Friction

authentik

goauthentik.io · Authentication and identity

Open-source identity provider and single sign-on platform.

50 items · 67 source threads · 2 source types · updated 2026-07

Compare

Pain points 32

ItemAreaSeveritySupportLast seen
Domain-level forward auth fails with external outposts (400)

Domain-level forward auth works with the embedded outpost but external proxy outposts return 400 with a session mismatch, while app-level forward auth works.

Affects: Multi-server docker-compose and Traefik user

Reliability & bugsBlocks work4 sources2024-08

“With Proxies, it returns 400 (in logs wrong session)”

“I do not see the headers : access-control-allow-origin: https://origin.domain.com”

WebAuthn login loops on security key after upgrade to 2026.5.4

After updating, logging in with a YubiKey repeatedly reopens the Windows Hello prompt. Rolling back to the previous version fixes it, and a second site on the same version still works.

Affects: User signing in with a hardware security key

Reliability & bugsBlocks work3 sources2026-07

“If I do a rollback to 2026.5.3 it let me login without the reappearing window”

“On mobile sometime 2FA page available but after entered code ,reload to 1st stage”

Outpost unhealthy and apps return 500 after 2025.12.2 upgrade

After moving from 2025.12.1 to 2025.12.2 the outpost reports unhealthy and applications behind Nginx Proxy Manager fail with 500. Downgrading to the earlier version fixes it.

Affects: Docker user with Nginx Proxy Manager

Self-hosting & upgradesBlocks work3 sources2026-01

“After updating to 2025.12.2 my Outpost shows as unhealthy and Applications can not login (error 500 from NGinx Proxy Manager)”

“When accessing an outpost after all components were upgraded to 2025.10.0 I get this error”

UI says no workers connected after upgrading to 2025.10.1/2

After updating with the official compose file, the interface warns that no workers are connected and background tasks will not run, though worker logs keep flowing. Rolling back to 2025.10.0 fixes it.

Affects: Docker compose user

Reliability & bugsBlocks work3 sources2025-11

“In versions 2025.10.1 and 2025.10.2, the worker is displayed as not connected”

“Getting an unhealthy container for the authentik worker”

Invitation docs ship an enrollment flow without an invitation stage

The invitation guide provides a ready-made enrollment flow lacking an invitation stage, so no invite link is available until the user adds the stage manually.

Affects: Admin enrolling users by invitation

DocumentationBlocks work3 sources2025-01

“Is it really required to write your own lookup code for each property”

“The doc is providing a ready-made enrollment flow that do not contains an invitation stage”

Infinite redirect loop on all proxy providers since 2024.10

Locked: summary and evidence are part of Sprint Pass and Pro

Self-hosting & upgradesCauses churn2 sources2024-11
Fresh docker-compose install: initial setup page not found, hours lost

Locked: summary and evidence are part of Sprint Pass and Pro

Setup & onboardingCauses churn2 sources2024-08
Worker container causes high CPU right after startup

Locked: summary and evidence are part of Sprint Pass and Pro

PerformanceCauses churn2 sources2023-10
Domain-level forward auth lands on authentik start page, not the app

Locked: summary and evidence are part of Sprint Pass and Pro

Reliability & bugsBlocks work2 sources2025-03
2024.12 regression breaks recovery links and recovery emails

Locked: summary and evidence are part of Sprint Pass and Pro

Reliability & bugsBlocks work2 sources2025-03
Users randomly redirected to the wrong service after session expiry

Locked: summary and evidence are part of Sprint Pass and Pro

Reliability & bugsBlocks work2 sources2024-02
Failed 2026.2 upgrade leaves database in a hanging migration state

Locked: summary and evidence are part of Sprint Pass and Pro

Self-hosting & upgradesCauses churn1 source2026-03
Proxy outpost fills shared memory with sessions and crashes the server

Locked: summary and evidence are part of Sprint Pass and Pro

Reliability & bugsCauses churn1 source2024-11
2026.2 upgrade raises Postgres connections 1.5 to 3 times

Locked: summary and evidence are part of Sprint Pass and Pro

PerformanceBlocks work1 source2026-03
Custom CSS in brand settings stopped applying after 2025.12

