background tasks in authentik.","authentikSpecific":true,"longDescription":"These are longer-running tasks which authentik runs in the background, such as syncing LDAP sources and other maintenance tasks."},"docId":"core/glossary/terms/system-tasks","unlisted":false},{"type":"link","href":"/core/glossary/terms/token-endpoint","label":"Token endpoint","customProps":{"termName":"Token endpoint","tags":["Endpoints"],"shortDescription":"Exchanges codes or credentials for tokens.","longDescription":"Returns access, refresh, and optionally ID tokens depending on the grant type."},"docId":"core/glossary/terms/token-endpoint","unlisted":false},{"type":"link","href":"/core/glossary/terms/userinfo-endpoint","label":"UserInfo endpoint","customProps":{"termName":"UserInfo endpoint","tags":["OAuth2/OIDC"],"shortDescription":"OIDC endpoint returning user claims.","longDescription":"Returns standardized claims about the authenticated user when called with a valid access token."},"docId":"core/glossary/terms/userinfo-endpoint","unlisted":false},{"type":"link","href":"/core/glossary/terms/webauthn","label":"WebAuthn","customProps":{"termName":"WebAuthn","tags":["Authentication"],"shortDescription":"W3C standard for phishing\u2011resistant authentication with FIDO2 authenticators.","longDescription":"Enables authentication with platform or roaming authenticators (e.g., Windows Hello, Touch ID, YubiKey). Supports user verification (biometrics/PIN), resident (discoverable) credentials for passwordless, and attestation/metadata. In authentik, exposed via the WebAuthn authenticator stages."},"docId":"core/glossary/terms/webauthn","unlisted":false}]}],"href":"/core/glossary/"}],"collapsed":true,"collapsible":true},{"type":"category","label":"Enterprise","items":[{"type":"link","href":"/enterprise/","label":"authentik Enterprise","docId":"enterprise/index","unlisted":false},{"type":"link","href":"/enterprise/get-started","label":"Get started with authentik Enterprise","docId":"enterprise/get-started","unlisted":false},{"type":"link","href":"/enterprise/enterprise-features","label":"Enterprise features","docId":"enterprise/enterprise-features","unlisted":false},{"type":"link","href":"/enterprise/manage-enterprise","label":"Manage licenses and billing","docId":"enterprise/manage-enterprise","unlisted":false},{"type":"link","href":"/enterprise/enterprise-support","label":"Enterprise support","docId":"enterprise/enterprise-support","unlisted":false}],"collapsed":true,"collapsible":true,"href":"/enterprise/"},{"type":"category","label":"Installation and Configuration","items":[{"type":"link","href":"/install-config/","label":"Overview","docId":"install-config/index","unlisted":false},{"type":"category","label":"Installation","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/install-config/install/docker-compose","label":"Docker Compose installation","docId":"install-config/install/docker-compose","unlisted":false},{"type":"link","href":"/install-config/install/kubernetes","label":"Kubernetes installation","docId":"install-config/install/kubernetes","unlisted":false},{"type":"link","href":"/install-config/install/aws","label":"AWS installation","docId":"install-config/install/aws","unlisted":false}]},{"type":"link","href":"/install-config/configuration/","label":"Configuration","docId":"install-config/configuration/configuration","unlisted":false},{"type":"link","href":"/install-config/automated-install","label":"Automated install","docId":"install-config/automated-install","unlisted":false},{"type":"link","href":"/install-config/first-steps/","label":"First steps","docId":"install-config/first-steps/index","unlisted":false},{"type":"link","href":"/install-config/upgrade","label":"Upgrade authentik","docId":"install-config/upgrade","unlisted":false},{"type":"link","href":"/install-config/reverse-proxy","label":"Reverse proxy","docId":"install-config/reverse-proxy","unlisted":false},{"type":"link","href":"/install-config/email","label":"Email","docId":"install-config/email","unlisted":false},{"type":"link","href":"/install-config/high-availability","label":"High availability","docId":"install-config/high-availability","unlisted":false},{"type":"link","href":"/install-config/air-gapped","label":"Air-gapped environments","docId":"install-config/air-gapped","unlisted":false},{"type":"link","href":"/install-config/beta","label":"Beta and release candidate versions","docId":"install-config/beta","unlisted":false}],"collapsed":true,"collapsible":true,"href":"/install-config/"},{"type":"category","label":"Add and Secure Applications","items":[{"type":"category","label":"Applications","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/add-secure-apps/applications/manage_apps","label":"Manage applications","docId":"add-secure-apps/applications/manage_apps","unlisted":false}],"href":"/add-secure-apps/applications/"},{"type":"category","label":"Providers","collapsible":true,"collapsed":true,"items":[{"type":"category","label":"Property Mappings","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/add-secure-apps/providers/property-mappings/expression","label":"Property mapping expressions","docId":"add-secure-apps/providers/property-mappings/expression","unlisted":false}],"href":"/add-secure-apps/providers/property-mappings/"},{"type":"category","label":"OAuth2 Provider","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/add-secure-apps/providers/oauth2/create-oauth2-provider","label":"Create an OAuth2 provider","docId":"add-secure-apps/providers/oauth2/create-oauth2-provider","unlisted":false},{"type":"link","href":"/add-secure-apps/providers/oauth2/machine_to_machine","label":"Machine-to-machine authentication","docId":"add-secure-apps/providers/oauth2/machine_to_machine","unlisted":false},{"type":"link","href":"/add-secure-apps/providers/oauth2/token_exchange","label":"Token exchange","docId":"add-secure-apps/providers/oauth2/token_exchange","unlisted":false},{"type":"link","href":"/add-secure-apps/providers/oauth2/dynamic-client-registration","label":"Dynamic Client Registration","docId":"add-secure-apps/providers/oauth2/dynamic-client-registration","unlisted":false},{"type":"link","href":"/add-secure-apps/providers/oauth2/frontchannel_and_backchannel_logout","label":"Front-channel and back-channel logout","docId":"add-secure-apps/providers/oauth2/frontchannel_and_backchannel_logout","unlisted":false},{"type":"link","href":"/add-secure-apps/providers/oauth2/device_code","label":"Device code flow","docId":"add-secure-apps/providers/oauth2/device_code","unlisted":false},{"type":"link","href":"/add-secure-apps/providers/oauth2/github-compatibility","label":"GitHub compatibility","docId":"add-secure-apps/providers/oauth2/github-compatibility","unlisted":false},{"type":"link","href":"/add-secure-apps/providers/oauth2/webfinger_support","label":"WebFinger support","docId":"add-secure-apps/providers/oauth2/webfinger_support","unlisted":false},{"type":"link","href":"/add-secure-apps/providers/oauth2/key-binding","label":"Key binding","docId":"add-secure-apps/providers/oauth2/key-binding","unlisted":false}],"href":"/add-secure-apps/providers/oauth2/"},{"type":"category","label":"SAML Provider","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/add-secure-apps/providers/saml/create-saml-provider","label":"Create a SAML provider","docId":"add-secure-apps/providers/saml/create-saml-provider","unlisted":false},{"type":"link","href":"/add-secure-apps/providers/saml/saml_single_logout","label":"SAML Single Logout","docId":"add-secure-apps/providers/saml/saml_single_logout","unlisted":false}],"href":"/add-secure-apps/providers/saml/"},{"type":"category","label":"SCIM Provider","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/add-secure-apps/providers/scim/create-scim-provider","label":"Create a SCIM provider","docId":"add-secure-apps/providers/scim/create-scim-provider","unlisted":false}],"href":"/add-secure-apps/providers/scim/"},{"type":"category","label":"LDAP Provider","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/add-secure-apps/providers/ldap/create-ldap-provider","label":"Create an LDAP provider","docId":"add-secure-apps/providers/ldap/create-ldap-provider","unlisted":false}],"href":"/add-secure-apps/providers/ldap/"},{"type":"category","label":"Proxy Provider","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/add-secure-apps/providers/proxy/create-proxy-provider","label":"Create a proxy provider","docId":"add-secure-apps/providers/proxy/create-proxy-provider","unlisted":false},{"type":"link","href":"/add-secure-apps/providers/proxy/custom_headers","label":"Custom headers","docId":"add-secure-apps/providers/proxy/custom_headers","unlisted":false},{"type":"link","href":"/add-secure-apps/providers/proxy/forward_auth","label":"Forward auth","docId":"add-secure-apps/providers/proxy/forward_auth","unlisted":false},{"type":"link","href":"/add-secure-apps/providers/proxy/header_authentication","label":"Header authentication","docId":"add-secure-apps/providers/proxy/header_authentication","unlisted":false},{"type":"link","href":"/add-secure-apps/providers/proxy/server_caddy","label":"Caddy","docId":"add-secure-apps/providers/proxy/server_caddy","unlisted":false},{"type":"link","href":"/add-secure-apps/providers/proxy/server_envoy","label":"Envoy","docId":"add-secure-apps/providers/proxy/server_envoy","unlisted":false},{"type":"link","href":"/add-secure-apps/providers/proxy/server_haproxy","label":"HAProxy","docId":"add-secure-apps/providers/proxy/server_haproxy","unlisted":false},{"type":"link","href":"/add-secure-apps/providers/proxy/server_nginx","label":"nginx","docId":"add-secure-apps/providers/proxy/server_nginx","unlisted":false},{"type":"link","href":"/add-secure-apps/providers/proxy/server_traefik","label":"Traefik","docId":"add-secure-apps/providers/proxy/server_traefik","unlisted":false}],"href":"/add-secure-apps/providers/proxy/"},{"type":"category","label":"Remote Access Control (RAC) Provider","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/add-secure-apps/providers/rac/create-rac-provider","label":"Create a Remote Access Control (RAC) provider","docId":"add-secure-apps/providers/rac/create-rac-provider","unlisted":false},{"type":"link","href":"/add-secure-apps/providers/rac/rac-public-key","label":"RAC SSH Public Key Authentication","docId":"add-secure-apps/providers/rac/rac-public-key","unlisted":false},{"type":"link","href":"/add-secure-apps/providers/rac/rac_credentials_prompt","label":"RAC Credentials Prompt","docId":"add-secure-apps/providers/rac/rac_credentials_prompt","unlisted":false}],"href":"/add-secure-apps/providers/rac/"},{"type":"link","href":"/add-secure-apps/providers/radius/","label":"RADIUS Provider","docId":"add-secure-apps/providers/radius/index","unlisted":false},{"type":"category","label":"SSF Provider","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/add-secure-apps/providers/ssf/create-ssf-provider","label":"Configure an SSF provider","docId":"add-secure-apps/providers/ssf/create-ssf-provider","unlisted":false}],"href":"/add-secure-apps/providers/ssf/"},{"type":"category","label":"WS-Fed Provider","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/add-secure-apps/providers/wsfed/create-wsfed-provider","label":"Create a WS-Federation provider","docId":"add-secure-apps/providers/wsfed/create-wsfed-provider","unlisted":false}],"href":"/add-secure-apps/providers/wsfed/"},{"type":"category","label":"Entra ID Provider","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/add-secure-apps/providers/entra/configure-entra","label":"Configure Entra ID","docId":"add-secure-apps/providers/entra/configure-entra","unlisted":false},{"type":"link","href":"/add-secure-apps/providers/entra/create-entra-provider","label":"Create an Entra ID provider","docId":"add-secure-apps/providers/entra/create-entra-provider","unlisted":false}],"href":"/add-secure-apps/providers/entra/"}
1,{"type":"category","label":"Google Workspace Provider","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/add-secure-apps/providers/gws/configure-gws","label":"Configure Google Workspace","docId":"add-secure-apps/providers/gws/configure-gws","unlisted":false},{"type":"link","href":"/add-secure-apps/providers/gws/create-gws-provider","label":"Create a Google Workspace provider","docId":"add-secure-apps/providers/gws/create-gws-provider","unlisted":false}],"href":"/add-secure-apps/providers/gws/"},{"type":"link","href":"/add-secure-apps/providers/single-logout/","label":"Single Logout","docId":"add-secure-apps/providers/single-logout/index","unlisted":false}],"href":"/add-secure-apps/providers"},{"type":"category","label":"Flows and Stages","collapsible":true,"collapsed":true,"items":[{"type":"category","label":"Flows","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/add-secure-apps/flows-stages/flow/default-flows","label":"Default flows","docId":"add-secure-apps/flows-stages/flow/default-flows","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/flow/planner","label":"Flow Planner","docId":"add-secure-apps/flows-stages/flow/planner","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/flow/context/","label":"Flow context","docId":"add-secure-apps/flows-stages/flow/context/index","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/flow/flows","label":"Example flows","docId":"add-secure-apps/flows-stages/flow/flows","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/flow/snippets","label":"Example policy snippets","docId":"add-secure-apps/flows-stages/flow/snippets","unlisted":false},{"type":"category","label":"Executors","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/add-secure-apps/flows-stages/flow/executors/headless","label":"Headless","docId":"add-secure-apps/flows-stages/flow/executors/headless","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/flow/executors/if-flow","label":"Default","docId":"add-secure-apps/flows-stages/flow/executors/if-flow","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/flow/executors/sfe","label":"Simplified flow executor","docId":"add-secure-apps/flows-stages/flow/executors/sfe","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/flow/executors/user-settings","label":"User settings","docId":"add-secure-apps/flows-stages/flow/executors/user-settings","unlisted":false}]},{"type":"link","href":"/add-secure-apps/flows-stages/flow/inspector","label":"Flow Inspector","docId":"add-secure-apps/flows-stages/flow/inspector","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/flow/collect-user-attributes","label":"Collect custom user attributes during enrollment","docId":"add-secure-apps/flows-stages/flow/collect-user-attributes","unlisted":false}],"href":"/add-secure-apps/flows-stages/flow/"},{"type":"category","label":"Stages","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/add-secure-apps/flows-stages/stages/account_lockdown/","label":"Account Lockdown stage","docId":"add-secure-apps/flows-stages/stages/account_lockdown/index","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/stages/authenticator_validate/","label":"Authenticator validation stage","docId":"add-secure-apps/flows-stages/stages/authenticator_validate/index","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/stages/captcha/","label":"Captcha stage","docId":"add-secure-apps/flows-stages/stages/captcha/index","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/stages/consent/","label":"Consent stage","docId":"add-secure-apps/flows-stages/stages/consent/index","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/stages/deny/","label":"Deny stage","docId":"add-secure-apps/flows-stages/stages/deny/index","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/stages/authenticator_duo/","label":"Duo authenticator setup stage","docId":"add-secure-apps/flows-stages/stages/authenticator_duo/index","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/stages/authenticator_email/","label":"Email authenticator setup stage","docId":"add-secure-apps/flows-stages/stages/authenticator_email/index","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/stages/email/","label":"Email stage","docId":"add-secure-apps/flows-stages/stages/email/index","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/stages/endpoint/","label":"Endpoint stage","docId":"add-secure-apps/flows-stages/stages/endpoint/index","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/stages/authenticator_endpoint_gdtc/","label":"Google Chrome Device Trust authenticator stage","docId":"add-secure-apps/flows-stages/stages/authenticator_endpoint_gdtc/index","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/stages/identification/","label":"Identification stage","docId":"add-secure-apps/flows-stages/stages/identification/index","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/stages/invitation/","label":"Invitation stage","docId":"add-secure-apps/flows-stages/stages/invitation/index","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/stages/mtls/","label":"Mutual TLS stage","docId":"add-secure-apps/flows-stages/stages/mtls/index","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/stages/password/","label":"Password stage","docId":"add-secure-apps/flows-stages/stages/password/index","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/stages/prompt/","label":"Prompt stage","docId":"add-secure-apps/flows-stages/stages/prompt/index","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/stages/redirect/","label":"Redirect stage","docId":"add-secure-apps/flows-stages/stages/redirect/index","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/stages/authenticator_sms/","label":"SMS authenticator setup stage","docId":"add-secure-apps/flows-stages/stages/authenticator_sms/index","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/stages/source/","label":"Source stage","docId":"add-secure-apps/flows-stages/stages/source/index","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/stages/authenticator_static/","label":"Static authenticator setup stage","docId":"add-secure-apps/flows-stages/stages/authenticator_static/index","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/stages/authenticator_totp/","label":"TOTP authenticator setup stage","docId":"add-secure-apps/flows-stages/stages/authenticator_totp/index","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/stages/user_delete/","label":"User delete stage","docId":"add-secure-apps/flows-stages/stages/user_delete/index","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/stages/user_login/","label":"User login stage","docId":"add-secure-apps/flows-stages/stages/user_login/index","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/stages/user_logout/","label":"User logout stage","docId":"add-secure-apps/flows-stages/stages/user_logout/index","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/stages/user_write/","label":"User write stage","docId":"add-secure-apps/flows-stages/stages/user_write/index","unlisted":false},{"type":"link","href":"/add-secure-apps/flows-stages/stages/authenticator_webauthn/","label":"WebAuthn / FIDO2 / Passkeys authenticator setup stage","docId":"add-secure-apps/flows-stages/stages/authenticator_webauthn/index","unlisted":false}],"href":"/add-secure-apps/flows-stages/stages/"}]},{"type":"category","label":"Bindings","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/add-secure-apps/bindings-overview/work-with-bindings","label":"Work with bindings","docId":"add-secure-apps/bindings-overview/work-with-bindings","unlisted":false}],"href":"/add-secure-apps/bindings-overview/"},{"type":"category","label":"Outposts","collapsible":true,"collapsed":true,"items":[{"type":"category","label":"Integrations","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/add-secure-apps/outposts/integrations/docker","label":"Docker","docId":"add-secure-apps/outposts/integrations/docker","unlisted":false},{"type":"link","href":"/add-secure-apps/outposts/integrations/kubernetes","label":"Kubernetes","docId":"add-secure-apps/outposts/integrations/kubernetes","unlisted":false}]},{"type":"link","href":"/add-secure-apps/outposts/embedded/","label":"Embedded Outpost","docId":"add-secure-apps/outposts/embedded/embedded","unlisted":false},{"type":"link","href":"/add-secure-apps/outposts/manual-deploy-docker-compose","label":"Manual Outpost deployment in Docker Compose","docId":"add-secure-apps/outposts/manual-deploy-docker-compose","unlisted":false},{"type":"link","href":"/add-secure-apps/outposts/manual-deploy-kubernetes","label":"Manual Outpost deployment on Kubernetes","docId":"add-secure-apps/outposts/manual-deploy-kubernetes","unlisted":false},{"type":"link","href":"/add-secure-apps/outposts/upgrading","label":"Upgrading an Outpost","docId":"add-secure-apps/outposts/upgrading","unlisted":false}],"href":"/add-secure-apps/outposts/"},{"type":"link","href":"/add-secure-apps/access-requests/","label":"Access requests","docId":"add-secure-apps/access-requests/index","unlisted":false}],"collapsed":true,"collapsible":true},{"type":"category","label":"Customize your Instance","items":[{"type":"link","href":"/customize/","label":"Overview","docId":"customize/index","unlisted":false},{"type":"category","label":"Policies","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/customize/policies/bindings","label":"Policy bindings and evaluation","docId":"customize/policies/bindings","unlisted":false},{"type":"category","label":"Types of policies in authentik","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/customize/policies/types/event-matcher","label":"Event Matcher Policy","docId":"customize/policies/types/event-matcher","unlisted":false},{"type":"category","label":"Expression Policies","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/customize/policies/types/expression/managing_flow_context_keys","label":"Managing flow context keys","docId":"customize/policies/types/expression/managing_flow_context_keys","unlisted":false},{"type":"link","href":"/customize/policies/types/expression/reference","label":"Expression