Authelia Fournisseur IAM
Authelia is a community-driven, open-source (Apache 2.0) 2FA and single sign-on authentication server. It is a forward-auth companion for reverse proxies (nginx, Traefik, Caddy, Envoy, HAProxy, Skipper), authenticating against a file or LDAP backend and issuing access-control decisions to protect self-hosted applications, with an optional built-in OpenID Certified OpenID Connect 1.0 Provider. There is no commercial edition or SaaS offering; the project is entirely community-maintained.
Fonctionnalités
Si vous souhaitez comparer les fonctionnalités IAM de différents fournisseurs, consultez le benchmark des fournisseurs d'identité (C)IAM.
Vous cherchez la compatibilité du protocole OpenID Connect de Authelia ? Voir Authelia sur le benchmark des fournisseurs OpenID Connect.
Foire aux questions
Authelia prend-il en charge Nom d'utilisateur et mot de passe méthode d'authentification ?
Authelia prend en charge Nom d'utilisateur et mot de passe méthode d'authentification. First-factor authentication against a file (YAML) or LDAP backend, with Argon2id (default) or SHA512 password hashing. En savoir plus
Authelia prend-il en charge Connexion sociale méthode d'authentification ?
Authelia ne prend pas en charge Connexion sociale méthode d'authentification. No built-in social/OAuth identity provider login; Authelia is itself an identity provider, not a relying party.
Authelia prend-il en charge Passkey méthode d'authentification ?
Authelia prend en charge Passkey méthode d'authentification. Passwordless logins via Passkeys, supported since v4.39.0, in addition to multi-credential WebAuthn security keys. En savoir plus
Authelia prend-il en charge Email Passwordless méthode d'authentification ?
Authelia ne prend pas en charge Email Passwordless méthode d'authentification. No email-OTP/magic-link passwordless first factor; password reset and identity verification use emailed links, not authentication itself.
Authelia prend-il en charge Phone Passwordless méthode d'authentification ?
Authelia ne prend pas en charge Phone Passwordless méthode d'authentification.
Authelia prend-il en charge Magic Link méthode d'authentification ?
Authelia ne prend pas en charge Magic Link méthode d'authentification.
Authelia prend-il en charge Anonymous / Guest méthode d'authentification ?
Authelia ne prend pas en charge Anonymous / Guest méthode d'authentification. Access control supports a bypass policy for unauthenticated routing, but there is no anonymous/guest user session concept.
Authelia prend-il en charge Time-based One-Time Password (TOTP) MFA ?
Authelia prend en charge Time-based One-Time Password (TOTP) MFA. En savoir plus
Authelia prend-il en charge HMAC-based One-Time Password (HOTP) MFA ?
Authelia ne prend pas en charge HMAC-based One-Time Password (HOTP) MFA. Only TOTP is supported for one-time password second factor; HOTP is not documented.
Authelia prend-il en charge Universal 2nd Factor (U2F) MFA ?
Authelia prend partiellement en charge Universal 2nd Factor (U2F) MFA. Legacy FIDO U2F is superseded by FIDO2/WebAuthn security key support. En savoir plus
Authelia prend-il en charge WebAuthn MFA ?
Authelia prend en charge WebAuthn MFA. FIDO2/WebAuthn hardware security keys (e.g. YubiKey), with multiple credential registration since v4.38.0. En savoir plus
Authelia prend-il en charge Email Code MFA ?
Authelia ne prend pas en charge Email Code MFA.
Authelia prend-il en charge Phone Code MFA ?
Authelia ne prend pas en charge Phone Code MFA.
Authelia prend-il en charge Push Notification MFA ?
Authelia prend en charge Push Notification MFA. Duo Push mobile app second factor, via the third-party Duo API. En savoir plus
Authelia prend-il en charge Cisco Duo MFA ?
Authelia prend en charge Cisco Duo MFA. En savoir plus
Authelia prend-il en charge Step-Up Authentication MFA ?
Authelia ne prend pas en charge Step-Up Authentication MFA. OAuth 2.0 Step-up Authentication Challenge is listed as unsupported in the OIDC support chart, though access control policies can require two_factor per route/domain. En savoir plus
Authelia prend-il en charge OpenID Connect (OIDC) protocole d'intégration ?
