Authentik vs Authelia vs Keycloak: SSO for Homelabs in 2026
Once you run more than a handful of apps (NPM, Nextcloud, Grafana, Immich, Mailcow, MeshCentral), logging into each one separately becomes a security problem — not just an inconvenience. A single identity layer with 2FA, app access policies, and one logout path is one of the highest-leverage upgrades you can make to a homelab or small business stack.
Three self-hosted options dominate in 2026: Authentik, Authelia, and Keycloak. They all do SSO. They do not all belong on the same kind of network.
What SSO Actually Solves
Credential Sprawl
One Identity, Many Apps
Stop creating a unique password in every container UI. One account, one 2FA device, consistent lockout policy.
Exposure
Fewer Public Logins
Put SSO in front of admin panels. Apps never see the internet — only the identity proxy does.
Offboarding
Revoke Once
Disable a user in one place and every proxied app stops working. Critical for family labs and small teams.
Protocol
OIDC / SAML / LDAP
Modern apps speak OpenID Connect. Older NAS and mail stacks still want LDAP. Your IdP needs to match the apps you actually run.
Forward Auth
Works With NPM
Nginx Proxy Manager + forward auth is the typical homelab pattern: Cloudflare → NPM → Authelia/Authentik → the app.
Reality Check
SSO Is Not a Firewall
Identity sits on top of mesh VPN, CrowdSec, and least-privilege ports. It does not replace them.
The Three Contenders
Homelab Favorite
Authentik
Full-featured IdP with a polished UI, flows, outposts, OIDC, SAML, LDAP, and proxy outposts. Heavier than Authelia, much easier than Keycloak for most self-hosters.
Lightweight Gate
Authelia
Purpose-built forward-auth companion for reverse proxies. Excellent 2FA, access rules, and NPM/Traefik integration. Not a full enterprise IdP.
Enterprise Standard
Keycloak
The heavyweight. Realms, federation, fine-grained clients, SAML at scale. Powerful and operationally expensive for a homelab.
Resource Use
RAM and Complexity
Authelia is tiny. Authentik wants a database and more RAM. Keycloak is a Java service — plan CPU, heap, and backups like a real app.
App Coverage
What They Protect
Authelia shines at “is this request allowed.” Authentik and Keycloak shine when the app itself is an OIDC client (Grafana, Nextcloud, Portainer, MeshCentral).
Operations
Day-2 Work
Upgrades, token signing keys, backup of the IdP database, and a break-glass local admin account. If the IdP dies, every app login dies with it.
A Practical 1-2-3 Homelab Pattern
1 — Put identity behind the mesh, not on the WAN
Reach Authentik/Authelia/Keycloak over Tailscale, Netbird, or ZeroTier. Do not forward their admin ports. Public apps still terminate TLS at Cloudflare + NPM.
2 — Forward-auth for dumb apps, OIDC for real clients
Jellyfin-style UIs that have no OIDC: protect with Authelia or an Authentik proxy outpost. Grafana, Nextcloud, and similar: native OIDC against Authentik or Keycloak.
3 — Break-glass and backups
Keep one local admin path that does not depend on the IdP (console, SSH, or a published emergency location). Backup the IdP database with the rest of your 3-2-1 plan.
Which One Should You Run?
Choose Authelia if
You mainly want 2FA in front of NPM/Traefik locations, you like YAML, and you do not need a full user-management suite.
Choose Authentik if
You want a GUI, mixed OIDC + forward-auth, invites, and room to grow without jumping to Keycloak. This is the usual 2026 homelab pick.
Choose Keycloak if
You are federating with another IdP, need SAML for a specific vendor, or you already operate Java services and want realm-level control.
Official Resources
Questions for the Community
What are you running?
Authentik, Authelia, Keycloak, or still per-app logins?
Forward-auth or native OIDC?
Which apps forced you to change approach?
What broke first?
Upgrades, cookies across subdomains, WebSockets, or a downed IdP locking you out?
SSO is how a homelab stops being a pile of passwords and starts looking like an actual access policy. Pick the smallest IdP that covers your apps — then protect the IdP itself like it is production.
Disclaimer
This content is for educational and informational purposes only. It is not technical advice. Identity and access changes can lock you out of your own systems. Keep a tested break-glass path and verify configuration in a non-production environment first.
No replies yet. Be the first to join the discussion!