Reference","docId":"customize/policies/types/expression/reference","unlisted":false},{"type":"link","href":"/customize/policies/types/expression/source_switch","label":"Switch which source is used based on email address","docId":"customize/policies/types/expression/source_switch","unlisted":false},{"type":"link","href":"/customize/policies/types/expression/unique_email","label":"Ensure unique email addresses","docId":"customize/policies/types/expression/unique_email","unlisted":false},{"type":"link","href":"/customize/policies/types/expression/whitelist_email","label":"Allow only specific email domains","docId":"customize/policies/types/expression/whitelist_email","unlisted":false}],"href":"/customize/policies/types/expression/"},{"type":"link","href":"/customize/policies/types/geoip","label":"GeoIP Policy","docId":"customize/policies/types/geoip","unlisted":false},{"type":"link","href":"/customize/policies/types/password-expiry","label":"Password Expiry Policy","docId":"customize/policies/types/password-expiry","unlisted":false},{"type":"link","href":"/customize/policies/types/password-uniqueness","label":"Password Uniqueness Policy","docId":"customize/policies/types/password-uniqueness","unlisted":false},{"type":"link","href":"/customize/policies/types/password","label":"Password Policy","docId":"customize/policies/types/password","unlisted":false},{"type":"link","href":"/customize/policies/types/reputation","label":"Reputation Policy","docId":"customize/policies/types/reputation","unlisted":false}],"href":"/customize/policies/types/"},{"type":"link","href":"/customize/policies/working_with_policies","label":"Working with policies","docId":"customize/policies/working_with_policies","unlisted":false}],"href":"/customize/policies/"},{"type":"category","label":"Interfaces","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/customize/interfaces/admin/","label":"Admin interface","docId":"customize/interfaces/admin/index","unlisted":false},{"type":"link","href":"/customize/interfaces/flow/","label":"Flow interface","docId":"customize/interfaces/flow/index","unlisted":false},{"type":"link","href":"/customize/interfaces/user/","label":"User interface","docId":"customize/interfaces/user/index","unlisted":false}]},{"type":"category","label":"Blueprints","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/customize/blueprints/export","label":"Export configurations to blueprints","docId":"customize/blueprints/export","unlisted":false},{"type":"category","label":"v1","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/customize/blueprints/v1/example","label":"Example","docId":"customize/blueprints/v1/example","unlisted":false},{"type":"link","href":"/customize/blueprints/v1/meta","label":"Meta models","docId":"customize/blueprints/v1/meta","unlisted":false},{"type":"link","href":"/customize/blueprints/v1/models","label":"Models","docId":"customize/blueprints/v1/models","unlisted":false},{"type":"link","href":"/customize/blueprints/v1/structure","label":"File structure","docId":"customize/blueprints/v1/structure","unlisted":false},{"type":"link","href":"/customize/blueprints/v1/tags","label":"YAML Tags","docId":"customize/blueprints/v1/tags","unlisted":false}]},{"type":"link","href":"/customize/blueprints/working_with_blueprints","label":"Working with blueprints","docId":"customize/blueprints/working_with_blueprints","unlisted":false}],"href":"/customize/blueprints/"},{"type":"category","label":"Branding","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/brands/custom-css","label":"Custom CSS","docId":"customize/branding/custom-css","unlisted":false}],"href":"/customize/branding/"},{"type":"link","href":"/customize/file-picker","label":"File picker values","docId":"customize/file-picker","unlisted":false},{"type":"link","href":"/customize/files","label":"Files","docId":"customize/files","unlisted":false}],"collapsed":true,"collapsible":true,"href":"/customize/"},{"type":"category","label":"Manage Users and Sources","items":[{"type":"category","label":"Users","collapsible":true,"collapsed":true,"items":[{"type":"category","label":"Account types","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/users-sources/user/account-types/internal-users","label":"Internal users","docId":"users-sources/user/account-types/internal-users","unlisted":false},{"type":"link","href":"/users-sources/user/account-types/external-users","label":"External users","docId":"users-sources/user/account-types/external-users","unlisted":false},{"type":"link","href":"/users-sources/user/account-types/service-accounts","label":"Service accounts","docId":"users-sources/user/account-types/service-accounts","unlisted":false},{"type":"link","href":"/users-sources/user/account-types/agent-accounts","label":"Agent accounts","docId":"users-sources/user/account-types/agent-accounts","unlisted":false}],"href":"/users-sources/user/account-types/"},{"type":"link","href":"/users-sources/user/user_basic_operations","label":"Manage users","docId":"users-sources/user/user_basic_operations","unlisted":false},{"type":"link","href":"/users-sources/user/user_ref","label":"User properties and attributes","docId":"users-sources/user/user_ref","unlisted":false},{"type":"link","href":"/users-sources/user/user-interface","label":"User interface","docId":"users-sources/user/user-interface","unlisted":false},{"type":"link","href":"/users-sources/user/user-switching","label":"User account switching","docId":"users-sources/user/user-switching","unlisted":false},{"type":"link","href":"/users-sources/user/invitations","label":"Invitations","
1docId":"users-sources/user/invitations","unlisted":false},{"type":"link","href":"/users-sources/user/password_reset_on_login","label":"Password reset on login","docId":"users-sources/user/password_reset_on_login","unlisted":false}],"href":"/users-sources/user/"},{"type":"category","label":"Groups","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/users-sources/groups/group_ref","label":"Group properties and attributes","docId":"users-sources/groups/group_ref","unlisted":false},{"type":"link","href":"/users-sources/groups/manage_groups","label":"Manage groups","docId":"users-sources/groups/manage_groups","unlisted":false}],"href":"/users-sources/groups/"},{"type":"category","label":"Roles","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/users-sources/roles/manage_roles","label":"Manage roles","docId":"users-sources/roles/manage_roles","unlisted":false}],"href":"/users-sources/roles/"},{"type":"category","label":"Access control","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/users-sources/access-control/permissions","label":"About permissions","docId":"users-sources/access-control/permissions","unlisted":false},{"type":"link","href":"/users-sources/access-control/manage_permissions","label":"Manage permissions","docId":"users-sources/access-control/manage_permissions","unlisted":false},{"type":"link","href":"/users-sources/access-control/initial_permissions","label":"Initial permissions","docId":"users-sources/access-control/initial_permissions","unlisted":false}],"href":"/users-sources/access-control/"},{"type":"category","label":"Federated and Social Sources","collapsible":true,"collapsed":true,"items":[{"type":"category","label":"Directory synchronization","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/users-sources/sources/directory-sync/active-directory/","label":"Active Directory","docId":"users-sources/sources/directory-sync/active-directory/index","unlisted":false},{"type":"link","href":"/users-sources/sources/directory-sync/freeipa/","label":"FreeIPA","docId":"users-sources/sources/directory-sync/freeipa/index","unlisted":false}]},{"type":"category","label":"Protocols","collapsible":true,"collapsed":true,"items":[{"type":"category","label":"Kerberos","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/users-sources/sources/protocols/kerberos/browser","label":"Browser configuration for SPNEGO","docId":"users-sources/sources/protocols/kerberos/browser","unlisted":false}],"href":"/users-sources/sources/protocols/kerberos/"},{"type":"link","href":"/users-sources/sources/protocols/ldap/","label":"LDAP source","docId":"users-sources/sources/protocols/ldap/index","unlisted":false},{"type":"link","href":"/users-sources/sources/protocols/oauth/","label":"OAuth source","docId":"users-sources/sources/protocols/oauth/index","unlisted":false},{"type":"link","href":"/users-sources/sources/protocols/saml/","label":"SAML source","docId":"users-sources/sources/protocols/saml/index","unlisted":false},{"type":"link","href":"/users-sources/sources/protocols/scim/","label":"SCIM source","docId":"users-sources/sources/protocols/scim/index","unlisted":false}]},{"type":"category","label":"Source property mappings","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/users-sources/sources/property-mappings/expressions","label":"Sources expression property mappings","docId":"users-sources/sources/property-mappings/expressions","unlisted":false}],"href":"/users-sources/sources/property-mappings/"},{"type":"category","label":"Identity providers","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/users-sources/sources/social-logins/apple/","label":"Apple","docId":"users-sources/sources/social-logins/apple/index","unlisted":false},{"type":"link","href":"/users-sources/sources/social-logins/cas/","label":"Apereo CAS","docId":"users-sources/sources/social-logins/cas/index","unlisted":false},{"type":"link","href":"/users-sources/sources/social-logins/discord/","label":"Discord","docId":"users-sources/sources/social-logins/discord/index","unlisted":false},{"type":"category","label":"Entra ID","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/users-sources/sources/social-logins/entra-id/oauth/","label":"Entra ID OAuth","docId":"users-sources/sources/social-logins/entra-id/oauth/index","unlisted":false},{"type":"link","href":"/users-sources/sources/social-logins/entra-id/scim/","label":"Entra ID SCIM","docId":"users-sources/sources/social-logins/entra-id/scim/index","unlisted":false}],"href":"/users-sources/sources/social-logins/entra-id/"},{"type":"link","href":"/users-sources/sources/social-logins/facebook/","label":"Facebook","docId":"users-sources/sources/social-logins/facebook/index","unlisted":false},{"type":"link","href":"/users-sources/sources/social-logins/github/","label":"GitHub","docId":"users-sources/sources/social-logins/github/index","unlisted":false},{"type":"link","href":"/users-sources/sources/social-logins/gitlab/","label":"GitLab","docId":"users-sources/sources/social-logins/gitlab/index","unlisted":false},{"type":"category","label":"Google","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/users-sources/sources/social-logins/google/cloud/","label":"Google Cloud (OAuth)","docId":"users-sources/sources/social-logins/google/cloud/index","unlisted":false},{"type":"link","href":"/users-sources/sources/social-logins/google/workspace/","label":"Google Worksp
1ace (SAML)","docId":"users-sources/sources/social-logins/google/workspace/index","unlisted":false}],"href":"/users-sources/sources/social-logins/google/"},{"type":"link","href":"/users-sources/sources/social-logins/jumpcloud/","label":"JumpCloud","docId":"users-sources/sources/social-logins/jumpcloud/index","unlisted":false},{"type":"link","href":"/users-sources/sources/social-logins/keycloak/","label":"Keycloak","docId":"users-sources/sources/social-logins/keycloak/index","unlisted":false},{"type":"link","href":"/users-sources/sources/social-logins/mailcow/","label":"Mailcow","docId":"users-sources/sources/social-logins/mailcow/index","unlisted":false},{"type":"link","href":"/users-sources/sources/social-logins/okta/","label":"Okta","docId":"users-sources/sources/social-logins/okta/index","unlisted":false},{"type":"link","href":"/users-sources/sources/social-logins/plex/","label":"Plex","docId":"users-sources/sources/social-logins/plex/index","unlisted":false},{"type":"link","href":"/users-sources/sources/social-logins/shibboleth/","label":"Shibboleth","docId":"users-sources/sources/social-logins/shibboleth/index","unlisted":false},{"type":"link","href":"/users-sources/sources/social-logins/telegram/","label":"Telegram","docId":"users-sources/sources/social-logins/telegram/index","unlisted":false},{"type":"link","href":"/users-sources/sources/social-logins/twitch/","label":"Twitch","docId":"users-sources/sources/social-logins/twitch/index","unlisted":false},{"type":"link","href":"/users-sources/sources/social-logins/twitter/","label":"X (formerly Twitter)","docId":"users-sources/sources/social-logins/twitter/index","unlisted":false},{"type":"link","href":"/users-sources/sources/social-logins/wechat/","label":"WeChat","docId":"users-sources/sources/social-logins/wechat/index","unlisted":false}],"href":"/users-sources/sources/social-logins/"}],"href":"/users-sources/sources/"}],"collapsed":true,"collapsible":true},{"type":"category","label":"System Management","items":[{"type":"link","href":"/sys-mgmt/akql","label":"AKQL search","docId":"sys-mgmt/akql","unlisted":false},{"type":"link","href":"/background-tasks","label":"Background tasks","docId":"sys-mgmt/background-tasks","unlisted":false},{"type":"link","href":"/sys-mgmt/certificates","label":"Certificates","docId":"sys-mgmt/certificates","unlisted":false},{"type":"link","href":"/sys-mgmt/data-exports","label":"Data Exports","docId":"sys-mgmt/data-exports","unlisted":false},{"type":"category","label":"Events","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/sys-mgmt/events/event-actions","label":"Event actions","docId":"sys-mgmt/events/event-actions","unlisted":false},{"type":"link","href":"/sys-mgmt/events/log-forwarding","label":"Log forwarding","docId":"sys-mgmt/events/log-forwarding","unlisted":false},{"type":"link","href":"/sys-mgmt/events/logging-events","label":"Logging events","docId":"sys-mgmt/events/logging-events","unlisted":false},{"type":"link","href":"/sys-mgmt/events/notification_rule_expression_policies","label":"Expression Policies","docId":"sys-mgmt/events/notification_rule_expression_policies","unlisted":false},{"type":"link","href":"/sys-mgmt/events/notifications","label":"Notification Rules","docId":"sys-mgmt/events/notifications","unlisted":false},{"type":"link","href":"/sys-mgmt/events/transports","label":"Notification Transports","docId":"sys-mgmt/events/transports","unlisted":false}],"href":"/sys-mgmt/events/"},{"type":"link","href":"/sys-mgmt/object-attributes","label":"Object attributes","docId":"sys-mgmt/object-attributes","unlisted":false},{"type":"link","href":"/sys-mgmt/object-lifecycle-management","label":"Object Lifecycle Management","docId":"sys-mgmt/object-lifecycle-management","unlisted":false},{"type":"category","label":"Operations","collapsible":true,"collapsed":true,"items":[{"type":"category","label":"Autoscaling","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/sys-mgmt/ops/autoscaling/hpa","label":"Helm chart HPA","docId":"sys-mgmt/ops/autoscaling/hpa","unlisted":false},{"type":"link","href":"/sys-mgmt/ops/autoscaling/keda","label":"KEDA","docId":"sys-mgmt/ops/autoscaling/keda","unlisted":false}],"href":"/sys-mgmt/ops/autoscaling"},{"type":"category","label":"S3 storage","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/sys-mgmt/ops/storage-s3/providers","label":"Providers","docId":"sys-mgmt/ops/storage-s3/providers","unlisted":false}],"href":"/sys-mgmt/ops/storage-s3/"},{"type":"link","href":"/sys-mgmt/ops/backup-restore","label":"Backup & Restore","docId":"sys-mgmt/ops/backup-restore","unlisted":false},{"type":"link","href":"/sys-mgmt/ops/geoip","label":"GeoIP","docId":"sys-mgmt/ops/geoip","unlisted":false},{"type":"link","href":"/sys-mgmt/ops/monitoring","label":"Monitoring","docId":"sys-mgmt/ops/monitoring","unlisted":false},{"type":"link","href":"/worker","label":"Worker","docId":"sys-mgmt/ops/worker","unlisted":false}]},{"type":"link","href":"/sys-mgmt/settings","label":"System settings","docId":"sys-mgmt/settings","unlisted":false},{"type":"link","href":"/sys-mgmt/tenancy","label":"Tenancy","docId":"sys-mgmt/tenancy","unlisted":false},{"type":"link","href":"/sys-mgmt/user-offboarding","label":"User offboarding","docId":"sys-mgmt/user-offboarding","unlisted":false}],"collapsed":true,"collapsible":true},{"type":"category","label":"Endpoint Devices (Early Preview)","items":[{"type":"link","href":"/endpoint-devices/","label":"Overview","docId":"endpoint-devices/index","unlisted":false},{"type":"category","label":"authentik Agent","collapsible":true,"collapsed":true,"items":[{"type":"category","label":"Deployment","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/endpoint-devices/authentik-agent/agent-deployment/automated","label":"Automated","docId":"endpoint-devices/authentik-agent/agent-deployment/automated","unlisted":false},{"type":"link","href":"/endpoint-devices/authentik-agent/agent-deployment/linux","label":"Linux","docId":"endpoint-devices/authentik-agent/agent-deployment/linux","unlisted":false},{"type":"link","href":"/endpoint-devices/authentik-agent/agent-deployment/macos","label":"macOS","docId":"endpoint-devices/authentik-agent/agent-deployment/macos","unlisted":false},{"type":"link","href":"/endpoint-devices/authentik-agent/agent-deployment/windows","label":"Windows","docId":"endpoint-devices/authentik-agent/agent-deployment/windows","unlisted":false}],"href":"/endpoint-devices/authentik-agent/agent-deployment/"},{"type":"link","href":"/endpoint-devices/authentik-agent/download","label":"Download","docId":"endpoint-devices/authentik-agent/download","unlisted":false},{"type":"link","href":"/endpoint-devices/authentik-agent/configuration","label":"Configuration","docId":"endpoint-devices/authentik-agent/configuration","unlisted":false},{"type":"category","label":"Device authentication","collapsible":true,"collapsed":true,"items":[{"type":"category","label":"CLI application authentication","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/endpoint-devices/authentik-agent/device-authentication/cli-app-authentication/aws","label":"AWS","docId":"endpoint-devices/authentik-agent/device-authentication/cli-app-authentication/aws","unlisted":false},{"type":"link","href":"/endpoint-devices/authentik-agent/device-authentication/cli-app-authentication/k8s","label":"Kubernetes","docId":"endpoint-devices/authentik-agent/device-authentication/cli-app-authentication/k8s","unlisted":false}],"href":"/endpoint-devices/authentik-agent/device-authentication/cli-app-authentication/"},{"type":"category","label":"Local Device Login","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/endpoint-devices/authentik-agent/device-authentication/local-device-login/linux","label":"Linux","docId":"endpoint-devices/authentik-agent/device-authentication/local-device-login/linux","unlisted":false},{"type":"link","href":"/endpoint-devices/authentik-agent/device-authentication/local-device-login/windows","label":"Windows","docId":"endpoint-devices/authentik-agent/device-authentication/local-device-login/windows","unlisted":false}],"href":"/endpoint-devices/authentik-agent/device-authentication/local-device-login/"},{"type":"link","href":"/endpoint-devices/authentik-agent/device-authentication/device-access-groups","label":"Device access groups","docId":"endpoint-devices/authentik-agent/device-authentication/device-access-groups","unlisted":false},{"type":"link","href":"/endpoint-devices/authentik-agent/device-authentication/ssh-authentication","label":"SSH authentication","docId":"endpoint-devices/authentik-agent/device-authentication/ssh-authentication","unlisted":false}],"href":"/endpoint-devices/authentik-agent/device-authentication/"},{"type":"link","href":"/endpoint-devices/authentik-agent/authentik-cli","label":"Agent CLI commands","docId":"endpoint-devices/authentik-agent/authentik-cli","unlisted":false},{"type":"link","href":"/endpoint-devices/authentik-agent/development","label":"Development","docId":"endpoint-devices/authentik-agent/development","unlisted":false},{"type":"category","label":"Release Notes","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/endpoint-devices/authentik-agent/release-notes/template","label":"x.x.x","docId":"endpoint-devices/authentik-agent/release-notes/template","unlisted":false},{"type":"link","href":"/endpoint-devices/authentik-agent/release-notes/v0.35","label":"0.35","docId":"endpoint-devices/authentik-agent/release-notes/v0.35","unlisted":false},{"type":"link","href":"/endpoint-devices/authentik-agent/release-notes/v0.40","label":"0.40","docId":"endpoint-devices/authentik-agent/release-notes/v0.40","unlisted":false}],"href":"/endpoint-devices/authentik-agent/release-notes/"}],"href":"/endpoint-devices/authentik-agent/"},{"type":"link","href":"/endpoint-devices/manage-devices","label":"Manage devices","docId":"endpoint-devices/manage-devices","unlisted":false},{"type":"category","label":"Device Compliance","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/endpoint-devices/device-compliance/configuration","label":"Configuration","docId":"endpoint-devices/device-compliance/configuration","unlisted":false},{"type":"category","label":"Connectors","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/endpoint-devices/device-compliance/connectors/authentik-agent","label":"authentik Agent connector","docId":"endpoint-devices/device-compliance/connectors/authentik-agent","unlisted":false},{"type":"link","href":"/endpoint-devices/device-compliance/connectors/fleetdm","label":"Fleet connector","docId":"endpoint-devices/device-compliance/connectors/fleetdm","unlisted":false},{"type":"link","href":"/endpoint-devices/device-compliance/connectors/google-chrome","label":"Google Chrome connector","docId":"endpoint-devices/device-compliance/connectors/google-chrome","unlisted":false}],"href":"/endpoint-devices/device-compliance/connectors/"},{"type":"link","href":"/endpoint-devices/device-compliance/device-compliance-policy","label":"Device compliance policy","docId":"endpoint-devices/device-compliance/device-compliance-policy","unlisted":false},{"type":"link","href":"/endpoint-devices/device-compliance/device-reporting","label":"Device