Authelia prend en charge OpenID Connect (OIDC) protocole d'intégration. OpenID Certified OpenID Connect 1.0 Provider. En savoir plus
Authelia prend-il en charge SAML 2.0 protocole d'intégration ?
Authelia ne prend pas en charge SAML 2.0 protocole d'intégration. SAML 2.0 Profile for OAuth 2.0 is listed as unsupported; Authelia does not implement a SAML IdP. En savoir plus
Authelia prend-il en charge WS-Federation protocole d'intégration ?
Authelia ne prend pas en charge WS-Federation protocole d'intégration.
Authelia prend-il en charge Machine-to-Machine (M2M) Authentication protocole d'intégration ?
Authelia prend en charge Machine-to-Machine (M2M) Authentication protocole d'intégration. OAuth 2.0 client_credentials grant for statically configured confidential clients. En savoir plus
Authelia prend-il en charge OpenID Connect (OIDC) Federation fédération d'identité ?
Authelia ne prend pas en charge OpenID Connect (OIDC) Federation fédération d'identité. Authelia is an OIDC Provider only; it does not act as a relying party federating to upstream OIDC IdPs.
Authelia prend-il en charge SAML 2.0 Federation fédération d'identité ?
Authelia ne prend pas en charge SAML 2.0 Federation fédération d'identité.
Authelia prend-il en charge Active Directory / LDAP fédération d'identité ?
Authelia prend en charge Active Directory / LDAP fédération d'identité. LDAP authentication backend, with tested implementations for Active Directory, OpenLDAP, LLDAP, FreeIPA, and others. En savoir plus
Authelia prend-il en charge Azure Active Directory (Entra ID) fédération d'identité ?
Authelia ne prend pas en charge Azure Active Directory (Entra ID) fédération d'identité. Not documented; LDAP integration targets Active Directory/LDAP servers directly, not Azure AD/Entra ID over OIDC/SAML federation.
Authelia prend-il en charge Bulk User Import gestion des utilisateurs ?
Authelia ne prend pas en charge Bulk User Import gestion des utilisateurs. The file backend is manually edited YAML with no bulk import tool; the LDAP backend is managed externally, and no SCIM API exists (open feature request). En savoir plus
Authelia prend-il en charge Bulk User Export gestion des utilisateurs ?
Authelia ne prend pas en charge Bulk User Export gestion des utilisateurs.
Authelia prend-il en charge Bulk User Update / Delete gestion des utilisateurs ?
Authelia ne prend pas en charge Bulk User Update / Delete gestion des utilisateurs.
Authelia prend-il en charge Upsert on Import gestion des utilisateurs ?
Authelia ne prend pas en charge Upsert on Import gestion des utilisateurs.
Authelia prend-il en charge MFA Enrollment Import gestion des utilisateurs ?
Authelia ne prend pas en charge MFA Enrollment Import gestion des utilisateurs.
Authelia prend-il en charge Inbound SCIM Provisioning gestion des utilisateurs ?
Authelia ne prend pas en charge Inbound SCIM Provisioning gestion des utilisateurs. SCIM 2.0 support is an open feature request, not implemented. En savoir plus
Authelia prend-il en charge Outbound SCIM Provisioning gestion des utilisateurs ?
Authelia ne prend pas en charge Outbound SCIM Provisioning gestion des utilisateurs.
Authelia prend-il en charge SCIM Groups Provisioning gestion des utilisateurs ?
Authelia ne prend pas en charge SCIM Groups Provisioning gestion des utilisateurs.
Authelia prend-il en charge Just-In-Time (JIT) User Provisioning gestion des utilisateurs ?
Authelia ne prend pas en charge Just-In-Time (JIT) User Provisioning gestion des utilisateurs. Users must already exist in the file or LDAP backend; Authelia does not create accounts on first login.
Authelia prend-il en charge Lazy / Trickle Migration from Legacy Database gestion des utilisateurs ?
Authelia ne prend pas en charge Lazy / Trickle Migration from Legacy Database gestion des utilisateurs.
Authelia prend-il en charge Self-Service Profile Management Portal gestion des utilisateurs ?
