Alternatives to Authelia
Self-hosted single sign-on and two-factor portal for reverse proxies. The listings below can replace it for an important use case. Each note says what changes if you switch.
The original
Authelia
Self-hosted single sign-on and two-factor portal for reverse proxies.
Replacements
Listings that take over the same core job as Authelia.
authentik
Self-hosted identity provider for single sign-on and application access control.
authentik is a full identity provider covering SAML, OAuth2/OIDC, LDAP and RADIUS with a flow builder, though some organisation-scale features sit in a paid enterprise edition.
Pomerium
An identity-aware reverse proxy that gives secure access to internal applications without a VPN.
Pomerium is an identity-aware reverse proxy with policy as code in YAML and audit logging, but it requires an existing OIDC identity provider and has paid features.
Keycloak
A self-hosted identity and access management server that adds single sign-on and login to applications.
Keycloak is a self-hosted identity server with OpenID Connect, SAML 2.0 and LDAP or Active Directory support, and takes real administrative effort to set up and secure.
Zitadel
An open-source identity and access management platform with SSO, MFA and a hosted login page.
Zitadel provides self-hostable SSO with built-in MFA, passwordless and social login plus SDKs, and is aimed at developers integrating identity into applications, with a freemium model.
Pocket ID
Small OpenID Connect provider that signs users in with passkeys only.
Pocket ID is a small OpenID Connect provider that signs users in with passkeys only, simpler to run but without LDAP, SAML or password fallback.
Casdoor
A self-hosted identity and access management server with single sign-on, MFA and a web interface.
Casdoor is a self-hosted identity server supporting OAuth, OIDC, SAML, CAS, LDAP and SCIM with several MFA options and a web UI.
Similar software
Related functionality, not a direct replacement.
Fail2ban
Log-watching daemon that bans addresses after repeated authentication failures.
CrowdSec
Detect suspicious behavior in server logs and web traffic.
HashiCorp Vault
Secrets management with dynamic credentials, encryption and PKI.
privacyIDEA
Open-source, self-hosted multi-factor authentication server that manages OTP and other token types.