reporting","docId":"endpoint-devices/device-compliance/device-reporting","unlisted":false},{"type":"link","href":"/endpoint-devices/device-compliance/browser-extension","label":"Browser extension","docId":"endpoint-devices/device-compliance/browser-extension","unlisted":false},{"type":"link","href":"/endpoint-devices/device-compliance/fleet-conditional-access","label":"Fleet conditional access","docId":"endpoint-devices/device-compliance/fleet-conditional-access","unlisted":false}],"href":"/endpoint-devices/device-compliance/"}],"collapsed":true,"collapsible":true,"href":"/endpoint-devices/"},{"type":"category","label":"Developer Documentation","collapsed":true,"items":[{"type":"link","href":"https://api.goauthentik.io","label":"API Overview","className":"api-overview"},{"type":"link","href":"/developer-docs/contributing","label":"Contributing","docId":"developer-docs/contributing","unlisted":false},{"type":"category","label":"Development environment","items":[{"type":"link","href":"/developer-docs/setup/debugging","label":"Debugging authentik","docId":"developer-docs/setup/debugging","unlisted":false},{"type":"link","href":"/developer-docs/setup/frontend-dev-environment","label":"Frontend development","docId":"developer-docs/setup/frontend-dev-environment","unlisted":false},{"type":"link","href":"/developer-docs/setup/full-dev-environment","label":"Full development","docId":"developer-docs/setup/full-dev-environment","unlisted":false},{"type":"link","href":"/developer-docs/setup/","label":"Development environment","docId":"developer-docs/setup/index","unlisted":false}],"collapsed":true,"collapsible":true,"href":"/developer-docs/setup/"},{"type":"category","label":"Writing documentation","items":[{"type":"link","href":"/developer-docs/docs/style-guide","label":"Style guide","docId":"developer-docs/docs/style-guide","unlisted":false},{"type":"category","label":"Templates","items":[{"type":"link","href":"/developer-docs/docs/templates/combo","label":"Combination topic (most common)","docId":"developer-docs/docs/templates/combo","unlisted":false},{"type":"link","href":"/developer-docs/docs/templates/combo.tmpl","label":"MDX template: combo","docId":"developer-docs/docs/templates/combo.tmpl","unlisted":false},{"type":"link","href":"/developer-docs/docs/templates/conceptual","label":"Conceptual topic","docId":"developer-docs/docs/templates/conceptual","unlisted":false},{"type":"link","href":"/developer-docs/docs/templates/conceptual.tmpl","label":"MDX template: conceptual","docId":"developer-docs/docs/templates/conceptual.tmpl","unlisted":false},{"type":"link","href":"/developer-docs/docs/templates/","label":"Templates","docId":"developer-docs/docs/templates/index","unlisted":false},{"type":"link","href":"/developer-docs/docs/templates/procedural","label":"Procedural topic","docId":"developer-docs/docs/templates/procedural","unlisted":false},{"type":"link","href":"/developer-docs/docs/templates/procedural.tmpl","label":"MDX template: procedural","docId":"developer-docs/docs/templates/procedural.tmpl","unlisted":false},{"type":"link","href":"/developer-docs/docs/templates/reference","label":"Reference topic","docId":"developer-docs/docs/templates/reference","unlisted":false},{"type":"link","href":"/developer-docs/docs/templates/reference.tmpl","label":"MDX template: reference","docId":"developer-docs/docs/templates/reference.tmpl","unlisted":false}],"collapsed":true,"collapsible":true,"href":"/developer-docs/docs/templates/"}],"collapsed":true,"collapsible":true,"href":"/developer-docs/docs/writing-documentation"},{"type":"link","href":"/developer-docs/translation","label":"Translations","docId":"developer-docs/translation","unlisted":false}],"collapsible":true,"href":"/developer-docs/"},{"type":"category","label":"Security","items":[{"type":"link","href":"/security/policy","label":"Security Policy","docId":"security/policy","unlisted":false},{"type":"link","href":"/security/security-hardening","label":"Hardening authentik","docId":"security/security-hardening","unlisted":false},{"type":"link","href":"/security/account-lockdown","label":"Account Lockdown","docId":"security/account-lockdown","unlisted":false},{"type":"category","label":"Audits and Certificates","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/security/audits-and-certs/2023-06-cure53","label":"2023-06 Cure53 Code audit","docId":"security/audits-and-certs/2023-06-cure53","unlisted":false},{"type":"link","href":"/security/audits-and-certs/2024-11-cobalt","label":"2024-11 Cobalt pentest","docId":"security/audits-and-certs/2024-11-cobalt","unlisted":false},{"type":"link","href":"/security/audits-and-certs/2025-09-includesec","label":"2025-09 IncludeSec pentest","docId":"security/audits-and-certs/2025-09-includesec","unlisted":false}],"href":"/security/audits-and-certs"},{"type":"category","label":"CVEs","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/security/cves/CVE-2022-23555","label":"CVE-2022-23555","docId":"security/cves/CVE-2022-23555","unlisted":false},{"type":"link","href
1":"/security/cves/CVE-2022-46145","label":"CVE-2022-46145","docId":"security/cves/CVE-2022-46145","unlisted":false},{"type":"link","href":"/security/cves/CVE-2022-46172","label":"CVE-2022-46172","docId":"security/cves/CVE-2022-46172","unlisted":false},{"type":"link","href":"/security/cves/CVE-2023-26481","label":"CVE-2023-26481","docId":"security/cves/CVE-2023-26481","unlisted":false},{"type":"link","href":"/security/cves/CVE-2023-36456","label":"CVE-2023-36456","docId":"security/cves/CVE-2023-36456","unlisted":false},{"type":"link","href":"/security/cves/CVE-2023-39522","label":"CVE-2023-39522","docId":"security/cves/CVE-2023-39522","unlisted":false},{"type":"link","href":"/security/cves/CVE-2023-46249","label":"CVE-2023-46249","docId":"security/cves/CVE-2023-46249","unlisted":false},{"type":"link","href":"/security/cves/CVE-2023-48228","label":"CVE-2023-48228","docId":"security/cves/CVE-2023-48228","unlisted":false},{"type":"link","href":"/security/cves/CVE-2024-21637","label":"CVE-2024-21637","docId":"security/cves/CVE-2024-21637","unlisted":false},{"type":"link","href":"/security/cves/CVE-2024-23647","label":"CVE-2024-23647","docId":"security/cves/CVE-2024-23647","unlisted":false},{"type":"link","href":"/security/cves/CVE-2024-37905","label":"CVE-2024-37905","docId":"security/cves/CVE-2024-37905","unlisted":false},{"type":"link","href":"/security/cves/CVE-2024-38371","label":"CVE-2024-38371","docId":"security/cves/CVE-2024-38371","unlisted":false},{"type":"link","href":"/security/cves/CVE-2024-42490","label":"CVE-2024-42490","docId":"security/cves/CVE-2024-42490","unlisted":false},{"type":"link","href":"/security/cves/CVE-2024-47070","label":"CVE-2024-47070","docId":"security/cves/CVE-2024-47070","unlisted":false},{"type":"link","href":"/security/cves/CVE-2024-47077","label":"CVE-2024-47077","docId":"security/cves/CVE-2024-47077","unlisted":false},{"type":"link","href":"/security/cves/CVE-2024-52287","label":"CVE-2024-52287","docId":"security/cves/CVE-2024-52287","unlisted":false},{"type":"link","href":"/security/cves/CVE-2024-52289","label":"CVE-2024-52289","docId":"security/cves/CVE-2024-52289","unlisted":false},{"type":"link","href":"/security/cves/CVE-2024-52307","label":"CVE-2024-52307","docId":"security/cves/CVE-2024-52307","unlisted":false},{"type":"link","href":"/security/cves/CVE-2025-29928","label":"CVE-2025-29928","docId":"security/cves/CVE-2025-29928","unlisted":false},{"type":"link","href":"/security/cves/CVE-2025-52553","label":"CVE-2025-52553","docId":"security/cves/CVE-2025-52553","unlisted":false},{"type":"link","href":"/security/cves/CVE-2025-53942","label":"CVE-2025-53942","docId":"security/cves/CVE-2025-53942","unlisted":false},{"type":"link","href":"/security/cves/CVE-2025-64521","label":"CVE-2025-64521","docId":"security/cves/CVE-2025-64521","unlisted":false},{"type":"link","href":"/security/cves/CVE-2025-64708","label":"CVE-2025-64708","docId":"security/cves/CVE-2025-64708","unlisted":false},{"type":"link","href":"/security/cves/CVE-2026-25227","label":"CVE-2026-25227","docId":"security/cves/CVE-2026-25227","unlisted":false},{"type":"link","href":"/security/cves/CVE-2026-25748","label":"CVE-2026-25748","docId":"security/cves/CVE-2026-25748","unlisted":false},{"type":"link","href":"/security/cves/CVE-2026-25922","label":"CVE-2026-25922","docId":"security/cves/CVE-2026-25922","unlisted":false},{"type":"link","href":"/security/cves/CVE-2026-40165","label":"CVE-2026-40165","docId":"security/cves/CVE-2026-40165","unlisted":false},{"type":"link","href":"/security/cves/CVE-2026-40166","label":"CVE-2026-40166","docId":"security/cves/CVE-2026-40166","unlisted":false},{"type":"link","href":"/security/cves/CVE-2026-41569","label":"CVE-2026-41569","docId":"security/cves/CVE-2026-41569","unlisted":false},{"type":"link","href":"/security/cves/CVE-2026-42849","label":"CVE-2026-42849","docId":"security/cves/CVE-2026-42849","unlisted":false},{"type":"link","href":"/security/cves/CVE-2026-47201","label":"CVE-2026-47201","docId":"security/cves/CVE-2026-47201","unlisted":false},{"type":"link","href":"/security/cves/CVE-2026-49443","label":"CVE-2026-49443","docId":"security/cves/CVE-2026-49443","unlisted":false},{"type":"link","href":"/security/cves/CVE-2026-49448","label":"CVE-2026-49443 / GHSA-5wcc-hf24-rf5h","docId":"security/cves/CVE-2026-49448","unlisted":false},{"type":"link","href":"/security/cves/CVE-2026-54730","label":"CVE-2026-54730 / GHSA-3v9h-3hrm-29cx","docId":"security/cves/CVE-2026-54730","unlisted":false},{"type":"link","href":"/security/cves/CVE-2026-55106","label":"CVE-2026-55106 / GHSA-h8ff-c3h7-2gf8","docId":"security/cves/CVE-2026-55106","unlisted":false},{"type":"link","href":"/security/cves/CVE-2026-57580","label":"CVE-2026-57580 / GHSA-35v6-hv2g-6992","docId":"security/cves/CVE-2026-57580","unlisted":false},{"type":"link","href":"/security/cves/GHSA-4r87-w2cx-fr3f","label":"GHSA-4r87-w2cx-fr3f","docId":"security/cves/GHSA-4r87-w2cx-fr3f","unlisted":false},{"type":"link","href":"/security/cves/GHSA-5wcc-hf24-rf5h","label":"GHSA-5wcc-hf24-rf5h","docId":"security/cves/GHSA-5wcc-hf24-rf5h","unlisted":false},{"type":"link","href":"/security/cves/GHSA-cqj8-fxxf-9pg7","label":"GHSA-cqj8-fxxf-9pg7","docId":"security/cves/GHSA-cqj8-fxxf-9pg7","unlisted":false},{"type":"link","href":"/security/cves/GHSA-cxwx-9x59-28qm","label":"GHSA-cxwx-9x59-28qm","docId":"security/cves/GHSA-cxwx-9x59-28qm","unlisted":false},{"type":"link","href":"/security/cves/GHSA-h6c5-mpvq-j4jc","label":"GHSA-h6c5-mpvq-j4jc","docId":"security/cves/GHSA-h6c5-mpvq-j4jc","unlisted":false},{"type":"link","href":"/security/cves/GHSA-jpx7-5hcf-w9xp","label":"GHSA-jpx7-5hcf-w9xp","docId":"security/cves/GHSA-jpx7-5hcf-w9xp","unlisted":false},{"type":"link","href":"/security/cves/GHSA-m9h4-7j9c-55x9","label":"GHSA-m9h4-7j9c-55x9","docId":"security/cves/GHSA-m9h4-7j9c-55x9","unlisted":false},{"type":"link","href":"/security/cves/GHSA-qgqp-xh8r-v73r","label":"GHSA-qgqp-xh8r-v73r","docId":"security/cves/GHSA-qgqp-xh8r-v73r","unlisted":false}]}],"collapsed":true,"collapsible":true},{"type":"category","label":"Troubleshooting","items":[{"type":"link","href":"/troubleshooting/access","label":"I can\'t access an application","docId":"troubleshooting/access","unlisted":false},{"type":"link","href":"/troubleshooting/csrf","label":"Troubleshooting CSRF Errors","docId":"troubleshooting/csrf","unlisted":false},{"type":"link","href":"/troubleshooting/emails","label":"Troubleshooting Email sending","docId":"troubleshooting/emails","unlisted":false},{"type":"link","href":"/troubleshooting/forward_auth","label":"Troubleshooting Forward auth","docId":"troubleshooting/forward_auth","unlisted":false},{"type":"link","href":"/troubleshooting/image_upload","label":"Errors when uploading icons","docId":"troubleshooting/image_upload","unlisted":false},{"type":"link","href":"/troubleshooting/ldap_source","label":"Troubleshooting LDAP Synchronization","docId":"troubleshooting/ldap_source","unlisted":false},{"type":"link","href":"/troubleshooting/login","label":"I can\'t log in to authentik","docId":"troubleshooting/login","unlisted":false},{"type":"category","label":"Logs","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/troubleshooting/logs/outpost_logs","label":"Capturing outpost logs","docId":"troubleshooting/logs/outpost_logs","unlisted":false}],"href":"/troubleshooting/logs/"},{"type":"link","href":"/troubleshooting/missing_admin_group","label":"Missing admin group","docId":"troubleshooting/missing_admin_group","unlisted":false},{"type":"link","href":"/troubleshooting/missing_permission","label":"Missing Permissions system_exception events","docId":"troubleshooting/missing_permission","unlisted":false},{"type":"category","label":"PostgreSQL","collapsible":true,"collapsed":true,"items":[{"type":"link","href":"/troubleshooting/postgres/slow-queries","label":"Troubleshoot slow PostgreSQL queries","docId":"troubleshooting/postgres/slow-queries","unlisted":false},{"type":"link","href":"/troubleshooting/postgres/upgrade_docker","label":"Upgrade PostgreSQL on Docker Compose","docId":"troubleshooting/postgres/upgrade_docker","unlisted":false},{"type":"link","href":"/troubleshooting/postgres/upgrade_kubernetes","label":"Upgrading PostgreSQL on Kubernetes","docId":"troubleshooting/postgres/upgrade_kubernetes","unlisted":false}]}],"collapsed":true,"collapsible":true},{"type":"category","label":"Release Notes","items":[{"type":"link","key":"release-2026.8","href":"/releases/2026.8","label":"2026.8","docId":"releases/2026/v2026.8","unlisted":false},{"type":"link","key":"release-2026.5","href":"/releases/2026.5","label":"2026.5","docId":"releases/2026/v2026.5","unlisted":false},{"type":"category","label":"Previous versions","items":[{"type":"link","key":"release-2026.2","href":"/releases/2026.2","label":"2026.2","docId":"releases/2026/v2026.2","unlisted":false},{"type":"link","key":"release-2025.12","href":"/releases/2025.12","label":"2025.12","docId":"releases/2025/v2025.12","unlisted":false},{"type":"link","key":"release-2025.10","href":"/releases/2025.10","label":"2025.10","docId":"releases/2025/v2025.10","unlisted":false},{"type":"link","key":"release-2025.8","href":"/releases/2025.8","label":"2025.8","docId":"releases/2025/v2025.8","unlisted":false},{"type":"link","key":"release-2025.6","href":"/releases/2025.6","label":"2025.6","docId":"releases/2025/v2025.6","unlisted":false},{"type":"link","key":"release-2025.4","href":"/releases/2025.4","label":"2025.4","docId":"releases/2025/v2025.4","unlisted":false},{"type":"link","key":"release-2025.2","href":"/releases/2025.2","label":"2025.2","docId":"releases/2025/v2025.2","unlisted":false},{"type":"link","key":"release-2024.12","href":"/releases/2024.12","label":"2024.12","docId":"releases/2024/v2024.12","unlisted":false},{"type":"link","key":"release-2024.10","href":"/releases/2024.10","label":"2024.10","docId":"releases/2024/v2024.10","unlisted":false},{"type":"link","key":"release-2024.8","href":"/releases/2024.8","label":"2024.8","docId":"releases/2024/v2024.8","unlisted":false},{"type":"link","key":"release-2024.6","href":"/releases/2024.6","label":"2024.6","docId":"releases/2024/v2024.6","unlisted":false},{"type":"link","key":"release-2024.4","href":"/releases/2024.4","label":"2024.4","docId":"releases/2024/v2024.4","unlisted":false},{"type":"link","key":"release-2024.2","href":"/releases/2024.2","label":"2024.2","docId":"releases/2024/v2024.2","unlisted":false},{"type":"link","key":"release-2023.10","href":"/releases/2023.10","label":"2023.10","docId":"releases/2023/v2023.10","unlisted":false},{"type":"link","key":"release-2023.8","href":"/releases/2023.8","label":"2023.8","docId":"releases/2023/v2023.8","unlisted":false},{"type":"link","key":"release-2023.6","href":"/releases/2023.6","label":"2023.6","docId":"releases/2023/v2023.6","unlisted":false},{"type":"link","key":"release-2023.5","href":"/releases/2023.5","label":"2023.5","docId":"releases/2023/v2023.5","unlisted":false},{"type":"link","key":"release-2023.4","href":"/releases/2023.4","label":"2023.4","docId":"releases/2023/v2023.4","unlisted":false},{"type":"link","key":"release-2023.3","href":"/releases/2023.3","label":"2023.3","docId":"releases/2023/v2023.3","unlisted":false},{"type":"link","key":"release-2023.2","href":"/releases/2023.2","label":"2023.2","docId":"releases/2023/v2023.2","unlisted":false},{"type":"link","key":"release-2023.1","href":"/releases/2023.1","label":"2023.1","docId":"releases/2023/v2023.1","unlisted":false},{"type":"link","key":"release-2022.12","href":"/releases/2022.12","label":"2022.12","docId":"releases/2022/v2022.12","unlisted":false},{"type":"link","key":"release-2022.11","href":"/releases/2022.11","label":"2022.11","docId":"releases/2022/v2022.11","unlisted":false},{"type":"link","key":"release-2022.10","href":"/releases/2022.10","label":"2022.10","docId":"releases/2022/v2022.10","unlisted":false},{"type":"link","key":"release-2022.9","href":"/releases/2022.9","label":"2022.9","docId":"releases/2022/v2022.9","unlisted":false},{"type":"link","key":"release-2022.8","href":"/releases/2022.8","label":"2022.8","docId":"releases/2022/v2022.8","unlisted":false},{"type":"link","key":"release-2022.7","href":"/releases/2022.7","label":"2022.7","docId":"releases/2022/v2022.7","unlisted":false},{"type":"link","key":"release-2022.6","href":"/releases/2022.6","label":"2022.6","docId":"releases/2022/v2022.6","unlisted":false},{"type":"link","key":"release-2022.5","href":"/releases/2022.5","label":"2022.5","docId":"releases/2022/v2022.5","unlisted":false},{"type":"link","key":"release-2022.4","href":"/releases/2022.4","label":"2022.4","docId":"releases/2022/v2022.4","unlisted":false},{"type":"link","key":"release-2022.3","href":"/releases/2022.3","label":"2022.3","docId":"releases/2022/v2022.3","unlisted":false},{"type":"link","key":"release-2022.2","href":"/releases/2022.2","label":"2022.2","docId":"releases/2022/v2022.2","unlisted":false},{"type":"link","key":"release-2022.1","href":"/releases/2022.1","label":"2022.1","docId":"releases/2022/v2022.1","unlisted":false},{"type":"link","key":"release-2021.12","href":"/releases/2021.12","label":"2021.12","docId":"releases/2021/v2021.12","unlisted":false},{"type":"link","key":"release-2021.10","href":"/releases/2021.10","label":"2021.10","docId":"releases/2021/v2021.10","unlisted":false},{"type":"link","key":"release-2021.9","href":"/releases/2021.9","label":"2021.9","docId":"releases/2021/v2021.9","unlisted":false},{"type":"link","key":"release-2021.8","href":"/releases/2021.8","label":"2021.8","docId":"releases/2021/v2021.8","unlisted":false},{"type":"link","key":"release-2021.7","href":"/releases/2021.7","label":"2021.7","docId":"releases/2021/v2021.7","unlisted":false},{"type":"link","key":"release-2021.6","href":"/releases/2021.6","label":"2021.6","docId":"releases/2021/v2021.6","unlisted":false},{"type":"link","key":"release-2021.5","href":"/releases/2021.5","label":"2021.5","docId":"releases/2021/v2021.5","unlisted":false},{"type":"link","key":"release-2021.4","href":"/releases/2021.4","label":"2021.4","docId":"releases/2021/v2021.4","unlisted":false},{"type":"link","key":"release-2021.3","href":"/releases/2021.3","label":"2021.3","docId":"releases/2021/v2021.3","unlisted":false},{"type":"link","key":"release-2021.2","href":"/releases/2021.2","label":"2021.2","docId":"releases/2021/v2021.2","unlisted":false},{"type":"link","key":"release-2021.1","href":"/releases/2021.1","label":"2021.1","docId":"releases/2021/v2021.1","unlisted":false},{"type":"link","key":"release-0.14","href":"/releases/0.14","label":"0.14","docId":"releases/old/v0.14","unlisted":false},{"type":"link","key":"release-0.13","href":"/releases/0.13","label":"0.13","docId":"releases/old/v0.13","unlisted":false},{"type":"link","key":"release-0.12","href":"/releases/0.12","label":"0.12","docId":"releases/old/v0.12","unlisted":false},{"type":"link","key":"release-0.11","href":"/releases/0.11","label":"0.11","docId":"releases/old/v0.11","unlisted":false},{"type":"link","key":"release-0.10","href":"/releases/0.10","label":"0.10","docId":"releases/old/v0.10","unlisted":false},{"type":"link","key":"release-0.9","href":"/releases/0.9","label":"0.9","docId":"releases/old/v0.9","unlisted":false}],"collapsed":true,"collapsible":true}],"collapsed":true,"collapsible":true,"href":"/releases"}]},"docs":{"add-secure-apps/access-requests/index":{"id":"add-secure-apps/access-requests/index","title":"Access requests","description":"Let users request time-bound access to applications and entitlements, with request rules, expiry, and a full audit trail","sidebar":"docs"},"add-secure-apps/applications/index":{"id":"add-secure-apps/applications/index","title":"Applications","description":"Applications, as defined in authentik, are used to configure and separate the authorization/access control and the appearance of a specific software application in the Application Dashboard page.","sidebar":"docs"},"add-secure-apps/applications/manage_apps":{"id":"add-secure-apps/applications/manage_apps","title":"Manage applications","description":"Managing the applications that your team uses involves several tasks, from initially adding the application and provider, to controlling access and visibility of the application, to providing access URLs.","sidebar":"docs"},"add-secure-apps/