Authelia prend en charge Self-Service Profile Management Portal gestion des utilisateurs. Self-service password reset and WebAuthn/TOTP device registration, gated by emailed identity verification links. En savoir plus
Authelia prend-il en charge User Account Linking gestion des utilisateurs ?
Authelia ne prend pas en charge User Account Linking gestion des utilisateurs.
Authelia prend-il en charge User Blocking / Banning gestion des utilisateurs ?
Authelia prend partiellement en charge User Blocking / Banning gestion des utilisateurs. Regulation (brute-force ban) temporarily bans a user/IP after repeated failed attempts; there is no persistent admin-triggered account disable in the file/LDAP backends themselves. En savoir plus
Authelia prend-il en charge User Metadata gestion des utilisateurs ?
Authelia prend partiellement en charge User Metadata gestion des utilisateurs. The file backend supports standard attributes (email, display name, groups) but no arbitrary custom user metadata schema. En savoir plus
Authelia prend-il en charge Application Metadata gestion des utilisateurs ?
Authelia ne prend pas en charge Application Metadata gestion des utilisateurs.
Authelia prend-il en charge User Search gestion des utilisateurs ?
Authelia ne prend pas en charge User Search gestion des utilisateurs. No admin UI or API for searching users; management is via the backing file/LDAP store directly.
Authelia prend-il en charge Role-Based Access Control (RBAC) gestion des utilisateurs ?
Authelia prend partiellement en charge Role-Based Access Control (RBAC) gestion des utilisateurs. Access control rules match on user/group subjects, domains, resources, methods and networks to assign bypass/one_factor/two_factor/deny policies; this is policy-based rather than a formal role hierarchy. En savoir plus
Authelia prend-il en charge Organizations (Multi-Tenancy B2B) gestion des utilisateurs ?
Authelia ne prend pas en charge Organizations (Multi-Tenancy B2B) gestion des utilisateurs. No multi-organization/tenant model; each deployment is a single instance.
Authelia prend-il en charge Password Strength Policies gestion des utilisateurs ?
Authelia prend en charge Password Strength Policies gestion des utilisateurs. Standard policy (min length, character classes) or zxcvbn-based strength metering. En savoir plus
Authelia prend-il en charge Progressive Profiling / Forms gestion des utilisateurs ?
Authelia ne prend pas en charge Progressive Profiling / Forms gestion des utilisateurs.
Authelia prend-il en charge Attribute-Based Access Control (ABAC) contrôle d'accès ?
Authelia prend partiellement en charge Attribute-Based Access Control (ABAC) contrôle d'accès. Access control rules can condition policies on network/subject attributes, but there is no general-purpose attribute-based policy engine beyond the built-in rule matcher. En savoir plus
Authelia prend-il en charge Fine-Grained Authorization (FGA / ReBAC) contrôle d'accès ?
Authelia prend en charge Fine-Grained Authorization (FGA / ReBAC) contrôle d'accès. Per-domain, per-resource-path, per-method, per-network access control rules with bypass/one_factor/two_factor/deny policies. En savoir plus
Authelia prend-il en charge API Authorization (Scopes / Permissions) contrôle d'accès ?
Authelia prend en charge API Authorization (Scopes / Permissions) contrôle d'accès. Forward-auth gate for reverse-proxied APIs, plus OAuth 2.0 scopes/audience for OIDC-protected APIs. En savoir plus
Authelia prend-il en charge Audit Log Retention fonctionnalité de sécurité ?
Authelia prend en charge Audit Log Retention fonctionnalité de sécurité. Structured logs of authentication and authorization events; retention is operator-configured. En savoir plus
Authelia prend-il en charge Audit Log Streaming fonctionnalité de sécurité ?
Authelia prend partiellement en charge Audit Log Streaming fonctionnalité de sécurité. Logs can be written to file or stdout for collection by external log shippers/SIEM; no native streaming integration. En savoir plus
Authelia prend-il en charge Security Center (Threat Monitoring Dashboard) fonctionnalité de sécurité ?
Authelia ne prend pas en charge Security Center (Threat Monitoring Dashboard) fonctionnalité de sécurité.
