← BACK TO FORUM INDEX

Authentik vs Authelia vs Keycloak | SSO for homelabs

BY | Sep 1, 2026 | Network Security

Authentik vs Authelia vs Keycloak: SSO for Homelabs in 2026

Once you run more than a handful of apps (NPM, Nextcloud, Grafana, Immich, Mailcow, MeshCentral), logging into each one separately becomes a security problem — not just an inconvenience. A single identity layer with 2FA, app access policies, and one logout path is one of the highest-leverage upgrades you can make to a homelab or small business stack.

Three self-hosted options dominate in 2026: Authentik, Authelia, and Keycloak. They all do SSO. They do not all belong on the same kind of network.

What SSO Actually Solves

Credential Sprawl

One Identity, Many Apps

Stop creating a unique password in every container UI. One account, one 2FA device, consistent lockout policy.

Exposure

Fewer Public Logins

Put SSO in front of admin panels. Apps never see the internet — only the identity proxy does.

Offboarding

Revoke Once

Disable a user in one place and every proxied app stops working. Critical for family labs and small teams.

Protocol

OIDC / SAML / LDAP

Modern apps speak OpenID Connect. Older NAS and mail stacks still want LDAP. Your IdP needs to match the apps you actually run.

Forward Auth

Works With NPM

Nginx Proxy Manager + forward auth is the typical homelab pattern: Cloudflare → NPM → Authelia/Authentik → the app.

Reality Check

SSO Is Not a Firewall

Identity sits on top of mesh VPN, CrowdSec, and least-privilege ports. It does not replace them.

The Three Contenders

Homelab Favorite

Authentik

Full-featured IdP with a polished UI, flows, outposts, OIDC, SAML, LDAP, and proxy outposts. Heavier than Authelia, much easier than Keycloak for most self-hosters.

Lightweight Gate

Authelia

Purpose-built forward-auth companion for reverse proxies. Excellent 2FA, access rules, and NPM/Traefik integration. Not a full enterprise IdP.

Enterprise Standard

Keycloak

The heavyweight. Realms, federation, fine-grained clients, SAML at scale. Powerful and operationally expensive for a homelab.

Resource Use

RAM and Complexity

Authelia is tiny. Authentik wants a database and more RAM. Keycloak is a Java service — plan CPU, heap, and backups like a real app.

App Coverage

What They Protect

Authelia shines at “is this request allowed.” Authentik and Keycloak shine when the app itself is an OIDC client (Grafana, Nextcloud, Portainer, MeshCentral).

Operations

Day-2 Work

Upgrades, token signing keys, backup of the IdP database, and a break-glass local admin account. If the IdP dies, every app login dies with it.

A Practical 1-2-3 Homelab Pattern

1 — Put identity behind the mesh, not on the WAN

Reach Authentik/Authelia/Keycloak over Tailscale, Netbird, or ZeroTier. Do not forward their admin ports. Public apps still terminate TLS at Cloudflare + NPM.

2 — Forward-auth for dumb apps, OIDC for real clients

Jellyfin-style UIs that have no OIDC: protect with Authelia or an Authentik proxy outpost. Grafana, Nextcloud, and similar: native OIDC against Authentik or Keycloak.

3 — Break-glass and backups

Keep one local admin path that does not depend on the IdP (console, SSH, or a published emergency location). Backup the IdP database with the rest of your 3-2-1 plan.

Which One Should You Run?

Choose Authelia if

You mainly want 2FA in front of NPM/Traefik locations, you like YAML, and you do not need a full user-management suite.

Choose Authentik if

You want a GUI, mixed OIDC + forward-auth, invites, and room to grow without jumping to Keycloak. This is the usual 2026 homelab pick.

Choose Keycloak if

You are federating with another IdP, need SAML for a specific vendor, or you already operate Java services and want realm-level control.

Official Resources

Questions for the Community

What are you running?

Authentik, Authelia, Keycloak, or still per-app logins?

Forward-auth or native OIDC?

Which apps forced you to change approach?

What broke first?

Upgrades, cookies across subdomains, WebSockets, or a downed IdP locking you out?

SSO is how a homelab stops being a pile of passwords and starts looking like an actual access policy. Pick the smallest IdP that covers your apps — then protect the IdP itself like it is production.

Disclaimer

This content is for educational and informational purposes only. It is not technical advice. Identity and access changes can lock you out of your own systems. Keep a tested break-glass path and verify configuration in a non-production environment first.

DISCUSSION

No replies yet. Be the first to join the discussion!

A1 AI Assistant
Call Text A1 Forum Tech News Contact Form