1bindings-overview/index":{"id":"add-secure-apps/bindings-overview/index","title":"Bindings in authentik","description":"A binding connects one authentik object to another object that uses it. Bindings let authentik answer two common questions:","sidebar":"docs"},"add-secure-apps/bindings-overview/work-with-bindings":{"id":"add-secure-apps/bindings-overview/work-with-bindings","title":"Work with bindings","description":"Bindings are configured from the object that uses them. The exact page depends on what you want the binding to control.","sidebar":"docs"},"add-secure-apps/flows-stages/flow/collect-user-attributes":{"id":"add-secure-apps/flows-stages/flow/collect-user-attributes","title":"Collect custom user attributes during enrollment","description":"Collect user data with an enrollment flow and store it as custom user attributes.","sidebar":"docs"},"add-secure-apps/flows-stages/flow/context/index":{"id":"add-secure-apps/flows-stages/flow/context/index","title":"Flow Context","description":"An overview of the data stored in a flow context and how authentik uses it.","sidebar":"docs"},"add-secure-apps/flows-stages/flow/default-flows":{"id":"add-secure-apps/flows-stages/flow/default-flows","title":"Default flows","description":"How authentik selects and uses default flows for providers and brands.","sidebar":"docs"},"add-secure-apps/flows-stages/flow/executors/headless":{"id":"add-secure-apps/flows-stages/flow/executors/headless","title":"Headless","description":"Run authentication flows for clients that do not have a web interface.","sidebar":"docs"},"add-secure-apps/flows-stages/flow/executors/if-flow":{"id":"add-secure-apps/flows-stages/flow/executors/if-flow","title":"Default","description":"An overview of the default web interface for running flows.","sidebar":"docs"},"add-secure-apps/flows-stages/flow/executors/sfe":{"id":"add-secure-apps/flows-stages/flow/executors/sfe","title":"Simplified flow executor","description":"How the simplified flow executor supports older browsers.","sidebar":"docs"},"add-secure-apps/flows-stages/flow/executors/user-settings":{"id":"add-secure-apps/flows-stages/flow/executors/user-settings","title":"User settings","description":"Use the user settings flow to let users update their profiles.","sidebar":"docs"},"add-secure-apps/flows-stages/flow/flows":{"id":"add-secure-apps/flows-stages/flow/flows","title":"Example flows","description":"Import example flow blueprints for enrollment, MFA login, magic links, and other workflows.","sidebar":"docs"},"add-secure-apps/flows-stages/flow/index":{"id":"add-secure-apps/flows-stages/flow/index","title":"Flows","description":"Create, configure, import, and manage flows for authentication, enrollment, and other processes.","sidebar":"docs"},"add-secure-apps/flows-stages/flow/inspector":{"id":"add-secure-apps/flows-stages/flow/inspector","title":"Flow Inspector","description":"Inspect running flows and troubleshoot their stages, history, and context.","sidebar":"docs"},"add-secure-apps/flows-stages/flow/planner":{"id":"add-secure-apps/flows-stages/flow/planner","title":"Flow Planner","description":"How authentik determines which stages run and the order in which they run.","sidebar":"docs"},"add-secure-apps/flows-stages/flow/snippets":{"id":"add-secure-apps/flows-stages/flow/snippets","title":"Example policy snippets","description":"Example policies for use with flows.","sidebar":"docs"},"add-secure-apps/flows-stages/stages/account_lockdown/index":{"id":"add-secure-apps/flows-stages/stages/account_lockdown/index","title":"Account Lockdown stage","description":"Secure user accounts and revoke access with the Account Lockdown stage.","sidebar":"docs"},"add-secure-apps/flows-stages/stages/authenticator_duo/index":{"id":"add-secure-apps/flows-stages/stages/authenticator_duo/index","title":"Duo authenticator setup stage","description":"Enroll Duo authenticators for users as part of an authentication flow.","sidebar":"docs"},"add-secure-apps/flows-stages/stages/authenticator_email/index":{"id":"add-secure-apps/flows-stages/stages/authenticator_email/index","title":"Email authenticator setup stage","description":"Set up email-based authenticators and one-time codes for users.","sidebar":"docs"},"add-secure-apps/flows-stages/stages/authenticator_endpoint_gdtc/index":{"id":"add-secure-apps/flows-stages/stages/authenticator_endpoint_gdtc/index","title":"Google Chrome Device Trust authenticator stage","description":"An overview of the deprecated Google Chrome Device Trust stage.","sidebar":"docs"},"add-secure-apps/flows-stages/stages/authenticator_sms/index":{"id":"add-secure-apps/flows-stages/stages/authenticator_sms/index","title":"SMS authenticator setup stage","description":"Set up SMS-based authenticators and one-time codes for users.","sidebar":"docs"},"add-secure-apps/flows-stages/stages/authenticator_static/index":{"id":"add-secure-apps/flows-stages/stages/authenticator_static/index","title":"Static authenticator setup stage","description":"Generate single-use backup codes for users when other authenticators are unavailable.","sidebar":"docs"},"add-secure-apps/flows-stages/stages/authenticator_totp/index":{"id":"add-secure-apps/flows-stages/stages/authenticator_totp/index","title":"TOTP authenticator setup stage","description":"Set up time-based one-time password authenticators for users.","sidebar":"docs"}
1,"add-secure-apps/flows-stages/stages/authenticator_validate/index":{"id":"add-secure-apps/flows-stages/stages/authenticator_validate/index","title":"Authenticator validation stage","description":"Validate the authentication methods that a user has already enrolled.","sidebar":"docs"},"add-secure-apps/flows-stages/stages/authenticator_webauthn/index":{"id":"add-secure-apps/flows-stages/stages/authenticator_webauthn/index","title":"WebAuthn / FIDO2 / Passkeys authenticator setup stage","description":"Enroll WebAuthn authenticators, security keys, and passkeys for users.","sidebar":"docs"},"add-secure-apps/flows-stages/stages/captcha/index":{"id":"add-secure-apps/flows-stages/stages/captcha/index","title":"Captcha stage","description":"Add CAPTCHA checks to flows to verify that an interaction is human.","sidebar":"docs"},"add-secure-apps/flows-stages/stages/consent/index":{"id":"add-secure-apps/flows-stages/stages/consent/index","title":"Consent stage","description":"Ask users to approve sharing their data with applications.","sidebar":"docs"},"add-secure-apps/flows-stages/stages/deny/index":{"id":"add-secure-apps/flows-stages/stages/deny/index","title":"Deny stage","description":"Stop a flow immediately and deny access to the user.","sidebar":"docs"},"add-secure-apps/flows-stages/stages/email/index":{"id":"add-secure-apps/flows-stages/stages/email/index","title":"Email stage","description":"Send verification, recovery, invitation, and other action emails from flows.","sidebar":"docs"},"add-secure-apps/flows-stages/stages/endpoint/index":{"id":"add-secure-apps/flows-stages/stages/endpoint/index","title":"Endpoint stage","description":"Check devices and make their information available to flows and policies.","sidebar":"docs"},"add-secure-apps/flows-stages/stages/identification/index":{"id":"add-secure-apps/flows-stages/stages/identification/index","title":"Identification stage","description":"Identify users by username, email address, or an external login source.","sidebar":"docs"},"add-secure-apps/flows-stages/stages/index":{"id":"add-secure-apps/flows-stages/stages/index","title":"Stages","description":"An introduction to creating stages and adding them to flows.","sidebar":"docs"},"add-secure-apps/flows-stages/stages/invitation/index":{"id":"add-secure-apps/flows-stages/stages/invitation/index","title":"Invitation stage","description":"Require an invitation before a user can continue through enrollment.","sidebar":"docs"},"add-secure-apps/flows-stages/stages/mtls/index":{"id":"add-secure-apps/flows-stages/stages/mtls/index","title":"Mutual TLS stage","description":"Authenticate or enroll users by validating their client certificates.","sidebar":"docs"},"add-secure-apps/flows-stages/stages/password/index":{"id":"add-secure-apps/flows-stages/stages/password/index","title":"Password stage","description":"Prompt users for a password and check it against configured sources.","sidebar":"docs"},"add-secure-apps/flows-stages/stages/prompt/index":{"id":"add-secure-apps/flows-stages/stages/prompt/index","title":"Prompt stage","description":"Collect user input and store the submitted values in the flow context.","sidebar":"docs"},"add-secure-apps/flows-stages/stages/redirect/index":{"id":"add-secure-apps/flows-stages/stages/redirect/index","title":"Redirect stage","description":"Redirect users to another flow or to a specified URL.","sidebar":"docs"},"add-secure-apps/flows-stages/stages/source/index":{"id":"add-secure-apps/flows-stages/stages/source/index","title":"Source stage","description":"Include authentication from an external login source within a flow.","sidebar":"docs"},"add-secure-apps/flows-stages/stages/user_delete/index":{"id":"add-secure-apps/flows-stages/stages/user_delete/index","title":"User delete stage","description":"Delete the current user\'s account during an unenrollment flow.","sidebar":"docs"},"add-secure-apps/flows-stages/stages/user_login/index":{"id":"add-secure-apps/flows-stages/stages/user_login/index","title":"User login stage","description":"Create a user session and configure how long it remains active.","sidebar":"docs"},"add-secure-apps/flows-stages/stages/user_logout/index":{"id":"add-secure-apps/flows-stages/stages/user_logout/index","title":"User logout stage","description":"End a user\'s session and optionally start Single Logout.","sidebar":"docs"},"add-secure-apps/flows-stages/stages/user_write/index":{"id":"add-secure-apps/flows-stages/stages/user_write/index","title":"User write stage","description":"Create or update users with information collected during a flow.","sidebar":"docs"},"add-secure-apps/outposts/embedded/embedded":{"id":"add-secure-apps/outposts/embedded/embedded","title":"Embedded Outpost","description":"authentik includes an embedded outpost to simplify deployments that use the Proxy provider.","sidebar":"docs"},"add-secure-apps/outposts/index":{"id":"add-secure-apps/outposts/index","title":"Outposts","de
1scription":"An outpost is a single deployment of an authentik component, essentially a service, that can be deployed anywhere that allows for a connection to the authentik API.","sidebar":"docs"},"add-secure-apps/outposts/integrations/docker":{"id":"add-secure-apps/outposts/integrations/docker","title":"Docker","description":"The Docker integration automatically deploys and manages outpost containers using the Docker HTTP API.","sidebar":"docs"},"add-secure-apps/outposts/integrations/kubernetes":{"id":"add-secure-apps/outposts/integrations/kubernetes","title":"Kubernetes","description":"The Kubernetes integration automatically deploys and manages outposts in a Kubernetes cluster.","sidebar":"docs"},"add-secure-apps/outposts/manual-deploy-docker-compose":{"id":"add-secure-apps/outposts/manual-deploy-docker-compose","title":"Manual Outpost deployment in Docker Compose","description":"To deploy an outpost with Docker Compose, use the appropriate snippet from the options below and add it to your Compose file.","sidebar":"docs"},"add-secure-apps/outposts/manual-deploy-kubernetes":{"id":"add-secure-apps/outposts/manual-deploy-kubernetes","title":"Manual Outpost deployment on Kubernetes","description":"Use the following manifest, replacing all values surrounded with ``.","sidebar":"docs"},"add-secure-apps/outposts/upgrading":{"id":"add-secure-apps/outposts/upgrading","title":"Upgrading an Outpost","description":"Outposts deployed using the Docker or Kubernetes integrations are managed by authentik and are upgraded automatically. Outposts deployed manually via Docker or Kubernetes must be upgraded by updating the outpost\'s image tag to the new version.","sidebar":"docs"},"add-secure-apps/providers/entra/configure-entra":{"id":"add-secure-apps/providers/entra/configure-entra","title":"Configure Entra ID","description":"For more information about using an Entra ID provider, see the Entra ID Overview documentation.","sidebar":"docs"},"add-secure-apps/providers/entra/create-entra-provider":{"id":"add-secure-apps/providers/entra/create-entra-provider","title":"Create an Entra ID provider","description":"For more information about using an Entra ID provider, see the Overview documentation.","sidebar":"docs"},"add-secure-apps/providers/entra/index":{"id":"add-secure-apps/providers/entra/index","title":"Microsoft Entra ID provider","description":"The Entra ID provider allows you to integrate with your Entra ID tenant. It supports syncing users and groups from authentik to Entra ID, allowing authentik to act as a source of truth for all users and groups.","sidebar":"docs"},"add-secure-apps/providers/gws/configure-gws":{"id":"add-secure-apps/providers/gws/configure-gws","title":"Configure Google Workspace","description":"For more information about using a Google Workspace provider, see the Overview documentation.","sidebar":"docs"},"add-secure-apps/providers/gws/create-gws-provider":{"id":"add-secure-apps/providers/gws/create-gws-provider","title":"Create a Google Workspace provider","description":"For more information about using a Google Workspace provider, see the Overview documentation.","sidebar":"docs"},"add-secure-apps/providers/gws/index":{"id":"add-secure-apps/providers/gws/index","title":"Google Workspace provider","description":"The Google Workspace provider allows you to integrate with your Google Workspace organization. It supports syncing users and groups from authentik to Google Workspace, allowing authentik to act as a source of truth for all users and groups.","sidebar":"docs"},"add-secure-apps/providers/index":{"id":"add-secure-apps/providers/index","title":"Providers","description":"A provider is an authentication method, a service that is used by authentik to authenticate the user for the associated application. Common providers are OpenID Connect (OIDC)/OAuth2, LDAP, SAML, a generic proxy provider, and others.","sidebar":"docs"},"add-secure-apps/providers/ldap/create-ldap-provider":{"id":"add-secure-apps/providers/ldap/create-ldap-provider","title":"Create an LDAP provider","description":"Creating an authentik LDAP provider requires the following steps:","sidebar":"docs"},"add-secure-apps/providers/ldap/index":{"id":"add-secure-apps/providers/ldap/index","title":"LDAP Provider","description":"The LDAP provider allows you to integrate with Service Providers using LDAP. It supports secure connections via LDAPS, code-based MFA authentication, basic LDAP schema compatibility, and can also be integrated
1with SSSD for authentication on Linux-based systems.","sidebar":"docs"},"add-secure-apps/providers/oauth2/create-oauth2-provider":{"id":"add-secure-apps/providers/oauth2/create-oauth2-provider","title":"Create an OAuth2 provider","description":"To create a provider along with the corresponding application that uses it for authentication, navigate to Applications > Applications and click New Application. We recommend this combined approach for most common use cases. (Alternatively, you can first create only the provider and then later pair it with an application, by navigating to Applications > Providers and clicking New Provider.)","sidebar":"docs"},"add-secure-apps/providers/oauth2/device_code":{"id":"add-secure-apps/providers/oauth2/device_code","title":"Device code flow","description":"The device code flow is also known as device flow or device authorization grant flow. This type of authentication flow is useful for devices with limited input capabilities and/or devices without browsers. The Request for Comments (RFC) 8628) abstract for this flow states:","sidebar":"docs"},"add-secure-apps/providers/oauth2/dynamic-client-registration":{"id":"add-secure-apps/providers/oauth2/dynamic-client-registration","title":"Dynamic Client Registration (DCR)","description":"Allow authorized clients to dynamically register OAuth2/OIDC applications in authentik","sidebar":"docs"},"add-secure-apps/providers/oauth2/frontchannel_and_backchannel_logout":{"id":"add-secure-apps/providers/oauth2/frontchannel_and_backchannel_logout","title":"Front-channel and back-channel logout","description":"Configure front-channel and back-channel logout for OAuth2/OpenID Connect providers","sidebar":"docs"},"add-secure-apps/providers/oauth2/github-compatibility":{"id":"add-secure-apps/providers/oauth2/github-compatibility","title":"GitHub compatibility","description":"The OAuth2 provider also exposes a GitHub-compatible endpoint. This endpoint can be used by applications, which support authenticating against GitHub Enterprise, but not generic OpenID Connect.","sidebar":"docs"},"add-secure-apps/providers/oauth2/index":{"id":"add-secure-apps/providers/oauth2/index","title":"OAuth 2.0 provider","description":"In authentik, you can create an OAuth 2.0 provider to authenticate users to an associated application. The provider supports both OAuth 2.0 and OpenID Connect (OIDC).","sidebar":"docs"},"add-secure-apps/providers/oauth2/key-binding":{"id":"add-secure-apps/providers/oauth2/key-binding","title":"OpenID Connect key binding","description":"Request key-bound ID tokens with DPoP, exchange authorization and device codes, and refresh with the same client key.","sidebar":"docs"},"add-secure-apps/providers/oauth2/machine_to_machine":{"id":"add-secure-apps/providers/oauth2/machine_to_machine","title":"Machine-to-Machine (M2M) authentication","description":"The OAuth 2.0 specification includes the client credentials grant, which allows machine-to-machine (M2M) authentication without user involvement. In authentik, machine clients do not authenticate using the typical clientid + clientsecret combination. This is because OAuth providers can only have a single secret at any given time.","sidebar":"docs"},"add-secure-apps/providers/oauth2/token_exchange":{"id":"add-secure-apps/providers/oauth2/token_exchange","title":"Token exchange","description":"Token exchange allows a client to exchange a token it already holds for a new token issued by an authentik provider. Token exchange is defined by RFC 8693, whose abstract states:","sidebar":"docs"},"add-secure-apps/providers/oauth2/webfinger_support":{"id":"add-secure-apps/providers/oauth2/webfinger_support","title":"WebFinger support","description":"About WebFinger","sidebar":"docs"},"add-secure-apps/providers/property-mappings/expression":{"id":"add-secure-apps/providers/property-mappings/expression","title":"Property mapping expressions","description":"Write Python expressions for provider property mappings.","sidebar":"docs"},"add-secure-apps/providers/property-mappings/index":{"id":"add-secure-apps/providers/property-mappings/index","title":"Provider property mappings","de
1scription":"Configure how authentik sends user, group, and other data to integrated applications.","sidebar":"docs"},"add-secure-apps/providers/proxy/create-proxy-provider":{"id":"add-secure-apps/providers/proxy/create-proxy-provider","title":"Create a proxy provider","description":"For an overview of how proxy providers work, see the proxy provider documentation.","sidebar":"docs"},"add-secure-apps/providers/proxy/custom_headers":{"id":"add-secure-apps/providers/proxy/custom_headers","title":"Custom headers","description":"The proxy can send custom headers to your upstream application. Configure these headers in one of two ways:","sidebar":"docs"},"add-secure-apps/providers/proxy/forward_auth":{"id":"add-secure-apps/providers/proxy/forward_auth","title":"Forward auth","description":"Forward auth uses your existing reverse proxy for application traffic and relies on the authentik outpost only to check authentication and authorization.","sidebar":"docs"},"add-secure-apps/providers/proxy/header_authentication":{"id":"add-secure-apps/providers/proxy/header_authentication","title":"Header authentication","description":"Sending authentication","sidebar":"docs"},"add-secure-apps/providers/proxy/index":{"id":"add-secure-apps/providers/proxy/index","title":"Proxy provider","description":"The proxy provider protects applications that do not support native authentication protocols such as OIDC, SAML, or LDAP.","sidebar":"docs"},"add-secure-apps/providers/proxy/server_caddy":{"id":"add-secure-apps/providers/proxy/server_caddy","title":"Caddy","description":"The configuration template shown below applies to both single-application and domain-level forward auth.","sidebar":"docs"},"add-secure-apps/providers/proxy/server_envoy":{"id":"add-secure-apps/providers/proxy/server_envoy","title":"Envoy","description":"The configuration template shown below applies to both single-application and domain-level forward auth.","sidebar":"docs"},"add-secure-apps/providers/proxy/server_haproxy":{"id":"add-secure-apps/providers/proxy/server_haproxy","title":"HAProxy","description":"Use this configuration to protect one HTTPS application with standalone HAProxy and authentik\'s Forward auth (single application) mode. HAProxy checks application requests with the outpost\'s nginx-compatible forward-auth endpoint and redirects unauthenticated users to sign in.","sidebar":"docs"},"add-secure-apps/providers/proxy/server_nginx":{"id":"add-secure-apps/providers/proxy/server_nginx","title":"nginx","description":"The configuration templates shown below apply to both single-application and domain-level forward auth.","sidebar":"docs"},"add-secure-apps/providers/proxy/server_traefik":{"id":"add-secure-apps/providers/proxy/server_traefik","title":"Traefik","description":"The configuration templates shown below apply to both single-application and domain-level forward auth.","sidebar":"docs"},"add-secure-apps/providers/rac/create-rac-provider":{"id":"add-secure-apps/providers/rac/create-rac-provider","title":"Create a Remote Access Control (RAC) provider","description":"For an overview of Remote Access Control (RAC), see the RAC provider documentation.","sidebar":"docs"},"add-secure-apps/providers/rac/index":{"id":"add-secure-apps/providers/rac/index","title":"Remote Access Control (RAC) Provider","description":"The RAC provider allows users to access remote Windows, macOS, and Linux machines via RDP/SSH/VNC. Just like other providers in authentik, the RAC provider is associated with an application that appears on a user\'s Application Dashboard page.","sidebar":"docs"},"add-secure-apps/providers/rac/rac_credentials_prompt":{"id":"add-secure-apps/providers/rac/rac_credentials_prompt","title":"RAC Credentials Prompt","description":"About the RAC credentials prompt","sidebar":"docs"},"add-secure-apps/providers/rac/rac-public-key":{"id":"add-secure-apps/providers/rac/rac-public-key","title":"RAC SSH Public Key Authentication","description":"About RAC SSH public key authentication","sidebar":"docs"},"add-secure-apps/providers/radius/index":{"id":"add-secure-apps/providers/radius/index","title":"RADIUS Provider","description":"You can configure a Radius provider for applications that don\'t support any other protocols or that require Radius.","sidebar":"docs"},"add-secure-apps/providers/saml/create-saml-provider":{"id":"add-secure-apps/providers/saml/create-saml-provider","title":"Create a SAML provider","description":"authentik SAML providers can be created either from scratch or by using SAML metadata exported from the Service Provider (SP). Optionally, the metadata of an authentik SAML provider can be exported back to the SP. Note, however, that many SPs do not support exporting their metadata or importing Identity Provider (IdP) metadata.","sidebar":"docs"},"add-secure-apps/providers/saml/index":{"id":"add-secure-apps/providers/saml/index","title":"SAML Provider","description":"The SAML provider allows you to integrate with Service Providers using the SAML2 protocol. It supports importing and exporting SAML metadata, signed requests and uses property mappings to align, or \\"map\\", Service Provider and authentik attributes.","sidebar":"docs"},"add-secure-apps/providers/saml/saml_single_logout":{"id":"add-secure-apps/providers/saml/saml_single_logout","title":"SAML Single Logout","description":"Single Logout (SLO) allows authentik to log out users from all configured providers simultaneously when they sign out of authentik. For SAML providers, this requires your service provider to supp