Authelia prend-il en charge Encryption at Rest fonctionnalité de sécurité ?
Authelia prend en charge Encryption at Rest fonctionnalité de sécurité. Sensitive fields (TOTP secrets, WebAuthn keys, OIDC session data) are encrypted in the storage backend using a configured HMAC/encryption secret. En savoir plus
Authelia prend-il en charge Encryption in Transit fonctionnalité de sécurité ?
Authelia prend en charge Encryption in Transit fonctionnalité de sécurité. TLS for the web portal and SMTP notifier, with certificate validation. En savoir plus
Authelia prend-il en charge Customer Managed Keys (BYOK) fonctionnalité de sécurité ?
Authelia prend en charge Customer Managed Keys (BYOK) fonctionnalité de sécurité. Full key/secret management control via self-hosted deployment, including OIDC JWKS signing keys. En savoir plus
Authelia prend-il en charge Bot Detection fonctionnalité de sécurité ?
Authelia ne prend pas en charge Bot Detection fonctionnalité de sécurité.
Authelia prend-il en charge Brute Force Protection fonctionnalité de sécurité ?
Authelia prend en charge Brute Force Protection fonctionnalité de sécurité. Regulation module bans a user after a configurable number of failed attempts within a time window, plus adaptive minimum-delay authentication timing to resist username enumeration. En savoir plus
Authelia prend-il en charge Suspicious IP Throttling fonctionnalité de sécurité ?
Authelia prend en charge Suspicious IP Throttling fonctionnalité de sécurité. Token-bucket rate limiters on authentication-sensitive endpoints, configurable per use case. En savoir plus
Authelia prend-il en charge Breached Password Detection fonctionnalité de sécurité ?
Authelia ne prend pas en charge Breached Password Detection fonctionnalité de sécurité. Not documented; password policy covers strength (standard rules or zxcvbn), not breach-corpus checks.
Authelia prend-il en charge Tenant Access Control List (IP ACL) fonctionnalité de sécurité ?
Authelia ne prend pas en charge Tenant Access Control List (IP ACL) fonctionnalité de sécurité.
Authelia prend-il en charge Per-Organization Branding multi-tenant ?
Authelia ne prend pas en charge Per-Organization Branding multi-tenant. Single-instance deployment; no multi-organization branding model.
Authelia prend-il en charge Per-Organization MFA Policy multi-tenant ?
Authelia prend partiellement en charge Per-Organization MFA Policy multi-tenant. Second-factor requirements are set per access-control rule (domain/resource/network), not per organization. En savoir plus
Authelia prend-il en charge Hosted / Universal Login Page fonctionnalité de branding ?
Authelia prend en charge Hosted / Universal Login Page fonctionnalité de branding. En savoir plus
Authelia prend-il en charge Embedded / Native Login Components fonctionnalité de branding ?
Authelia ne prend pas en charge Embedded / Native Login Components fonctionnalité de branding. Authentication happens on Authelia's own portal; no embeddable widget/SDK-driven inline login.
Authelia prend-il en charge White-Label / Full Brand Removal fonctionnalité de branding ?
Authelia prend partiellement en charge White-Label / Full Brand Removal fonctionnalité de branding. Built-in light/dark/auto themes and a configurable logo; full CSS/branding overrides require disabling the default Content-Security-Policy, which the docs discourage. En savoir plus
Authelia prend-il en charge Localization / i18n fonctionnalité de branding ?
Authelia prend en charge Localization / i18n fonctionnalité de branding. The portal UI is translated into numerous community-contributed languages. En savoir plus
Authelia prend-il en charge Prebuilt UI Components (SDK) fonctionnalité de branding ?
Authelia ne prend pas en charge Prebuilt UI Components (SDK) fonctionnalité de branding.
Authelia prend-il en charge Login / Auth Analytics Dashboard analytique ?
Authelia ne prend pas en charge Login / Auth Analytics Dashboard analytique. No built-in analytics dashboard; structured logs can feed external tooling.
Authelia prend-il en charge SOC 2 Type II Certification conformité ?
Authelia ne prend pas en charge SOC 2 Type II Certification conformité.
