Skip to content
STACK IT FAST

Authelia vs authentik vs Logto

Architecture comparison 3 projects Built from source-audited deep dives

Authelia is a single Go binary that adds SSO and MFA in front of apps behind your reverse proxy. authentik is a full identity provider on Django with Go outposts for LDAP, RADIUS and proxying. Logto is a TypeScript/Koa OIDC and OAuth 2.1 platform aimed at SaaS apps that need multi-tenancy and RBAC.

Authelia
Go · Apache-2.0
Authentik
Python · NOASSERTION
Logto
TypeScript · MPL-2.0
Updated
2026-09-25

Which one should you pick?

Pick Authelia if…
  • You want to protect existing web apps at the reverse proxy with SSO and MFA
  • You want one small Go binary with SQLite, MySQL or PostgreSQL
  • You need WebAuthn passkeys, TOTP or Duo push
Pick Authentik if…
  • You need a full IdP speaking SAML, OAuth2/OIDC, LDAP and RADIUS
  • You want PostgreSQL to be the only stateful dependency (no Redis)
  • You need multi-tenancy in a self-hosted IdP
Pick Logto if…
  • You are building a SaaS or AI product and need customer-facing auth
  • You want OIDC/OAuth 2.1, multi-tenancy, enterprise SSO and RBAC in a TypeScript stack
  • You want social and enterprise connectors as plugins

Side by side

Attribute Authelia Authentik Logto
Written in GoTypeScript PythonTypeScriptRust TypeScriptSCSS
License Apache-2.0 NOASSERTION MPL-2.0
Frontend ReactVite@simplewebauthn/browseri18next LitViteStorybookDocusaurus ReactViteSCSS
Backend & APIs Gofasthttpauthelia.com/provider/oauth2go-webauthn/webauthngo-ldap/ldap PythonDjangoDjango REST FrameworkDjango ChannelsRust (Axum) Koa
Data & persistence PostgreSQLMySQLSQLiteRedis PostgreSQLdjango-channels-postgresdjango-postgres-cachedjango-dramatiq-postgres PostgreSQLSlonik
Infrastructure & deploy DockerBuildkite DockerKubernetespnpm DockerRenderpnpmGitHub Actions
Key decisions
  • One Go binary is the full authentication portal, OIDC provider, and MFA server
  • Storage is pluggable across SQLite, MySQL, and PostgreSQL by design
  • fasthttp instead of the Go standard library net/http
  • Postgres replaces Redis for channels, cache, and the task queue
  • Legacy-protocol connectors run as separate Go "outpost" binaries, not the Django process
  • A Rust/Axum workspace exists alongside the Python core
  • The OIDC/OAuth core server is Koa, not Express
  • Console, Experience, and Core are separate packages, not one app
  • Social and enterprise connectors are a plugin ecosystem, not hardcoded
Audited 8da42b2 · 2026-09-17 836aad0 · 2026-09-17 c12d89f · 2026-09-17

How they differ

What each one is

Authelia is an authentication portal, OIDC provider and MFA server compiled into one Go binary (fasthttp, its own OAuth2/OIDC provider), with a React portal embedded. It sits beside your reverse proxy and decides who may reach each app. authentik is a general identity provider: a Django core with Django REST Framework and Channels, a Lit web UI, and separate Go “outpost” binaries for legacy protocols. Logto is identity infrastructure for applications: a Koa OIDC/OAuth core with separate Console and Experience packages.

Storage

Authelia supports SQLite, MySQL and PostgreSQL by design and can use Redis for sessions. authentik runs on PostgreSQL alone, moving channels, cache and tasks off Redis. Logto uses PostgreSQL through a typed Slonik query layer instead of an ORM.

Extensibility

authentik treats multi-tenancy as a first-class dependency. Logto ships social and enterprise connectors as a plugin ecosystem. Authelia focuses on the reverse-proxy integration and a pluggable user backend (LDAP or a file).

Architecture diagrams

Authelia Open SVG
Authelia architecture diagramBrowser → Reverse proxy (request); Reverse proxy → authelia binary (verify); Login portal → authelia binary (portal API); authelia binary → OIDC provider (OIDC flows); authelia binary → Storage (pgx / sqlite); authelia binary → Session cache (sessions); authelia binary → User backend (authenticate); authelia binary → MFA (second factor)CLIENTSSERVICESDATA & STORAGEEXTERNALBrowserprotected app userReverse proxyforward authLogin portalReact · WebAuthnauthelia binaryGo · fasthttpOIDC providerinternal/oidcStorageSQLite / MySQL / PostgresSession cacheRedis (optional)User backendLDAP or fileMFATOTP · WebAuthn · DuorequestOIDC flowsverifyportal APIpgx / sqlitesessionsauthenticatesecond factor
Authentik Open SVG
Authentik architecture diagramWeb UI → authentik core (REST · WebSocket); Apps & services → authentik core (SSO); Legacy clients → Go outposts (protocols); Go outposts → authentik core (API); authentik core → PostgreSQL (Django ORM); authentik core → Worker (enqueue); Worker → PostgreSQL (Postgres broker)CLIENTSSERVICESWORKERS & JOBSDATA & STORAGEWeb UILit · ViteApps & servicesSAML · OAuth2 · OIDCLegacy clientsLDAP · RADIUS · RDPauthentik coreDjango · DRF · ChannelsGo outpostsldap · radius · racWorkerDramatiqPostgreSQLdata · cache · channels · queueAPIREST · WebSocketSSOprotocolsenqueuePostgres brokerDjango ORM
Logto Open SVG
Logto architecture diagramConsole → @logto/core (Management API); Sign-in experience → @logto/core (Experience API); Your apps → @logto/core (OIDC); @logto/core → Connectors (connector-kit); Connectors → Identity providers (federate); @logto/core → PostgreSQL (Slonik); logto CLI → PostgreSQL (migrations)CLIENTSSERVICESWORKERS & JOBSDATA & STORAGEEXTERNALConsoleReact · ViteSign-in experienceReact · ViteYour appsOIDC / OAuth 2.1 SDKs@logto/coreKoa · OIDC providerConnectorssocial · SMS · emaillogto CLIsetup · alterationsPostgreSQLSlonikIdentity providerssocial · enterprise SSOconnector-kitManagement APIExperience APIOIDCmigrationsSlonikfederate

Frequently asked questions

Does authentik still need Redis?

The audited authentik codebase replaces Redis with PostgreSQL for channels, cache and the task queue, so PostgreSQL is its main stateful dependency.

Which of Authelia, authentik and Logto is written in Go?

Authelia's server is Go. authentik's core is Python/Django, with Go outposts and a Rust (Axum) workspace. Logto is TypeScript on Koa.