1ort Single Logout via a Single Logout Service URL. Check your provider\'s documentation to confirm Single Logout support.","sidebar":"docs"},"add-secure-apps/providers/scim/create-scim-provider":{"id":"add-secure-apps/providers/scim/create-scim-provider","title":"Create a SCIM provider","description":"Create a SCIM provider with token authentication","sidebar":"docs"},"add-secure-apps/providers/scim/index":{"id":"add-secure-apps/providers/scim/index","title":"SCIM Provider","description":"SCIM (System for Cross-domain Identity Management) is a set of APIs to provision users and groups. The SCIM provider in authentik supports SCIM 2.0 and can be used to provision and sync users from authentik into other applications.","sidebar":"docs"},"add-secure-apps/providers/single-logout/index":{"id":"add-secure-apps/providers/single-logout/index","title":"Single Logout (SLO)","description":"Single Logout (SLO) is a security feature that logs users out of all active applications when they log out of authentik. It uses the OAuth2/OpenID Connect front-channel and back-channel logout specifications in combination with SAML\'s Single Logout specification.","sidebar":"docs"},"add-secure-apps/providers/ssf/create-ssf-provider":{"id":"add-secure-apps/providers/ssf/create-ssf-provider","title":"Configure an SSF provider","description":"How to create and configure an SSF provider in authentik","sidebar":"docs"},"add-secure-apps/providers/ssf/index":{"id":"add-secure-apps/providers/ssf/index","title":"Shared Signals Framework (SSF) Provider","description":"Overview of SSF and the authentik SSF provider","sidebar":"docs"},"add-secure-apps/providers/wsfed/create-wsfed-provider":{"id":"add-secure-apps/providers/wsfed/create-wsfed-provider","title":"Create a WS-Federation provider","description":"An authentik WS-Federation provider is typically created as part of an application/provider pair, using the steps below. You can also create a standalone provider, and then later assign an application to use it.","sidebar":"docs"},"add-secure-apps/providers/wsfed/index":{"id":"add-secure-apps/providers/wsfed/index","title":"WS-Federation Provider","description":"The WS-Federation provider is used to integrate with applications and service providers that use WS-Federation protocol. WS-Federation is an XML-based identity federation protocol that uses token exchange for federated Single Sign-On (SSO) and IdP authentication, specifically for Windows applications such as SharePoint.","sidebar":"docs"},"core/architecture":{"id":"core/architecture","title":"Architecture","description":"authentik consists of a handful of components, most of which are required for a functioning setup.","sidebar":"docs"},"core/glossary/index":{"id":"core/glossary/index","title":"Glossary","description":"This glossary provides definitions for common terms used throughout the authentik documentation.","sidebar":"docs"},"core/glossary/terms/access-token":{"id":"core/glossary/terms/access-token","title":"Access Token","description":"","sidebar":"docs"},"core/glossary/terms/acs":{"id":"core/glossary/terms/acs","title":"Assertion Consumer Service (ACS)","description":"","sidebar":"docs"},"core/glossary/terms/application":{"id":"core/glossary/terms/application","title":"Application","description":"","sidebar":"docs"},"core/glossary/terms/audience":{"id":"core/glossary/terms/audience","title":"Audience (aud)","description":"","sidebar":"docs"},"core/glossary/terms/authorization-code":{"id":"core/glossary/terms/authorization-code","title":"Authorization code","description":"","sidebar":"docs"},"core/glossary/terms/authorization-endpoint":{"id":"core/glossary/terms/authorization-endpoint","title":"Authorization endpoint","description":"","sidebar":"docs"},"core/glossary/terms/authorization-server":{"id":"core/glossary/terms/authorization-server","title":"Authorization Server (AS)","description":"","sidebar":"docs"},"core/glossary/terms/back-channel":{"id":"core/glossary/terms/back-channel","title":"Back-channel","description":"","sidebar":"docs"},"core/glossary/terms/back-channel-logout":{"id":"core/glossary/terms/back-channel-logout","title":"Back-channel logout","description":"","sidebar":"docs"},"core/glossary/terms/blueprints":{"id":"core/glossary/terms/blueprints","title":"Blueprints","de
1scription":"","sidebar":"docs"},"core/glossary/terms/brand":{"id":"core/glossary/terms/brand","title":"Brand","description":"","sidebar":"docs"},"core/glossary/terms/claim":{"id":"core/glossary/terms/claim","title":"Claim","description":"","sidebar":"docs"},"core/glossary/terms/dynamic-in-memory-stage":{"id":"core/glossary/terms/dynamic-in-memory-stage","title":"Dynamic in-memory stage","description":"","sidebar":"docs"},"core/glossary/terms/entity-id":{"id":"core/glossary/terms/entity-id","title":"Entity ID","description":"","sidebar":"docs"},"core/glossary/terms/flow":{"id":"core/glossary/terms/flow","title":"Flow","description":"","sidebar":"docs"},"core/glossary/terms/front-channel":{"id":"core/glossary/terms/front-channel","title":"Front-channel","description":"","sidebar":"docs"},"core/glossary/terms/front-channel-logout":{"id":"core/glossary/terms/front-channel-logout","title":"Front-channel logout","description":"","sidebar":"docs"},"core/glossary/terms/grant-type":{"id":"core/glossary/terms/grant-type","title":"Grant type","description":"","sidebar":"docs"},"core/glossary/terms/id-token":{"id":"core/glossary/terms/id-token","title":"ID token","description":"","sidebar":"docs"},"core/glossary/terms/identity-provider":{"id":"core/glossary/terms/identity-provider","title":"Identity Provider (IdP)","description":"","sidebar":"docs"},"core/glossary/terms/idp-initiated-sso":{"id":"core/glossary/terms/idp-initiated-sso","title":"IdP-initiated SSO","description":"","sidebar":"docs"},"core/glossary/terms/introspection-endpoint":{"id":"core/glossary/terms/introspection-endpoint","title":"Introspection endpoint","description":"","sidebar":"docs"},"core/glossary/terms/issuer":{"id":"core/glossary/terms/issuer","title":"Issuer (iss)","description":"","sidebar":"docs"},"core/glossary/terms/jwk":{"id":"core/glossary/terms/jwk","title":"JWK","description":"","sidebar":"docs"},"core/glossary/terms/jwks":{"id":"core/glossary/terms/jwks","title":"JWKS","description":"","sidebar":"docs"},"core/glossary/terms/jwt":{"id":"core/glossary/terms/jwt","title":"JWT","description":"","sidebar":"docs"},"core/glossary/terms/ldap":{"id":"core/glossary/terms/ldap","title":"LDAP","description":"","sidebar":"docs"},"core/glossary/terms/ldap-base-dn":{"id":"core/glossary/terms/ldap-base-dn","title":"Base DN","description":"","sidebar":"docs"},"core/glossary/terms/ldap-bind-dn":{"id":"core/glossary/terms/ldap-bind-dn","title":"Bind DN","description":"","sidebar":"docs"},"core/glossary/terms/ldap-dn":{"id":"core/glossary/terms/ldap-dn","title":"Distinguished Name (DN)","description":"","sidebar":"docs"},"core/glossary/terms/ldap-filter":{"id":"core/glossary/terms/ldap-filter","title":"LDAP search f
1ilter","description":"","sidebar":"docs"},"core/glossary/terms/ldap-objectclass":{"id":"core/glossary/terms/ldap-objectclass","title":"ObjectClass","description":"","sidebar":"docs"},"core/glossary/terms/nameid":{"id":"core/glossary/terms/nameid","title":"NameID","description":"","sidebar":"docs"},"core/glossary/terms/notification-rule":{"id":"core/glossary/terms/notification-rule","title":"Notification rule","description":"","sidebar":"docs"},"core/glossary/terms/oidc-discovery":{"id":"core/glossary/terms/oidc-discovery","title":"OIDC discovery document","description":"","sidebar":"docs"},"core/glossary/terms/openid-provider":{"id":"core/glossary/terms/openid-provider","title":"OpenID Provider (OP)","description":"","sidebar":"docs"},"core/glossary/terms/outpost":{"id":"core/glossary/terms/outpost","title":"Outpost","description":"","sidebar":"docs"},"core/glossary/terms/passkey":{"id":"core/glossary/terms/passkey","title":"Passkey","description":"","sidebar":"docs"},"core/glossary/terms/pkce":{"id":"core/glossary/terms/pkce","title":"PKCE","description":"","sidebar":"docs"},"core/glossary/terms/policy":{"id":"core/glossary/terms/policy","title":"Policy","description":"","sidebar":"docs"},"core/glossary/terms/property-mappings":{"id":"core/glossary/terms/property-mappings","title":"Property mappings","de
1scription":"","sidebar":"docs"},"core/glossary/terms/provider":{"id":"core/glossary/terms/provider","title":"Provider","description":"","sidebar":"docs"},"core/glossary/terms/radius":{"id":"core/glossary/terms/radius","title":"RADIUS","description":"","sidebar":"docs"},"core/glossary/terms/radius-auth-methods":{"id":"core/glossary/terms/radius-auth-methods","title":"RADIUS auth methods","description":"","sidebar":"docs"},"core/glossary/terms/radius-messages":{"id":"core/glossary/terms/radius-messages","title":"RADIUS messages","description":"","sidebar":"docs"},"core/glossary/terms/radius-nas":{"id":"core/glossary/terms/radius-nas","title":"Network Access Server (NAS)","description":"","sidebar":"docs"},"core/glossary/terms/radius-shared-secret":{"id":"core/glossary/terms/radius-shared-secret","title":"RADIUS shared secret","description":"","sidebar":"docs"},"core/glossary/terms/radius-vsa":{"id":"core/glossary/terms/radius-vsa","title":"Vendor\u2011Specific Attribute (VSA)","description":"","sidebar":"docs"},"core/glossary/terms/redirect-uri":{"id":"core/glossary/terms/redirect-uri","title":"Redirect URI","description":"","sidebar":"docs"},"core/glossary/terms/refresh-token":{"id":"core/glossary/terms/refresh-token","title":"Refresh token","description":"","sidebar":"docs"},"core/glossary/terms/relying-party":{"id":"core/glossary/terms/relying-party","title":"Relying Party (RP)","description":"","sidebar":"docs"},"core/glossary/terms/response-type":{"id":"core/glossary/terms/response-type","title":"Response type","description":"","sidebar":"docs"},"core/glossary/terms/revocation-endpoint":{"id":"core/glossary/terms/revocation-endpoint","title":"Revocation endpoint","description":"","sidebar":"docs"},"core/glossary/terms/saml-assertion":{"id":"core/glossary/terms/saml-assertion","title":"SAML assertion","description":"","sidebar":"docs"},"core/glossary/terms/saml-binding":{"id":"core/glossary/terms/saml-binding","title":"SAML binding","description":"","sidebar":"docs"},"core/glossary/terms/scim":{"id":"core/glossary/terms/scim","title":"SCIM","description":"","sidebar":"docs"},"core/glossary/terms/scim-endpoints":{"id":"core/glossary/terms/scim-endpoints","title":"SCIM endpoints (Users, Groups)","description":"","sidebar":"docs"},"core/glossary/terms/scim-externalid":{"id":"core/glossary/terms/scim-externalid","title":"SCIM externalId","description":"","sidebar":"docs"},"core/glossary/terms/scim-lifecycle":{"id":"core/glossary/terms/scim-lifecycle","title":"SCIM provisioning lifecycle","description":"","sidebar":"docs"},"core/glossary/terms/scim-patch":{"id":"core/glossary/terms/scim-patch","title":"SCIM PATCH","description":"","sidebar":"docs"},"core/glossary/terms/scim-resource":{"id":"core/glossary/terms/scim-resource","title":"SCIM resource","description":"","sidebar":"docs"},"core/glossary/terms/scope":{"id":"core/glossary/terms/scope","title":"Scope","description":"","sidebar":"docs"},"core/glossary/terms/service-provider":{"id":"core/glossary/terms/service-provider","title":"Service Provider (SP)","description":"","sidebar":"docs"},"core/glossary/terms/single-logout":{"id":"core/glossary/terms/single-logout","title":"Single Logout (SLO)","description":"","sidebar":"docs"},"core/glossary/terms/source":{"id":"core/glossary/terms/source","title":"Source","description":"","sidebar":"docs"},"core/glossary/terms/sp-initiated-sso":{"id":"core/glossary/terms/sp-initiated-sso","title":"SP-initiated SSO","description":"","sidebar":"docs"},"core/glossary/terms/stage":{"id":"core/glossary/terms/stage","title":"Stage","description":"","sidebar":"docs"},"core/glossary/terms/subject":{"id":"core/glossary/terms/subject","title":"Subject (sub)","description":"","sidebar":"docs"},"core/glossary/terms/system-tasks":{"id":"core/glossary/terms/system-tasks","title":"System tasks","description":"","sidebar":"docs"},"core/glossary/terms/token-endpoint":{"id":"core/glossary/terms/token-endpoint","title":"Token endpoint","description":"","sidebar":"docs"},"core/glossary/terms/userinfo-endpoint":{"id":"core/glossary/terms/userinfo-endpoint","title":"UserInfo endpoint","description":"","sidebar":"docs"},"core/glossary/terms/webauthn":{"id":"core/glossary/terms/webauthn","title":"WebAuthn","description":"","sidebar":"docs"},"customize/blueprints/export":{"id":"customize/blueprints/export","title":"Export configurations to blueprints","de
1scription":"Global export","sidebar":"docs"},"customize/blueprints/index":{"id":"customize/blueprints/index","title":"Blueprints","description":"Blueprints provide a way to template, automate, and distribute authentik configuration. Blueprints can be used to automatically configure instances, manage infrastructure-as-code without any external tools, and to distribute application configurations. Blueprints are YAML files, whose format is described further in File structure.","sidebar":"docs"},"customize/blueprints/v1/example":{"id":"customize/blueprints/v1/example","title":"Example","description":"This is one of the default packaged blueprints to create the default authentication flow.","sidebar":"docs"},"customize/blueprints/v1/meta":{"id":"customize/blueprints/v1/meta","title":"Meta models","description":"Since blueprints have a pretty strict mapping of each entry to an instance of a model in the database, meta models exist to trigger other actions within authentik that don\'t directly map to a model.","sidebar":"docs"},"customize/blueprints/v1/models":{"id":"customize/blueprints/v1/models","title":"Models","description":"Some models behave differently and allow for access to different API fields when created via blueprint.","sidebar":"docs"},"customize/blueprints/v1/structure":{"id":"customize/blueprints/v1/structure","title":"File structure","description":"Blueprints are YAML files, which can use some additional tags to ease blueprint creation.","sidebar":"docs"},"customize/blueprints/v1/tags":{"id":"customize/blueprints/v1/tags","title":"YAML Tags","description":"To use the custom tags with your preferred editor, you must make the editor aware of the custom tags.","sidebar":"docs"},"customize/blueprints/working_with_blueprints":{"id":"customize/blueprints/working_with_blueprints","title":"Working with blueprints","description":"For an overview of what blueprints are, how they\'re executed, and where they are stored, see the Blueprints overview documentation.","sidebar":"docs"},"customize/branding/custom-css":{"id":"customize/branding/custom-css","title":"Custom CSS","description":"You can add custom CSS to further customize the look of authentik. Some areas where custom CSS can be applied include:","sidebar":"docs"},"customize/branding/index":{"id":"customize/branding/index","title":"Branding","description":"As an authentik administrator, you can customize your instance\'s appearance and behavior using brands. Brands apply to a single domain, a domain wildcard, or can be set as default, in which case the brand will be applied when no other brand matches the domain.","sidebar":"docs"},"customize/file-picker":{"id":"customize/file-picker","title":"File picker values","description":"Many fields in the authentik Admin interface use the same file picker. You can use it to select an uploaded file, reference a built-in static asset, point at an external URL, or use a Font Awesome icon.","sidebar":"docs"},"customize/files":{"id":"customize/files","title":"Files","description":"Image files are used in authentik to add icons to new applications or sources, and to define the \\"branded\\" look of the authentik interface, with your company\'s logo and title, a favicon, or a background image for the flows.","sidebar":"docs"},"customize/index":{"id":"customize/index","title":"Customize your instance","description":"You can customize the behavior, look, and available resources for your authentik instance. For more information, refer to each of the topics below:","sidebar":"docs"},"customize/interfaces/admin/index":{"id":"customize/interfaces/admin/index","title":"Customize the Admin interface","description":"The Admin interface can be customized using attributes configured in Brands.","sidebar":"docs"},"customize/interfaces/flow/index":{"id":"customize/interfaces/flow/index","title":"Customize a flow","description":"Typically, settings for flows are defined as defaults in the Brand settings. However, it\u2019s important to note that some flows are executed before the specific user is authenticated and thus before authentik can determine which user is viewing the flow (for example, the default-authentication-flow!). Consequently, using default settings for all flows ensures a more consistent user experience.","sidebar":"docs"},"customize/interfaces/user/index":{"id":"customize/interfaces/user/index","title":"Customize the User interface","description":"The User interface can be customized using attributes configured in Brands.","sidebar":"docs"},"customize/policies/bindings":{"id":"customize/policies/bindings","title":"Policy bindings and evaluation","description":"This page covers policy bindings: where they apply, how authentik evaluates them, and which options affect the result. For the broader binding model, see Bindings in authentik. For step-by-step instructions, see Working with policies.","sidebar":"docs"},"customize/policies/index":{"id":"customize/policies/index","title":"Policies","description":"Policies are reusable checks in authentik. They let you control whether a user can access an application, whether a stage in a flow should run, whether a source can be used, or whether data entered in a prompt stage is valid.","sidebar":"docs"},"customize/policies/types/event-matcher":{"id":"customize/policies/types/event-matcher","title":"Event Matcher Policy","description":"Use an Event Matcher policy when you want to match authentik events with built-in fields or an AKQL query.","sidebar":"docs"},"customize/policies/types/expression/index":{"id":"customize/policies/types/expression/index","title":"Expression Policies","description":"Expression policies let you write custom Python for cases where the built-in policy types are not enough.","sidebar":"docs"},"customize/policies/types/expression/managing_flow_context_keys":{"id":"customize/policies/types/expression/managing_flow_context_keys","title":"Managing flow context keys","description":"Flow context c