Authelia prend-il en charge ISO 27001 / 27017 / 27018 Certification conformité ?
Authelia ne prend pas en charge ISO 27001 / 27017 / 27018 Certification conformité.
Authelia prend-il en charge HIPAA Business Associate Agreement (BAA) conformité ?
Authelia ne prend pas en charge HIPAA Business Associate Agreement (BAA) conformité.
Authelia prend-il en charge PCI DSS Compliance conformité ?
Authelia ne prend pas en charge PCI DSS Compliance conformité.
Authelia prend-il en charge CSA STAR Certification conformité ?
Authelia ne prend pas en charge CSA STAR Certification conformité.
Authelia prend-il en charge FedRAMP Authorization conformité ?
Authelia ne prend pas en charge FedRAMP Authorization conformité.
Authelia prend-il en charge GDPR: Data Export (Portability) conformité ?
Authelia ne prend pas en charge GDPR: Data Export (Portability) conformité. No built-in data export tooling; self-hosted operators have direct access to the backing store.
Authelia prend-il en charge GDPR: Right to be Forgotten (User Deletion) conformité ?
Authelia ne prend pas en charge GDPR: Right to be Forgotten (User Deletion) conformité. No built-in account deletion API; erasure is a manual operation on the file/LDAP/database backend.
Authelia prend-il en charge Consent Management conformité ?
Authelia prend en charge Consent Management conformité. OpenID Connect consent screen (pre-configured or interactive) per client/scope. En savoir plus
Authelia prend-il en charge Region Deployment conformité ?
Authelia prend en charge Region Deployment conformité. Self-hosted in any region; no managed hosting offering exists. En savoir plus
Authelia prend-il en charge Private Cloud Deployment conformité ?
Authelia prend en charge Private Cloud Deployment conformité. Deployable via Docker, Kubernetes, or bare-metal binary, with SQLite/MySQL/PostgreSQL storage and Redis for HA session state. En savoir plus
Authelia prend-il en charge SDK Coverage intégration développeur ?
Authelia ne prend pas en charge SDK Coverage intégration développeur. No official client SDKs; integration is via standard OAuth 2.0/OIDC libraries or the forward-auth proxy contract.
Authelia prend-il en charge Management API intégration développeur ?
Authelia ne prend pas en charge Management API intégration développeur. No REST management API; configuration is file-based (YAML) with environment variable/secret overrides.
Authelia prend-il en charge Authentication API Rate Limits intégration développeur ?
Authelia prend en charge Authentication API Rate Limits intégration développeur. Configurable per-endpoint rate limiters for authentication-sensitive routes. En savoir plus
Authelia prend-il en charge Actions / Extensibility Pipeline intégration développeur ?
Authelia ne prend pas en charge Actions / Extensibility Pipeline intégration développeur. No scripting/custom-code extensibility hooks; behavior is driven entirely by declarative YAML configuration.
Authelia prend-il en charge TypeScript Support in Extensibility intégration développeur ?
Authelia ne prend pas en charge TypeScript Support in Extensibility intégration développeur.
Authelia prend-il en charge Custom Domain intégration développeur ?
Authelia prend en charge Custom Domain intégration développeur. Self-hosted on any domain, with multi-cookie-domain support for protecting multiple root domains from one instance. En savoir plus
Authelia prend-il en charge Deploy CLI (Infrastructure as Code) intégration développeur ?
Authelia prend en charge Deploy CLI (Infrastructure as Code) intégration développeur. authelia CLI binary and Docker/Kubernetes manifests for configuration validation and deployment; no interactive admin CLI beyond config management. En savoir plus
Authelia prend-il en charge Terraform Provider intégration développeur ?
Authelia ne prend pas en charge Terraform Provider intégration développeur. No official Authelia Terraform provider; configuration is plain YAML, which can be templated by generic Terraform file/template resources.
Authelia prend-il en charge Custom Database Connections intégration développeur ?
Authelia prend en charge Custom Database Connections intégration développeur. SQLite, MySQL/MariaDB, or PostgreSQL storage backends, plus Redis/Redis Sentinel for session/cache high availability. En savoir plus
Authelia prend-il en charge Native Webhook Support intégration développeur ?
Authelia ne prend pas en charge Native Webhook Support intégration développeur. Notification system modernization (webhook notifier) is an open feature request, not yet implemented. En savoir plus
Authelia prend-il en charge Universal Login / Hosted Login Page Customization intégration développeur ?
Authelia prend partiellement en charge Universal Login / Hosted Login Page Customization intégration développeur. Logo and theme are configurable; deeper HTML/CSS customization requires relaxing the built-in Content-Security-Policy. En savoir plus
Authelia prend-il en charge Custom Email Provider (SMTP) intégration développeur ?
Authelia prend en charge Custom Email Provider (SMTP) intégration développeur. SMTP notifier (with a filesystem notifier for testing only). En savoir plus
Authelia prend-il en charge Email Templates intégration développeur ?
Authelia prend en charge Email Templates intégration développeur. HTML and plaintext notification templates (password reset, WebAuthn/TOTP registration) are overridable per template_path. En savoir plus
Authelia prend-il en charge Custom OIDC Claims / Token Enrichment intégration développeur ?
Authelia prend en charge Custom OIDC Claims / Token Enrichment intégration développeur. Per-client claims_policy configuration maps custom scopes/claims onto ID tokens and userinfo responses. En savoir plus
Authelia prend-il en charge No-Code Auth Flow Builder / Orchestration fonctionnalité ?
Authelia ne prend pas en charge No-Code Auth Flow Builder / Orchestration fonctionnalité.
Authelia prend-il en charge Identity Verification / Document Proofing fonctionnalité ?
Authelia ne prend pas en charge Identity Verification / Document Proofing fonctionnalité.
Authelia prend-il en charge Decentralized / Verifiable Credentials fonctionnalité ?
Authelia ne prend pas en charge Decentralized / Verifiable Credentials fonctionnalité.
Authelia prend-il en charge Built-in Billing / Subscription Management fonctionnalité ?
Authelia ne prend pas en charge Built-in Billing / Subscription Management fonctionnalité.
Authelia prend-il en charge Agentic AI / MCP Server Authentication fonctionnalité ?
Authelia ne prend pas en charge Agentic AI / MCP Server Authentication fonctionnalité. No documented support for AI agent/workload identity tokens beyond standard OAuth 2.0 client_credentials.
Authelia prend-il en charge Post-Quantum Digital Signature Algorithms fonctionnalité de cryptographie post-quantique ?
Authelia ne prend pas en charge Post-Quantum Digital Signature Algorithms fonctionnalité de cryptographie post-quantique. No evidence found of ML-DSA/Dilithium, SLH-DSA/SPHINCS+, or FN-DSA/Falcon support for OIDC ID token or JWT signing. Targeted GitHub searches of authelia/authelia issues/discussions for quantum-related terms returned no results. En savoir plus
Authelia prend-il en charge Post-Quantum Token & Data Encryption fonctionnalité de cryptographie post-quantique ?
Authelia ne prend pas en charge Post-Quantum Token & Data Encryption fonctionnalité de cryptographie post-quantique. No public evidence found that the provider supports ML-KEM or HPKE (RFC 9180) for encrypting JWE tokens, SAML assertions, or user secrets.
Authelia prend-il en charge Post-Quantum Certificate & mTLS Support fonctionnalité de cryptographie post-quantique ?
Authelia ne prend pas en charge Post-Quantum Certificate & mTLS Support fonctionnalité de cryptographie post-quantique. No public evidence found of post-quantum or hybrid X.509 digital certificate support for mTLS client authentication or federation endpoints.
Authelia prend-il en charge Post-Quantum Stateful Hash Signatures fonctionnalité de cryptographie post-quantique ?
Authelia ne prend pas en charge Post-Quantum Stateful Hash Signatures fonctionnalité de cryptographie post-quantique. No public evidence found of NIST SP 800-208 stateful hash-based signature scheme support (LMS/HSS, XMSS).
Comparer avec d'autres fournisseurs
Remarque : Les données actuelles sont basées sur la documentation/l'expérience des fournisseurs et peuvent ne pas être exactes à 100 %. Veuillez ouvrir un ticket si vous avez constaté des incohérences.