1an be read and updated from an Expression policy through context\\"flow_plan\\"].context. For more information about the active plan, see [Flow Planner.","sidebar":"docs"},"customize/policies/types/expression/reference":{"id":"customize/policies/types/expression/reference","title":"Expression Reference","description":"This page documents the expression policy execution environment in authentik.","sidebar":"docs"},"customize/policies/types/expression/source_switch":{"id":"customize/policies/types/expression/source_switch","title":"Switch which source is used based on email address","description":"You can use an expression policy to route users to different sources based on the email address they enter.","sidebar":"docs"},"customize/policies/types/expression/unique_email":{"id":"customize/policies/types/expression/unique_email","title":"Ensure unique email addresses","description":"By default, authentik does not require email addresses to be unique. If you want to enforce uniqueness, use an expression policy during enrollment or profile-edit flows.","sidebar":"docs"},"customize/policies/types/expression/whitelist_email":{"id":"customize/policies/types/expression/whitelist_email","title":"Allow only specific email domains","description":"Use an expression policy when only specific email domains should be allowed to enroll or authenticate.","sidebar":"docs"},"customize/policies/types/geoip":{"id":"customize/policies/types/geoip","title":"GeoIP Policy","description":"Use a GeoIP policy when you want to make access decisions based on where a request appears to come from.","sidebar":"docs"},"customize/policies/types/index":{"id":"customize/policies/types/index","title":"Types of policies in authentik","description":"These pages describe the built-in policy objects you can create in authentik.","sidebar":"docs"},"customize/policies/types/password":{"id":"customize/policies/types/password","title":"Password Policy","description":"Use a Password policy when you want to validate a password entered in a prompt stage.","sidebar":"docs"},"customize/policies/types/password-expiry":{"id":"customize/policies/types/password-expiry","title":"Password Expiry Policy","description":"Use a Password Expiry policy when passwords should expire after a fixed number of days.","sidebar":"docs"},"customize/policies/types/password-uniqueness":{"id":"customize/policies/types/password-uniqueness","title":"Password Uniqueness Policy","description":"The Password Uniqueness policy is an enterprise policy that prevents users from reusing previously used passwords.","sidebar":"docs"},"customize/policies/types/reputation":{"id":"customize/policies/types/reputation","title":"Reputation Policy","description":"Use a Reputation policy when you want authentik to react to repeated failed authentication attempts from a username, a client IP, or both.","sidebar":"docs"},"customize/policies/working_with_policies":{"id":"customize/policies/working_with_policies","title":"Working with policies","description":"For an overview of policies, refer to our documentation on Policies.","sidebar":"docs"},"developer-docs/contributing":{"id":"developer-docs/contributing","title":"Contributing to authentik","description":"Guidelines for contributing code, docs, and enhancements to authentik.","sidebar":"docs"},"developer-docs/docs/style-guide":{"id":"developer-docs/docs/style-guide","title":"Style guide","description":"This style guide helps keep authentik documentation consistent, clear, and easy to follow. It standardizes phrasing, formatting, tone, and structure.","sidebar":"docs"},"developer-docs/docs/templates/combo":{"id":"developer-docs/docs/templates/combo","title":"Combination topic (most common)","description":"Start with the MDX template, either by copying the combo.tmpl.mdx file from our GitHub repo or downloading the template file using the following command:","sidebar":"docs"},"developer-docs/docs/templates/combo.tmpl":{"id":"developer-docs/docs/templates/combo.tmpl","title":"MDX template: combo","description":"Add a brief description of the feature or functionality.","sidebar":"docs"},"developer-docs/docs/templates/conceptual":{"id":"developer-docs/docs/templates/conceptual","title":"Conceptual topic","description":"Start with the MDX template, either by copying the conceptual.tmpl.mdx file from our GitHub repo or downloading the template file using the following command:","sidebar":"docs"},"developer-docs/docs/templates/conceptual.tmpl":{"id":"developer-docs/docs/templates/conceptual.tmpl","title":"MDX template: conceptual","description":"Write a few sentences introducing the feature/component/technology.","sidebar":"docs"},"developer-docs/docs/templates/index":{"id":"developer-docs/docs/templates/index","title":"Templates","de
1scription":"In technical documentation, there are document \\"types\\" (similar to how there are data types). We have templates for the different types, to make it super-easy to divide longer topics into separate pages (one for each content type) if needed. And templates in general make it easy for whomever wants to contribute some documentation!","sidebar":"docs"},"developer-docs/docs/templates/procedural":{"id":"developer-docs/docs/templates/procedural","title":"Procedural topic","description":"Start with the MDX template, either by copying the procedural.tmpl.mdx file from our GitHub repo or downloading the template file using the following command:","sidebar":"docs"},"developer-docs/docs/templates/procedural.tmpl":{"id":"developer-docs/docs/templates/procedural.tmpl","title":"MDX template: procedural","description":"Add a brief description of the feature or functionality.","sidebar":"docs"},"developer-docs/docs/templates/reference":{"id":"developer-docs/docs/templates/reference","title":"Reference topic","description":"Start with the MDX template, either by copying the reference.tmpl.mdx file from our GitHub repo or downloading the template file using the following command:","sidebar":"docs"},"developer-docs/docs/templates/reference.tmpl":{"id":"developer-docs/docs/templates/reference.tmpl","title":"MDX template: reference","description":"Write a few sentences introducing the feature/component/technology, and state that this page contains reference materials.","sidebar":"docs"},"developer-docs/docs/theming/index":{"id":"developer-docs/docs/theming/index","title":"Documentation Theming","description":"This section is intended for developers of authentik\'s documentation site. If you are looking to customize the theming of your own authentik instance, please refer to the branding documentation."},"developer-docs/docs/writing-documentation":{"id":"developer-docs/docs/writing-documentation","title":"Writing documentation","description":"Writing documentation for authentik is a great way for both new and experienced users to improve and contribute to the project. We appreciate contributions to our documentation, from fixing typos and adding content to writing completely new topics.","sidebar":"docs"},"developer-docs/frontend/cascade-layers":{"id":"developer-docs/frontend/cascade-layers","title":"Cascade layers","description":"How authentik\'s web UI orders its CSS with @layer, and where each kind of rule belongs."},"developer-docs/frontend/css-architecture":{"id":"developer-docs/frontend/css-architecture","title":"CSS architecture","description":"How authentik\'s runtime CSS and design tokens fit together across the theme package, the document cascade, and Lit components."},"developer-docs/hackathon/index":{"id":"developer-docs/hackathon/index","title":"2023 hackathon archive","description":"Participants collaborating during a hackathon"},"developer-docs/index":{"id":"developer-docs/index","title":"Developer Documentation","description":"Quick links and entry points for developers working on authentik.","sidebar":"docs"},"developer-docs/setup/debugging":{"id":"developer-docs/setup/debugging","title":"Debugging authentik","description":"This page describes how to debug different components of an authentik instance, running either in production or in a development setup. To learn more about the structure of authentik, refer to our architecture documentation.","sidebar":"docs"},"developer-docs/setup/frontend-dev-environment":{"id":"developer-docs/setup/frontend-dev-environment","title":"Frontend development environment","description":"If you\'re focusing solely on frontend development, you can create a minimal development environment using Docker and Node.js. This setup allows you to make and preview changes to the frontend in real-time, without needing to interact with the backend.","sidebar":"docs"},"developer-docs/setup/full-dev-environment":{"id":"developer-docs/setup/full-dev-environment","title":"Full development environment","description":"Prerequisites","sidebar":"docs"},"developer-docs/setup/index":{"id":"developer-docs/setup/index","title":"Development environment","description":"Choose how you want to run and work on authentik.","sidebar":"docs"},"developer-docs/translation":{"id":"developer-docs/translation","title":"Translations","description":"authentik uses @lit/localize for frontend translations and Django\'s translation tools for backend messages. English is the source language for both.","sidebar":"docs"},"endpoint-devices/authentik-agent/agent-deployment/automated":{"id":"endpoint-devices/authentik-agent/agent-deployment/automated","title":"Automated authentik Agent deployment","description":"The authentik Agent can be deployed at scale to multiple devices via Mobile Device Management (MDM) and automation tools.","sidebar":"docs"},"endpoint-devices/authentik-agent/agent-deployment/index":{"id":"endpoint-devices/authentik-agent/agent-deployment/index","title":"Deployment","description":"You can deploy the authentik Agent on Linux, macOS, and Windows devices.","sidebar":"docs"},"endpoint-devices/authentik-agent/agent-deployment/linux":{"id":"endpoint-devices/authentik-agent/agent-deployment/linux","title":"Deploy authentik Agent on Linux","description":"What it can do","sidebar":"docs"},"endpoint-devices/authentik-agent/agent-deployment/macos":{"id":"endpoint-devices/authentik-agent/agent-deployment/macos","title":"Deploy authentik Agent on macOS","de
1scription":"What it can do","sidebar":"docs"},"endpoint-devices/authentik-agent/agent-deployment/windows":{"id":"endpoint-devices/authentik-agent/agent-deployment/windows","title":"Deploy authentik Agent on Windows","description":"What it can do","sidebar":"docs"},"endpoint-devices/authentik-agent/authentik-cli":{"id":"endpoint-devices/authentik-agent/authentik-cli","title":"Agent CLI commands","description":"The following commands are available when interacting with the authentik Agent via the command line.","sidebar":"docs"},"endpoint-devices/authentik-agent/configuration":{"id":"endpoint-devices/authentik-agent/configuration","title":"Configuration","description":"Before deploying the authentik Agent, configure your authentik deployment. This involves:","sidebar":"docs"},"endpoint-devices/authentik-agent/development":{"id":"endpoint-devices/authentik-agent/development","title":"Development","description":"The authentik Agent and associated components are developed in the authentik Platform GitHub repository. For source code and information on contributing to the project, refer to the documentation included in the GitHub repository.","sidebar":"docs"},"endpoint-devices/authentik-agent/device-authentication/cli-app-authentication/aws":{"id":"endpoint-devices/authentik-agent/device-authentication/cli-app-authentication/aws","title":"AWS CLI authentication","description":"You can use the authentik Agent to authenticate to the AWS CLI with authentik credentials.","sidebar":"docs"},"endpoint-devices/authentik-agent/device-authentication/cli-app-authentication/index":{"id":"endpoint-devices/authentik-agent/device-authentication/cli-app-authentication/index","title":"CLI application authentication","description":"The authentik Agent can authenticate to CLI applications such as aws and kubectl.","sidebar":"docs"},"endpoint-devices/authentik-agent/device-authentication/cli-app-authentication/k8s":{"id":"endpoint-devices/authentik-agent/device-authentication/cli-app-authentication/k8s","title":"Kubernetes CLI authentication","description":"You can use the authentik Agent to authenticate to kubectl with authentik credentials.","sidebar":"docs"},"endpoint-devices/authentik-agent/device-authentication/device-access-groups":{"id":"endpoint-devices/authentik-agent/device-authentication/device-access-groups","title":"Device access groups","description":"Device access groups control access to endpoint devices. You can organize devices into groups and bind users, user groups, and policies to determine which users can access the device.","sidebar":"docs"},"endpoint-devices/authentik-agent/device-authentication/index":{"id":"endpoint-devices/authentik-agent/device-authentication/index","title":"Device authentication","description":"The authentik Agent supports multiple types of authentication and authorization using authentik credentials:","sidebar":"docs"},"endpoint-devices/authentik-agent/device-authentication/local-device-login/index":{"id":"endpoint-devices/authentik-agent/device-authentication/local-device-login/index","title":"Local device login","description":"Local device login allows you to log in to devices using authentik credentials instead of separate local accounts.","sidebar":"docs"},"endpoint-devices/authentik-agent/device-authentication/local-device-login/linux":{"id":"endpoint-devices/authentik-agent/device-authentication/local-device-login/linux","title":"Linux local device login","description":"Prerequisites","sidebar":"docs"},"endpoint-devices/authentik-agent/device-authentication/local-device-login/windows":{"id":"endpoint-devices/authentik-agent/device-authentication/local-device-login/windows","title":"Windows local device login","description":"Windows Credential Provider","sidebar":"docs"},"endpoint-devices/authentik-agent/device-authentication/ssh-authentication":{"id":"endpoint-devices/authentik-agent/device-authentication/ssh-authentication","title":"SSH authentication","description":"You can use the authentik Agent to authenticate SSH connections between endpoint devices using authentik credentials.","sidebar":"docs"},"endpoint-devices/authentik-agent/download":{"id":"endpoint-devices/authentik-agent/download","title":"Download the authentik Agent","description":"Download the authentik Agent installer for macOS or Windows, or install it on Linux from the APT or RPM repository.","sidebar":"docs"},"endpoint-devices/authentik-agent/index":{"id":"endpoint-devices/authentik-agent/index","title":"authentik Agent","description":"What is the authentik Agent?","sidebar":"docs"},"endpoint-devices/authentik-agent/release-notes/index":{"id":"endpoint-devices/authentik-agent/release-notes/index","title":"authentik Agent Releases","description":"Release notes for recent authentik Agent versions","sidebar":"docs"},"endpoint-devices/authentik-agent/release-notes/template":{"id":"endpoint-devices/authentik-agent/release-notes/template","title":"x.x.x","description":"Highlights","sidebar":"docs"},"endpoint-devices/authentik-agent/release-notes/v0.35":{"id":"endpoint-devices/authentik-agent/release-notes/v0.35","title":"Release 0.35","description":"Highlights","sidebar":"docs"},"endpoint-devices/authentik-agent/release-notes/v0.40":{"id":"endpoint-devices/authentik-agent/release-notes/v0.40","title":"Release 0.40","de
1scription":"Highlights","sidebar":"docs"},"endpoint-devices/device-compliance/browser-extension":{"id":"endpoint-devices/device-compliance/browser-extension","title":"authentik browser extension","description":"The authentik Endpoint SSO browser extension is required for device compliance functionality, and is currently available via the Chrome Web Store, the Firefox Add-ons site, and the Edge Add-ons site.","sidebar":"docs"},"endpoint-devices/device-compliance/configuration":{"id":"endpoint-devices/device-compliance/configuration","title":"Configuration","description":"Prerequisites","sidebar":"docs"},"endpoint-devices/device-compliance/connectors/authentik-agent":{"id":"endpoint-devices/device-compliance/connectors/authentik-agent","title":"authentik Agent connector","description":"The authentik Agent connector allows device information to be reported by the authentik Agent.","sidebar":"docs"},"endpoint-devices/device-compliance/connectors/fleetdm":{"id":"endpoint-devices/device-compliance/connectors/fleetdm","title":"Fleet connector","description":"Fleet is an open-source device management platform designed to monitor, manage, and secure large fleets of devices.","sidebar":"docs"},"endpoint-devices/device-compliance/connectors/google-chrome":{"id":"endpoint-devices/device-compliance/connectors/google-chrome","title":"Google Chrome connector","description":"With this connector, authentik can validate users\' Chrome browsers and ensure that users\' devices are compliant and up-to-date.","sidebar":"docs"},"endpoint-devices/device-compliance/connectors/index":{"id":"endpoint-devices/device-compliance/connectors/index","title":"Connectors","description":"Connectors allow device information to be reported to authentik. Connectors for third-party services like Fleet can be used standalone or alongside the authentik Agent connector.","sidebar":"docs"},"endpoint-devices/device-compliance/device-compliance-policy":{"id":"endpoint-devices/device-compliance/device-compliance-policy","title":"Device compliance policy","description":"Device compliance policies are used to limit access to authentik and applications based on Device Compliance information.","sidebar":"docs"},"endpoint-devices/device-compliance/device-reporting":{"id":"endpoint-devices/device-compliance/device-reporting","title":"Device reporting","description":"Endpoint devices registered with authentik through a connector, such as the authentik Agent connector, regularly check in with authentik and report their device facts.","sidebar":"docs"},"endpoint-devices/device-compliance/fleet-conditional-access":{"id":"endpoint-devices/device-compliance/fleet-conditional-access","title":"Fleet conditional access for Apple devices","description":"authentik can be configured to restrict access to specific services so that only Fleet-registered Apple devices are allowed.","sidebar":"docs"},"endpoint-devices/device-compliance/index":{"id":"endpoint-devices/device-compliance/index","title":"Device Compliance","description":"Device compliance lets authentik verify that a user\'s device meets security and configuration criteria, such as operating system version, disk encryption, antivirus status etc, before allowing access to resources.","sidebar":"docs"},"endpoint-devices/index":{"id":"endpoint-devices/index","title":"Endpoint Devices","description":"The endpoint devices feature set is currently in early preview and in development. It is not recommended for production use.","sidebar":"docs"},"endpoint-devices/manage-devices":{"id":"endpoint-devices/manage-devices","title":"Manage devices","description":"The Devices page provides a list of all endpoint devices registered with your authentik deployment. Refer to Device reporting for more details on how device facts are reported to authentik.","sidebar":"docs"},"enterprise/enterprise-features":{"id":"enterprise/enterprise-features","title":"Enterprise features","description":"Features included in authentik Enterprise","sidebar":"docs"},"enterprise/enterprise-support":{"id":"enterprise/enterprise-support","title":"Enterprise support","description":"Open and manage authentik Enterprise support tickets","sidebar":"docs"},"enterprise/get-started":{"id":"enterprise/get-started","title":"Get started with authentik Enterprise","description":"Obtain and install an Enterprise license, including in air-gapped environments.","sidebar":"docs"},"enterprise/index":{"id":"enterprise/index","title":"authentik Enterprise","description":"Enterprise features, offline license installation, license management, and support.","sidebar":"docs"},"enterprise/manage-enterprise":{"id":"enterprise/manage-enterprise","title":"Manage licenses and billing","description":"Manage authentik Customer Portal organizations, licenses, and billing","sidebar":"docs"},"index":{"id":"index","title":"Welcome to authentik","description":"What is authentik?","sidebar":"docs"},"install-config/air-gapped":{"id":"install-config/air-gapped","title":"Air-gapped environments","description":"Install, license, and upgrade authentik without internet access.","sidebar":"docs"},"install-config/automated-install":{"id":"install-config/automated-install","title":"Automated install","description":"To install authentik automatically (skipping the Out-of-box experience), you can use the following environment variables on the worker container:","sidebar":"docs"},"install-config/beta":{"id":"install-config/beta","title":"Beta and release candidate versions","description":"You can test upcoming authentik versions before they are released as stable. There are two types of pre-release versions available:","sidebar":"docs"},"install-config/configuration/configuration":{"id":"install-config/configuration/configuration","title":"Configuration","description":"This page details all the authentik configuration options that you can set via environment variables.","sidebar":"docs"},"install-config/email":{"id":"install-config/email","title":"Email","description":"This page covers both configuring authentik to send email and testing that email delivery is working.","sidebar":"docs"},"install-config/first-steps/index":{"id":"install-config/first-steps/index","title":"First steps","description":"After you have installed and started authentik, you are now ready to add your first application and provider, add some users, and get started with using authentik as your Identity provider.","sidebar":"docs"},"install-config/high-availability":{"id":"install-config/high-availability","title":"High availability","de
1scription":"High availability refers to system design that minimizes downtime even in the event of failures or disruptions.","sidebar":"docs"},"install-config/index":{"id":"install-config/index","title":"Installation and Configuration","description":"Everything you need to get authentik up and running!","sidebar":"docs"},"install-config/install/aws":{"id":"install-config/install/aws","title":"AWS installation","description":"You can install authentik to run on AWS with a CloudFormation template.","sidebar":"docs"},"install-config/install/docker-compose":{"id":"install-config/install/docker-compose","title":"Docker Compose installation","description":"This installation method is for test setups and small-scale production setups.","sidebar":"docs"},"install-config/install/kubernetes":{"id":"install-config/install/kubernetes","title":"Kubernetes installation","description":"You can install authentik to run on Kubernetes using a Helm chart.","sidebar":"docs"},"install-config/reverse-proxy":{"id":"install-config/reverse-proxy","title":"Reverse proxy","description":"Use this page when authentik is exposed through a reverse proxy or load balancer.","sidebar":"docs"},"install-config/upgrade":{"id":"install-config/upgrade","title":"Upgrade authentik","description":"Upgrading to the latest version of authentik, whether a new major release or a patch, involves running a few commands to pull down the latest images and then restarting the servers and databases.","sidebar":"docs"},"releases/2021/v2021.1":{"id":"releases/2021/v2021.1","title":"Release 2021.1","description":"Headline Changes","sidebar":"docs"},"releases/2021/v2021.10":{"id":"releases/2021/v2021.10","title":"Release 2021.10","description":"Headline Changes","sidebar":"docs"},"releases/2021/v2021.12":{"id":"releases/2021/v2021.12","title":"Release 2021.12","description":"Headline changes","sidebar":"docs"},"releases/2021/v2021.2":{"id":"releases/2021/v2021.2","title":"Release 2021.2","description":"Headline Changes","sidebar":"docs"}
1,"releases/2021/v2021.3":{"id":"releases/2021/v2021.3","title":"Release 2021.3","description":"Headline Changes","sidebar":"docs"},"releases/2021/v2021.4":{"id":"releases/2021/v2021.4","title":"Release 2021.4","description":"Headline Changes","sidebar":"docs"},"releases/2021/v2021.5":{"id":"releases/2021/v2021.5","title":"Release 2021.5","description":"Headline Changes","sidebar":"docs"},"releases/2021/v2021.6":{"id":"releases/2021/v2021.6","title":"Release 2021.6","description":"Headline Changes","sidebar":"docs"},"releases/2021/v2021.7":{"id":"releases/2021/v2021.7","title":"Release 2021.7","description":"Headline Changes","sidebar":"docs"},"releases/2021/v2021.8":{"id":"releases/2021/v2021.8","title":"Release 2021.8","description":"Headline Changes","sidebar":"docs"},"releases/2021/v2021.9":{"id":"releases/2021/v2021.9","title":"Release 2021.9","description":"Headline Changes","sidebar":"docs"},"releases/2022/v2022.1":{"id":"releases/2022/v2022.1","title":"Release 2022.1","description":"Breaking changes","sidebar":"docs"},"releases/2022/v2022.10":{"id":"releases/2022/v2022.10","title":"Release 2022.10","description":"Breaking changes","sidebar":"docs"},"releases/2022/v2022.11":{"id":"releases/2022/v2022.11","title":"Release 2022.11","description":"Breaking changes","sidebar":"docs"},"releases/2022/v2022.12":{"id":"releases/2022/v2022.12","title":"Release 2022.12","description":"Breaking changes","sidebar":"docs"},"releases/2022/v2022.2":{"id":"releases/2022/v2022.2","title":"Release 2022.2","description":"Breaking changes","sidebar":"docs"},"releases/2022/v2022.3":{"id":"releases/2022/v2022.3","title":"Release 2022.3","description":"New features","sidebar":"docs"},"releases/2022/v2022.4":{"id":"releases/2022/v2022.4","title":"Release 2022.4","description":"Breaking changes","sidebar":"docs"},"releases/2022/v2022.5":{"id":"releases/2022/v2022.5","title":"Release 2022.5","description":"Breaking changes","sidebar":"docs"},"releases/2022/v2022.6":{"id":"releases/2022/v2022.6","title":"Release 2022.6","description":"New features","sidebar":"docs"},"releases/2022/v2022.7":{"id":"releases/2022/v2022.7","title":"Release 2022.7","description":"Breaking changes","sidebar":"docs"},"releases/2022/v2022.8":{"id":"releases/2022/v2022.8","title":"Release 2022.8","description":"Breaking changes","sidebar":"docs"},"releases/2022/v2022.9":{"id":"releases/2022/v2022.9","title":"Release 2022.9","description":"Breaking changes","sidebar":"docs"},"releases/2023/v2023.1":{"id":"releases/2023/v2023.1","title":"Release 2023.1","description":"Breaking changes","sidebar":"docs"},"releases/2023/v2023.10":{"id":"releases/2023/v2023.10","title":"Release 2023.10","description":"Breaking changes","sidebar":"docs"},"releases/2023/v2023.2":{"id":"releases/2023/v2023.2","title":"Release 2023.2 - Signout and Avatar improvements","description":"New features","sidebar":"docs"},"releases/2023/v2023.3":{"id":"releases/2023/v2023.3","title":"Release 2023.3 - SCIM support","description":"New features","sidebar":"docs"},"releases/2023/v2023.4":{"id":"releases/2023/v2023.4","title":"Release 2023.4 - RADIUS support","description":"Breaking changes","sidebar":"docs"},"releases/2023/v2023.5":{"id":"releases/2023/v2023.5","title":"Release 2023.5","description":"Breaking changes","sidebar":"docs"},"releases/2023/v2023.6":{"id":"releases/2023/v2023.6","title":"Release 2023.6","description":"New features","sidebar":"docs"},"releases/2023/v2023.8":{"id":"releases/2023/v2023.8","title":"Release 2023.8","description":"Breaking changes","sidebar":"docs"},"releases/2024/v2024.10":{"id":"releases/2024/v2024.10","title":"Release 2024.10","description":"Highlights","sidebar":"docs"},"releases/2024/v2024.12":{"id":"releases/2024/v2024.12","title":"Release 2024.12","description":"Highlights","sidebar":"docs"},"releases/2024/v2024.2":{"id":"releases/2024/v2024.2","title":"Release 2024.2","description":"Highlights","sidebar":"docs"},"releases/2024/v2024.4":{"id":"releases/2024/v2024.4","title":"Release 2024.4","description":"Highlights","sidebar":"docs"},"releases/2024/v2024.6":{"id":"releases/2024/v2024.6","title":"Release 2024.6","description":"Highlights","sidebar":"docs"},"releases/2024/v2024.8":{"id":"releases/2024/v2024.8","title":"Release 2024.8","description":"Highlights","sidebar":"docs"},"releases/2025/v2025.10":{"id":"releases/2025/v2025.10","title":"Release 2025.10","description":"Highlights","sidebar":"docs"},"releases/2025/v2025.12":{"id":"releases/2025/v2025.12","title":"Release 2025.12","description":"Highlights","sidebar":"docs"},"releases/2025/v2025.2":{"id":"releases/2025/v2025.2","title":"Release 2025.2","description":"Highlights","sidebar":"docs"},"releases/2025/v2025.4":{"id":"releases/2025/v2025.4","title":"Release 2025.4","description":"Highlights","sidebar":"docs"},"releases/2025/v2025.6":{"id":"releases/2025/v2025.6","title":"Release 2025.6","description":"Highlights","sidebar":"docs"},"releases/2025/v2025.8":{"id":"releases/2025/v2025.8","title":"Release 2025.8","description":"Highlights","sidebar":"docs"},"releases/2026/v2026.2":{"id":"releases/2026/v2026.2","title":"Release 2026.2","description":"Highlights","sidebar":"docs"},"releases/2026/v2026.5":{"id":"releases/2026/v2026.5","title":"Release 2026.5","description":"Highlights","sidebar":"docs"}
1,"releases/2026/v2026.8":{"id":"releases/2026/v2026.8","title":"Release 2026.8","description":"Highlights","sidebar":"docs"},"releases/old/v0.10":{"id":"releases/old/v0.10","title":"Release 0.10","description":"This update brings a lot of big features, such as:","sidebar":"docs"},"releases/old/v0.11":{"id":"releases/old/v0.11","title":"Release 0.11","description":"This update brings these headline features:","sidebar":"docs"},"releases/old/v0.12":{"id":"releases/old/v0.12","title":"Release 0.12","description":"This update brings these headline features:","sidebar":"docs"},"releases/old/v0.13":{"id":"releases/old/v0.13","title":"Release 0.13 (passbook -> authentik)","description":"After a long back and forth, we\'ve finally switched to a more permanent name. Whilst the upgrade is pretty much seamless, there are some things you have to change before upgrading.","sidebar":"docs"},"releases/old/v0.14":{"id":"releases/old/v0.14","title":"Release 0.14","description":"Headline features","sidebar":"docs"},"releases/old/v0.9":{"id":"releases/old/v0.9","title":"Release 0.9","description":"Due to some database changes that had to be rather sooner than later, there is no possibility to directly upgrade. You must extract the data before hand and import it again. It is recommended to spin up a second instance of authentik to do this.","sidebar":"docs"},"security/account-lockdown":{"id":"security/account-lockdown","title":"Account Lockdown","description":"Account Lockdown is a security feature that allows administrators to quickly secure a user account during emergencies, such as suspected compromise or unauthorized access. Users can also lock down their own account if they believe it has been compromised.","sidebar":"docs"},"security/audits-and-certs/2023-06-cure53":{"id":"security/audits-and-certs/2023-06-cure53","title":"2023-06 Cure53 Code audit","description":"In May/June of 2023, we had a pentest conducted by Cure53. The following security updates, 2023.4.2 and 2023.5.3 were released as a response to the found issues.","sidebar":"docs"},"security/audits-and-certs/2024-11-cobalt":{"id":"security/audits-and-certs/2024-11-cobalt","title":"2024-11 Cobalt pentest","description":"We are committed to engaging in regular pentesting and security audits of authentik. Defining and adhering to a cadence of external testing ensures a stronger probability that our code base, our features, and our architecture is as secure and non-exploitable as possible.","sidebar":"docs"},"security/audits-and-certs/2025-09-includesec":{"id":"security/audits-and-certs/2025-09-includesec","title":"2025-09 IncludeSec pentest","description":"In September of 2025, we had a pentest conducted by Include Security. This resulted in a number of code improvements to our application, however did not result in any assigned CVEs.","sidebar":"docs"},"security/cves/CVE-2022-23555":{"id":"security/cves/CVE-2022-23555","title":"CVE-2022-23555","description":"Reported by @fuomag9","sidebar":"docs"},"security/cves/CVE-2022-46145":{"id":"security/cves/CVE-2022-46145","title":"CVE-2022-46145","description":"Reported by @sdimovv","sidebar":"docs"},"security/cves/CVE-2022-46172":{"id":"security/cves/CVE-2022-46172","title":"CVE-2022-46172","description":"Reported by @DreamingRaven","sidebar":"docs"},"security/cves/CVE-2023-26481":{"id":"security/cves/CVE-2023-26481","title":"CVE-2023-26481","description":"Reported by @fuomag9","sidebar":"docs"},"security/cves/CVE-2023-36456":{"id":"security/cves/CVE-2023-36456","title":"CVE-2023-36456","description":"Reported by @thijsa","sidebar":"docs"},"security/cves/CVE-2023-39522":{"id":"security/cves/CVE-2023-39522","title":"CVE-2023-39522","description":"Reported by @markrassamni","sidebar":"docs"},"security/cves/CVE-2023-46249":{"id":"security/cves/CVE-2023-46249","title":"CVE-2023-46249","description":"Reported by @devSparkle","sidebar":"docs"},"security/cves/CVE-2023-48228":{"id":"security/cves/CVE-2023-48228","title":"CVE-2023-48228","description":"Reported by @Sapd","sidebar":"docs"}
1,"security/cves/CVE-2024-21637":{"id":"security/cves/CVE-2024-21637","title":"CVE-2024-21637","description":"Reported by @lauritzh","sidebar":"docs"},"security/cves/CVE-2024-23647":{"id":"security/cves/CVE-2024-23647","title":"CVE-2024-23647","description":"Reported by @pieterphilippaerts","sidebar":"docs"},"security/cves/CVE-2024-37905":{"id":"security/cves/CVE-2024-37905","title":"CVE-2024-37905","description":"Reported by @m2a2","sidebar":"docs"},"security/cves/CVE-2024-38371":{"id":"security/cves/CVE-2024-38371","title":"CVE-2024-38371","description":"Reported by Stefan Zwanenburg","sidebar":"docs"},"security/cves/CVE-2024-42490":{"id":"security/cves/CVE-2024-42490","title":"CVE-2024-42490","description":"Reported by @m2a2","sidebar":"docs"},"security/cves/CVE-2024-47070":{"id":"security/cves/CVE-2024-47070","title":"CVE-2024-47070","description":"Reported by @efpi-bot from LogicalTrust","sidebar":"docs"},"security/cves/CVE-2024-47077":{"id":"security/cves/CVE-2024-47077","title":"CVE-2024-47077","description":"Reported by @quentinmit","sidebar":"docs"},"security/cves/CVE-2024-52287":{"id":"security/cves/CVE-2024-52287","title":"CVE-2024-52287","description":"Reported by @matt1097","sidebar":"docs"},"security/cves/CVE-2024-52289":{"id":"security/cves/CVE-2024-52289","title":"CVE-2024-52289","description":"Reported by @PontusHanssen","sidebar":"docs"},"security/cves/CVE-2024-52307":{"id":"security/cves/CVE-2024-52307","title":"CVE-2024-52307","description":"Reported by @mgerstner","sidebar":"docs"},"security/cves/CVE-2025-29928":{"id":"security/cves/CVE-2025-29928","title":"CVE-2025-29928","description":"Deletion of sessions did not revoke sessions when using database session storage","sidebar":"docs"},"security/cves/CVE-2025-52553":{"id":"security/cves/CVE-2025-52553","title":"CVE-2025-52553","description":"Reported by SPIEGEL-Verlag","sidebar":"docs"},"security/cves/CVE-2025-53942":{"id":"security/cves/CVE-2025-53942","title":"CVE-2025-53942","description":"Reported by @pascalwei","sidebar":"docs"},"security/cves/CVE-2025-64521":{"id":"security/cves/CVE-2025-64521","title":"CVE-2025-64521","description":"Deactivated service account can authenticate to OAuth","sidebar":"docs"},"security/cves/CVE-2025-64708":{"id":"security/cves/CVE-2025-64708","title":"CVE-2025-64708","description":"Reported by @melizeche","sidebar":"docs"},"security/cves/CVE-2026-25227":{"id":"security/cves/CVE-2026-25227","title":"CVE-2026-25227","description":"Reported by @rahulgovind","sidebar":"docs"},"security/cves/CVE-2026-25748":{"id":"security/cves/CVE-2026-25748","title":"CVE-2026-25748","description":"Reported by @imlonghao","sidebar":"docs"},"security/cves/CVE-2026-25922":{"id":"security/cves/CVE-2026-25922","title":"CVE-2026-25922","description":"Reported by @odgrso","sidebar":"docs"},"security/cves/CVE-2026-40165":{"id":"security/cves/CVE-2026-40165","title":"CVE-2026-40165","description":"Reported by @kodareef5, @Android-Login-Analysis, and @AyushParkara","sidebar":"docs"},"security/cves/CVE-2026-40166":{"id":"security/cves/CVE-2026-40166","title":"CVE-2026-40166","description":"Reported by @Colbascov","sidebar":"docs"},"security/cves/CVE-2026-41569":{"id":"security/cves/CVE-2026-41569","title":"CVE-2026-41569","description":"Reported by @jmecom and @AyushParkara","sidebar":"docs"},"security/cves/CVE-2026-42849":{"id":"security/cves/CVE-2026-42849","title":"CVE-2026-42849","description":"Reported by Jan Kahmen, turingpoint GmbH","sidebar":"docs"},"security/cves/CVE-2026-47201":{"id":"security/cves/CVE-2026-47201","title":"CVE-2026-47201","description":"XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user","sidebar":"docs"},"security/cves/CVE-2026-49443":{"id":"security/cves/CVE-2026-49443","title":"CVE-2026-49443","description":"SourceStage bypass via empty POST","sidebar":"docs"},"security/cves/CVE-2026-49448":{"id":"security/cves/CVE-2026-49448","title":"CVE-2026-49443 / GHSA-5wcc-hf24-rf5h","description":"UserSourceConnection.user and GroupSourceConnection.group are changeable through the API","sidebar":"docs"},"security/cves/CVE-2026-54730":{"id":"security/cves/CVE-2026-54730","title":"CVE-2026-54730 / GHSA-3v9h-3hrm-29cx","description":"Reported by @dhairya7760","sidebar":"docs"},"security/cves/CVE-2026-55106":{"id":"security/cves/CVE-2026-55106","title":"CVE-2026-55106 / GHSA-h8ff-c3h7-2gf8","description":"Reported by @geo-chen","sidebar":"docs"},"security/cves/CVE-2026-57580":{"id":"security/cves/CVE-2026-57580","title":"CVE-2026-57580 / GHSA-35v6-hv2g-6992","description":"Reported by @XlabAITeam, @vcth4nh, @ericchiang, @LHeiakim","sidebar":"docs"},"security/cves/GHSA-4r87-w2cx-fr3f":{"id":"security/cves/GHSA-4r87-w2cx-fr3f","title":"GHSA-4r87-w2cx-fr3f","description":"Reported by @kamil-sawicki, @savio-doyensec, and @szybnev","sidebar":"docs"},"security/cves/GHSA-5wcc-hf24-rf5h":{"id":"security/cves/GHSA-5wcc-hf24-rf5h","title":"GHSA-5wcc-hf24-rf5h","description":"Reported by @bugbunny-research","sidebar":"docs"},"security/cves/GHSA-cqj8-fxxf-9pg7":{"id":"security/cves/GHSA-cqj8-fxxf-9pg7","title":"GHSA-cqj8-fxxf-9pg7","description":"Reported by @0xWerz, @JebeenLee, @renmizo, @bhaswanthc, @vcth4nh, @bozellqp, @kanywst, @LoganCybersec, @g
1igioneggiando, @DavidCarliez","sidebar":"docs"},"security/cves/GHSA-cxwx-9x59-28qm":{"id":"security/cves/GHSA-cxwx-9x59-28qm","title":"GHSA-cxwx-9x59-28qm","description":"Denial of Service via Malformed SAML Messages","sidebar":"docs"},"security/cves/GHSA-h6c5-mpvq-j4jc":{"id":"security/cves/GHSA-h6c5-mpvq-j4jc","title":"GHSA-h6c5-mpvq-j4jc","description":"Reported by @tonghuaroot, @Uhudsavasindankacanokcu2, @oduoke567, @szybnev, @Hann1bl3L3ct3r, @voraci0us, @everping, @4dollar4, @arthurscchan, @DavidKorczynski, @AdamKorcz, @r0hanSH, @thefoulowl, @bayramshirinov, @MayankPandey01, @DavidCarliez, @XlabAITeam, @keenanwgn, @pkuGenuine, @liangjs, @A7um, @KasperBuilds, @cipher-creator, @antigone4224, @JebeenLee, @senti-man, @Rorasaurus, @Alpastx, @code-and-covfefe, @riyandhiman14, @0xDvc-RE, @rodrigoarrelaro, @owen050724, @cy3erm, @Sn1r, @chndlrx, @moizxsec, @anthonyk2923, @isazajuancarlos","sidebar":"docs"},"security/cves/GHSA-jpx7-5hcf-w9xp":{"id":"security/cves/GHSA-jpx7-5hcf-w9xp","title":"GHSA-jpx7-5hcf-w9xp","description":"Reported by @szybnev, @Su1ph3r, @bl4cksku11, @XlabAITeam, @arthurscchan, @DavidKorczynski, @AdamKorcz","sidebar":"docs"},"security/cves/GHSA-m9h4-7j9c-55x9":{"id":"security/cves/GHSA-m9h4-7j9c-55x9","title":"GHSA-m9h4-7j9c-55x9","description":"Reported by @0xWerz, @szybnev, @Santoshkumarpuppala, @gigioneggiando","sidebar":"docs"},"security/cves/GHSA-qgqp-xh8r-v73r":{"id":"security/cves/GHSA-qgqp-xh8r-v73r","title":"GHSA-qgqp-xh8r-v73r","description":"Reported by @CallumBasham, @MattWidz","sidebar":"docs"},"security/policy":{"id":"security/policy","title":"Security Policy","description":"","sidebar":"docs"},"security/security-hardening":{"id":"security/security-hardening","title":"Hardening authentik","description":"authentik is secure by default, but you can tighten it further. Most of the changes below cost something in convenience. Apply the ones that match your threat model rather than all of them at once.","sidebar":"docs"},"sys-mgmt/akql":{"id":"sys-mgmt/akql","title":"AKQL search syntax","description":"Use AKQL to filter events, users, groups, and event matcher policies.","sidebar":"docs"},"sys-mgmt/background-tasks":{"id":"sys-mgmt/background-tasks","title":"Background tasks","description":"authentik uses background tasks to run various operations independently and asynchronously, separated from the continuous web requests processed for general user interaction. These background tasks are run by the worker.","sidebar":"docs"},"sys-mgmt/certificates":{"id":"sys-mgmt/certificates","title":"Certificates","description":"Certificates in authentik are used for:","sidebar":"docs"},"sys-mgmt/data-exports":{"id":"sys-mgmt/data-exports","title":"Data Exports","description":"authentik enterprise allows you to export user and event data in CSV format for backup or analysis purposes.","sidebar":"docs"},"sys-mgmt/events/event-actions":{"id":"sys-mgmt/events/event-actions","title":"Event actions","description":"Whenever any of the following actions occur, an event is created. Actions are used to define Notification Rules.","sidebar":"docs"},"sys-mgmt/events/index":{"id":"sys-mgmt/events/index","title":"Events","description":"Events are authentik\'s built-in logging system. Every event is logged, whether it is initiated by a user or by authentik.","sidebar":"docs"},"sys-mgmt/events/log-forwarding":{"id":"sys-mgmt/events/log-forwarding","title":"Log forwarding","description":"authentik records system, user, and admin activity as events. You can keep those events in authentik for investigation and audit workflows, or forward them to another system when you need longer retention, centralized search, alerting, or correlation with infrastructure and application logs.","sidebar":"docs"},"sys-mgmt/events/logging-events":{"id":"sys-mgmt/events/logging-events","title":"Logging events","description":"Logs are a vital tool for system diagnostics, event auditing, user management, reporting, and more. They capture detailed information about each event including the client\'s IP address, the user involved, the date and time, and the specific action taken.","sidebar":"docs"},"sys-mgmt/events/notification_rule_expression_policies":{"id":"sys-mgmt/events/notification_rule_expression_policies","title":"Notification Rule Expression Policies","description":"Notification rules with bound expression policies can match event context, update related objects, and send custom messages. The following examples show common event-driven automation patterns.","sidebar":"docs"},"sys-mgmt/events/notifications":{"id":"sys-mgmt/events/notifications","title":"Notification Rules","de
1scription":"To prevent notification loops, events created by policies that are attached to any notification rule do not trigger notifications.","sidebar":"docs"},"sys-mgmt/events/transports":{"id":"sys-mgmt/events/transports","title":"Notification Transports","description":"To receive notifications about events, first create a notification transport, and then define a notification rule with a bound policy. For more information, see the workflow overview.","sidebar":"docs"},"sys-mgmt/object-attributes":{"id":"sys-mgmt/object-attributes","title":"Object attributes","description":"Define reusable object attribute fields for authentik objects","sidebar":"docs"},"sys-mgmt/object-lifecycle-management":{"id":"sys-mgmt/object-lifecycle-management","title":"Object Lifecycle Management","description":"Configure authentik to auto-schedule and track periodic reviews of authentication settings for groups, roles, and applications.","sidebar":"docs"},"sys-mgmt/ops/autoscaling/hpa":{"id":"sys-mgmt/ops/autoscaling/hpa","title":"Autoscaling with the Helm chart HPA","description":"The authentik Helm chart can create a Horizontal Pod Autoscaler (HPA) for either the server or worker Deployment. This guide configures server scaling based on average CPU utilization. For queue-based worker scaling, see KEDA.","sidebar":"docs"},"sys-mgmt/ops/autoscaling/index":{"id":"sys-mgmt/ops/autoscaling/index","title":"Autoscaling on Kubernetes","description":"On Kubernetes, you can automatically adjust the number of authentik server and worker replicas independently:","sidebar":"docs"},"sys-mgmt/ops/autoscaling/keda":{"id":"sys-mgmt/ops/autoscaling/keda","title":"Autoscaling with KEDA","description":"KEDA can scale authentik servers on CPU usage and workers on queued tasks.","sidebar":"docs"},"sys-mgmt/ops/backup-restore":{"id":"sys-mgmt/ops/backup-restore","title":"Backup and restore your authentik instance","description":"This guide outlines the critical components to back up and restore in authentik.","sidebar":"docs"},"sys-mgmt/ops/geoip":{"id":"sys-mgmt/ops/geoip","title":"GeoIP","description":"authentik supports GeoIP to add additional information to login/authorization/enrollment requests. Additionally, a GeoIP Policy can be used to make policy decisions based on the lookup result.","sidebar":"docs"},"sys-mgmt/ops/monitoring":{"id":"sys-mgmt/ops/monitoring","title":"Monitoring","description":"authentik can be easily monitored in multiple ways.","sidebar":"docs"},"sys-mgmt/ops/storage-s3/index":{"id":"sys-mgmt/ops/storage-s3/index","title":"S3-compatible storage","description":"authentik can store uploaded files in Amazon S3 or an S3-compatible object storage service instead of storing them on the local filesystem in /data.","sidebar":"docs"},"sys-mgmt/ops/storage-s3/providers":{"id":"sys-mgmt/ops/storage-s3/providers","title":"S3-compatible storage providers","description":"Configure the shared settings in S3-compatible storage, then use the section for your storage service to set its endpoint and authentication options.","sidebar":"docs"},"sys-mgmt/ops/worker":{"id":"sys-mgmt/ops/worker","title":"Worker","description":"The authentik worker runs background tasks. The worker also watches for blueprints and certificates that are added to the file system. It runs in a separate container from the server to handle these tasks.","sidebar":"docs"},"sys-mgmt/settings":{"id":"sys-mgmt/settings","title":"System settings","description":"System settings control system-wide behavior. They can be changed through the authentik Admin interface or API.","sidebar":"docs"},"sys-mgmt/tenancy":{"id":"sys-mgmt/tenancy","title":"Tenancy","description":"This feature is in alpha. Use at your own risk.","sidebar":"docs"},"sys-mgmt/user-offboarding":{"id":"sys-mgmt/user-offboarding","title":"User offboarding","description":"Schedule the deactivation or deletion of a user, with optional session and token revocation.","sidebar":"docs"},"troubleshooting/access":{"id":"troubleshooting/access","title":"I can\'t access an application","description":"If your user is a superuser, or has the attribute goauthentik.io/user/debug set to true (can also be set on a group level):","sidebar":"docs"},"troubleshooting/csrf":{"id":"troubleshooting/csrf","title":"Troubleshooting CSRF Errors","description":"With some proxy setups, you might run into CSRF errors when attempting to create/save objects in authentik. This is usually caused by either the Origin or Host header being incorrect.","sidebar":"docs"},"troubleshooting/emails":{"id":"troubleshooting/emails","title":"Troubleshooting Email sending","description":"Some hosting providers block outgoing SMTP ports, in which case you\'ll have to host an SMTP relay on a different port with a different provider.","sidebar":"docs"},"troubleshooting/forward_auth":{"id":"troubleshooting/forward_auth","title":"Troubleshooting Forward auth","description":"Steps to help debug forward auth setups with various reverse proxies","sidebar":"docs"},"troubleshooting/image_upload":{"id":"troubleshooting/image_upload","title":"Errors when uploading icons","description":"There are two common causes for icon and image upload problems when authentik uses local file storage.","sidebar":"docs"},"troubleshooting/ldap_source":{"id":"troubleshooting/ldap_source","title":"Troubleshooting LDAP Synchronization","description":"To troubleshoot LDAP sources, you can run the command below to run a synchronization in the foreground and see any errors or warnings that might happen directly","sidebar":"docs"},"troubleshooting/login":{"id":"troubleshooting/login","title":"I can\'t log in to authentik","description":"In case you can\'t log in anymore, perhaps due to an incorrectly configured stage or a failed flow import, you can create a recovery key.","sidebar":"docs"},"troubleshooting/logs/logs":{"id":"troubleshooting/logs/logs","title":"Capturing authentik logs","de
1scription":"When troubleshooting issues in authentik, reviewing the logs can be invaluable. These logs provide continuous output, helping to diagnose problems effectively.","sidebar":"docs"},"troubleshooting/logs/outpost_logs":{"id":"troubleshooting/logs/outpost_logs","title":"Capturing outpost logs","description":"This guide only applies to standalone outposts, the embedded outpost outputs to the same place as the server, refer to Capturing authentik logs for more information.","sidebar":"docs"},"troubleshooting/missing_admin_group":{"id":"troubleshooting/missing_admin_group","title":"Missing admin group","description":"If all of the Admin groups have been deleted, or misconfigured during sync, you can use the following command to gain access back.","sidebar":"docs"},"troubleshooting/missing_permission":{"id":"troubleshooting/missing_permission","title":"Missing Permissions system_exception events","description":"This error can occur during initial setup, when authentik bootstraps the embedded Outpost, while the database migrations are not finished yet.","sidebar":"docs"},"troubleshooting/postgres/slow-queries":{"id":"troubleshooting/postgres/slow-queries","title":"Troubleshoot slow PostgreSQL queries","description":"If authentik requests become slow, especially after a PostgreSQL upgrade or a large change to the database, PostgreSQL might be planning queries with outdated table statistics. Queries that join many tables can be especially sensitive to poor row estimates. PostgreSQL\'s just-in-time (JIT) compilation can add substantial latency when it spends more time compiling a query than executing it.","sidebar":"docs"},"troubleshooting/postgres/upgrade_docker":{"id":"troubleshooting/postgres/upgrade_docker","title":"Upgrade PostgreSQL on Docker Compose","description":"This guide describes a manual PostgreSQL major-version upgrade for the default authentik Docker Compose deployment.","sidebar":"docs"},"troubleshooting/postgres/upgrade_kubernetes":{"id":"troubleshooting/postgres/upgrade_kubernetes","title":"Upgrading PostgreSQL on Kubernetes","description":"This guide walks through a manual PostgreSQL major-version upgrade for an authentik Kubernetes deployment. The process requires downtime while the database is exported, recreated, and restored.","sidebar":"docs"},"users-sources/access-control/index":{"id":"users-sources/access-control/index","title":"Access control","description":"To comply with important regulations such as PCI-DSS, HIPAA, SOC 2, and GDPR, it\'s necessary to have the ability to control which users have access to specific areas of the system, what permissions they have globally and on certain objects, and a way to monitor events related to user activity.","sidebar":"docs"},"users-sources/access-control/initial_permissions":{"id":"users-sources/access-control/initial_permissions","title":"Initial permissions","description":"Set permissions for object creation.","sidebar":"docs"},"users-sources/access-control/manage_permissions":{"id":"users-sources/access-control/manage_permissions","title":"Manage permissions","description":"Learn how to use global and object permissions in authentik.","sidebar":"docs"},"users-sources/access-control/permissions":{"id":"users-sources/access-control/permissions","title":"About permissions","description":"Learn about global and object permissions in authentik.","sidebar":"docs"},"users-sources/groups/group_ref":{"id":"users-sources/groups/group_ref","title":"Group properties and attributes","description":"Object properties","sidebar":"docs"},"users-sources/groups/index":{"id":"users-sources/groups/index","title":"Groups","description":"Learn about groups in authentik","sidebar":"docs"},"users-sources/groups/manage_groups":{"id":"users-sources/groups/manage_groups","title":"Manage groups","description":"Learn how to work with groups in authentik.","sidebar":"docs"},"users-sources/roles/index":{"id":"users-sources/roles/index","title":"Roles","description":"Roles are a way to simplify the assignment of permissions. Roles are also the backbone of role-based access control (RBAC), an industry standard for managing access control. In authentik, RBAC is how you manage access to system components and specific objects such as flows, stages, users, etc.","sidebar":"docs"},"users-sources/roles/manage_roles":{"id":"users-sources/roles/manage_roles","title":"Manage roles","description":"Learn how to work with roles and permissions in authentik.","sidebar":"docs"},"users-sources/sources/directory-sync/active-directory/index":{"id":"users-sources/sources/directory-sync/active-directory/index","title":"Active Directory","de
1scription":"Preparation","sidebar":"docs"},"users-sources/sources/directory-sync/freeipa/index":{"id":"users-sources/sources/directory-sync/freeipa/index","title":"FreeIPA","description":"Preparation","sidebar":"docs"},"users-sources/sources/index":{"id":"users-sources/sources/index","title":"Sources","description":"Sources allow you to connect authentik to an external user directory. Sources can also be used with social login providers such as Facebook, X, or GitHub.","sidebar":"docs"},"users-sources/sources/property-mappings/expressions":{"id":"users-sources/sources/property-mappings/expressions","title":"Sources expression property mappings","description":"The property mapping should return a value that is expected by the source. Returning None is always accepted and skips the mapping that returned None.","sidebar":"docs"},"users-sources/sources/property-mappings/index":{"id":"users-sources/sources/property-mappings/index","title":"Source property mappings","description":"Source property mappings allow you to modify or gather extra information from sources.","sidebar":"docs"},"users-sources/sources/protocols/kerberos/browser":{"id":"users-sources/sources/protocols/kerberos/browser","title":"Browser configuration for SPNEGO","description":"You might need to configure your web browser to allow SPNEGO. Following are the instructions for major browsers.","sidebar":"docs"},"users-sources/sources/protocols/kerberos/index":{"id":"users-sources/sources/protocols/kerberos/index","title":"Kerberos","description":"This source allows users to enroll themselves with an existing Kerberos identity.","sidebar":"docs"},"users-sources/sources/protocols/ldap/index":{"id":"users-sources/sources/protocols/ldap/index","title":"LDAP source","description":"Sources allow you to connect authentik to an existing user directory. This source allows you to import users and groups from an LDAP server.","sidebar":"docs"},"users-sources/sources/protocols/oauth/index":{"id":"users-sources/sources/protocols/oauth/index","title":"OAuth source","description":"This source allows users to enroll themselves with an external OAuth-based i
1dentity provider. The generic provider expects the endpoint to return OpenID Connect-compatible information. Vendor-specific implementations have their own OAuth source.","sidebar":"docs"},"users-sources/sources/protocols/saml/index":{"id":"users-sources/sources/protocols/saml/index","title":"SAML source","description":"This source allows authentik to act as a SAML service provider. Like the SAML provider, it supports signed requests. Vendor-specific documentation is available in the integrations section.","sidebar":"docs"},"users-sources/sources/protocols/scim/index":{"id":"users-sources/sources/protocols/scim/index","title":"SCIM source","description":"The SCIM source allows other applications to directly create users and groups within authentik. SCIM provides a predefined schema for users and groups, along with a RESTful API, to enable automatic user provisioning and deprovisioning. SCIM is supported by applications such as Microsoft Entra ID, Google Workspace, and Okta.","sidebar":"docs"},"users-sources/sources/social-logins/apple/index":{"id":"users-sources/sources/social-logins/apple/index","title":"Log in with Apple","description":"This source lets users authenticate with their Apple ID credentials by configuring Apple as a federated identity provider with OAuth 2.0.","sidebar":"docs"},"users-sources/sources/social-logins/cas/index":{"id":"users-sources/sources/social-logins/cas/index","title":"Log in with Apereo CAS","description":"Integrate Apereo CAS as a source in authentik","sidebar":"docs"},"users-sources/sources/social-logins/discord/index":{"id":"users-sources/sources/social-logins/discord/index","title":"Log in with Discord","description":"This source lets users authenticate with their Discord credentials by configuring Discord as a federated identity provider with OAuth 2.0.","sidebar":"docs"},"users-sources/sources/social-logins/entra-id/index":{"id":"users-sources/sources/social-logins/entra-id/index","title":"Log in with Entra ID","description":"There are several ways that Entra ID can be integrated with authentik to allow for user and group provisioning and authentication with Entra ID user credentials. If you are instead looking to authenticate to Entra ID with authentik credentials, refer to our Microsoft 365 SAML or Microsoft 365 WS-Federation integrations guides.","sidebar":"docs"},"users-sources/sources/social-logins/entra-id/oauth/index":{"id":"users-sources/sources/social-logins/entra-id/oauth/index","title":"Entra ID OAuth authentication","description":"Authenticating to authentik with Entra ID credentials via the OAuth 2.0 protocol","sidebar":"docs"},"users-sources/sources/social-logins/entra-id/scim/index":{"id":"users-sources/sources/social-logins/entra-id/scim/index","title":"Entra ID SCIM user and group provisioning","description":"Provisioning users and groups from Entra ID to authentik via the SCIM protocol","sidebar":"docs"},"users-sources/sources/social-logins/facebook/index":{"id":"users-sources/sources/social-logins/facebook/index","title":"Log in with Facebook","description":"This source lets users authenticate with their Facebook credentials by configuring Facebook as a federated identity provider with OAuth 2.0.","sidebar":"docs"},"users-sources/sources/social-logins/github/index":{"id":"users-sources/sources/social-logins/github/index","title":"Log in with GitHub","description":"This source lets users authenticate with their GitHub credentials by configuring GitHub as a federated identity provider with OAuth 2.0.","sidebar":"docs"},"users-sources/sources/social-logins/gitlab/index":{"id":"users-sources/sources/social-logins/gitlab/index","title":"Log in with GitLab","description":"This source lets users authenticate with their GitLab credentials by configuring GitLab as a federated identity provider with OAuth 2.0.","sidebar":"docs"},"users-sources/sources/social-logins/google/cloud/index":{"id":"users-sources/sources/social-logins/google/cloud/index","title":"Google Cloud (with OAuth)","description":"This source lets users authenticate with their Google credentials by configuring Google Cloud as a federated identity provider with OAuth 2.0.","sidebar":"docs"},"users-sources/sources/social-logins/google/index":{"id":"users-sources/sources/social-logins/google/index","title":"Google identity providers","description":"There are several ways that Google services can be integrated
1with authentik to allow for authentication with Google user credentials.","sidebar":"docs"},"users-sources/sources/social-logins/google/workspace/index":{"id":"users-sources/sources/social-logins/google/workspace/index","title":"Google Workspace (with SAML)","description":"This source lets users authenticate with their Google Workspace credentials by configuring Google Workspace as a federated identity provider with SAML.","sidebar":"docs"},"users-sources/sources/social-logins/index":{"id":"users-sources/sources/social-logins/index","title":"Federated identity providers","description":"Configuring authentik with a federated identity provider allows users to authenticate with their existing credentials, such as social logins or enterprise identity providers.","sidebar":"docs"},"users-sources/sources/social-logins/jumpcloud/index":{"id":"users-sources/sources/social-logins/jumpcloud/index","title":"Log in with JumpCloud","description":"Integrate JumpCloud as a source in authentik","sidebar":"docs"},"users-sources/sources/social-logins/keycloak/index":{"id":"users-sources/sources/social-logins/keycloak/index","title":"Log in with Keycloak","description":"This source lets users authenticate with their Keycloak credentials by configuring Keycloak as a federated identity provider with SAML.","sidebar":"docs"},"users-sources/sources/social-logins/mailcow/index":{"id":"users-sources/sources/social-logins/mailcow/index","title":"Log in with Mailcow","description":"This source lets users authenticate with their Mailcow credentials by configuring Mailcow as a federated identity provider with OAuth 2.0.","sidebar":"docs"},"users-sources/sources/social-logins/okta/index":{"id":"users-sources/sources/social-logins/okta/index","title":"Log in with Okta","description":"Integrate Okta as a source in authentik","sidebar":"docs"},"users-sources/sources/social-logins/plex/index":{"id":"users-sources/sources/social-logins/plex/index","title":"Log in with Plex","description":"This source lets users authenticate with their Plex credentials by configuring Plex as a federated identity provider.","sidebar":"docs"},"users-sources/sources/social-logins/shibboleth/index":{"id":"users-sources/sources/social-logins/shibboleth/index","title":"Log in with Shibboleth","description":"This source lets users authenticate with their Shibboleth credentials by configuring Shibboleth as a federated identity provider with SAML.","sidebar":"docs"},"users-sources/sources/social-logins/telegram/index":{"id":"users-sources/sources/social-logins/telegram/index","title":"Log in with Telegram","description":"This source lets users authenticate with their Telegram account credentials.","sidebar":"docs"},"users-sources/sources/social-logins/twitch/index":{"id":"users-sources/sources/social-logins/twitch/index","title":"Log in with Twitch","description":"This source lets users authenticate with their Twitch credentials by configuring Twitch as a federated identity provider with OAuth 2.0.","sidebar":"docs"},"users-sources/sources/social-logins/twitter/index":{"id":"users-sources/sources/social-logins/twitter/index","title":"Log in with X (formerly Twitter)","description":"This source lets users authenticate with their X credentials by configuring X as a federated identity provider with OAuth 2.0.","sidebar":"docs"},"users-sources/sources/social-logins/wechat/index":{"id":"users-sources/sources/social-logins/wechat/index","title":"Log in with WeChat","description":"This source lets users authenticate with their WeChat credentials by configuring WeChat as a federated identity provider with OAuth 2.0.","sidebar":"docs"},"users-sources/user/account-types/agent-accounts":{"id":"users-sources/user/account-types/agent-accounts","title":"Agent accounts","description":"Agent accounts are service accounts that act on behalf of a parent user when calling the authentik API. Use them for automation, integrations, and other machine identities that need delegated access.","sidebar":"docs"},"users-sources/user/account-types/external-users":{"id":"users-sources/user/account-types/external-users","title":"External users","description":"External users are accounts for people who need access to an application but not to the authentik application dashboard.","sidebar":"docs"},"users-sources/user/account-types/index":{"id":"users-sources/user/account-types/index","title":"Account types","description":"Choose between internal users, external users, service accounts, and agent accounts.","sidebar":"docs"},"users-sources/user/account-types/internal-users":{"id":"users-sources/user/account-types/internal-users","title":"Internal users","description":"Internal users are accounts for people who need the authentik application dashboard and their own user settings.","sidebar":"docs"},"users-sources/user/account-types/service-accounts":{"id":"users-sources/user/account-types/service-accounts","title":"Service accounts","description":"Service accounts are specialized user accounts for machine-to-machine authentication and automation. Use them when an external service, script, integration, or protocol client needs to authenticate to authentik without representing a human user.","sidebar":"docs"},"users-sources/user/index":{"id":"users-sources/user/index","title":"About users","description":"In authentik you can create and manage users with fine-tuned access control, session and event details, group membership, role assignment, super-user rights, impersonation, and password management and recovery.","sidebar":"docs"},"users-sources/user/invitations":{"id":"users-sources/user/invitations","title":"Invitations","description":"Learn how to create an invitation URL for new users to enroll.","sidebar":"docs"},"users-sources/user/password_reset_on_login":{"id":"users-sources/user/password_reset_on_login","title":"Force password reset on next login","description":"You can require users to reset the
1ir password on their next login, using expression policies, custom stages, and a custom user attribute. This guide explains how to configure this with the default-authentication-flow; however, the same steps apply to any authentication flow.","sidebar":"docs"},"users-sources/user/user_basic_operations":{"id":"users-sources/user/user_basic_operations","title":"Manage users","description":"Use these procedures to create, modify, deactivate, delete, and recover users.","sidebar":"docs"},"users-sources/user/user_ref":{"id":"users-sources/user/user_ref","title":"User properties and attributes","description":"Object properties","sidebar":"docs"},"users-sources/user/user-interface":{"id":"users-sources/user/user-interface","title":"User interface","description":"End-users who are accessing their applications via authentik typically only access the User interface, not the Admin interface. (There are exceptions; some end-users have permissions to also access the Admin interface, while some end-users never go to the User interface, but rather log directly into their application using authentik behind the scenes.)","sidebar":"docs"},"users-sources/user/user-switching":{"id":"users-sources/user/user-switching","title":"User account switching","description":"authentik can keep multiple user accounts signed in within the same browser. Users can switch between their user accounts from the User interface header.","sidebar":"docs"}}}}')}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.