Locked: summary and evidence are part of Sprint Pass and Pro

CustomizationBlocks work1 source2026-01
Firefox for Android freezes on the user library page since 2025.10

Locked: summary and evidence are part of Sprint Pass and Pro

UI & usabilityBlocks work1 source2025-10
Enrollment and password recovery email flows fail with a generic error

Locked: summary and evidence are part of Sprint Pass and Pro

Reliability & bugsBlocks work1 source2025-02
Kerberos source against Windows AD fails with a database error

Locked: summary and evidence are part of Sprint Pass and Pro

IntegrationsBlocks work1 source2025-01
AWS SCIM provisioning fails with 400 on group PATCH

Locked: summary and evidence are part of Sprint Pass and Pro

IntegrationsBlocks work1 source2024-12
Cannot create OpenID Connect provider after upgrading to 2024.8.0

Locked: summary and evidence are part of Sprint Pass and Pro

Reliability & bugsBlocks work1 source2024-09
Post-logout redirect parameters ignored

Locked: summary and evidence are part of Sprint Pass and Pro

API & developer experienceBlocks work1 source2024-07
Blueprint export command fails with a traceback

Locked: summary and evidence are part of Sprint Pass and Pro

Data export & migrationBlocks work1 source2024-04
Configured web certificate is not served

Locked: summary and evidence are part of Sprint Pass and Pro

Reliability & bugsBlocks work1 source2023-10
LDAP provider lacks Samba schema for Synology NAS joining

Locked: summary and evidence are part of Sprint Pass and Pro

IntegrationsBlocks work1 source2023-07
OAuth2 password grant listed as supported but requests fail

Locked: summary and evidence are part of Sprint Pass and Pro

API & developer experienceBlocks work1 source2023-06
RADIUS provider for WPA Enterprise times out with no logs

Locked: summary and evidence are part of Sprint Pass and Pro

IntegrationsBlocks work1 source2023-04
Proxy provider stops working after upgrading to 23.1.2

Locked: summary and evidence are part of Sprint Pass and Pro

Self-hosting & upgradesBlocks work1 source2023-01
Login screen takes 15-20 seconds to load

Locked: summary and evidence are part of Sprint Pass and Pro

PerformanceBlocks work1 source2022-06
Proxy provider with an app in a subpath redirects to a disallowed URI

Locked: summary and evidence are part of Sprint Pass and Pro

Reliability & bugsBlocks work1 source2022-02
Random 502 errors with authentik starting message during login

Locked: summary and evidence are part of Sprint Pass and Pro

Reliability & bugsBlocks work1 source2022-02
Password manager fails to detect fields in compatibility mode

Locked: summary and evidence are part of Sprint Pass and Pro

UI & usabilityAnnoyance1 source2024-02
Enterprise-oriented features add complexity for self-hosting use

Locked: summary and evidence are part of Sprint Pass and Pro

Setup & onboardingAnnoyance1 source2023-06

Feature requests 17

ItemAreaSeveritySupportLast seen
No HAProxy forward-auth documentation, blocking adoption

The forward-auth docs list Nginx, Caddy, Envoy and Traefik but not HAProxy. A prospective user cannot adopt authentik without a HAProxy guide and points to a competitor that has one.

Affects: HAProxy user evaluating authentik

DocumentationCauses churn1 source2023-05

“I use HAProxy, and am not sure how to set it up, so I cannot use Authentik yet”

Implicit consent for refresh tokens (offline_access) not possible

The offline_access scope always shows a consent prompt, awkward when the app creates users through the API. No API endpoint was found to set consent programmatically.

Affects: Developers creating users via the API

API & developer experienceBlocks work1 source2024-04

“Is it posible to have implicit consent with offline_access scope, it appears to always opens the consent promt”

Unclear how to back up and restore authentik configuration

User wants to back up all authentik config and restore it to a new instance. Blueprint export is confusing and the UI only exports flows, not stages or other objects.

Affects: Self-hosting admin

Data export & migrationBlocks work1 source2024-02

“How to create a back up of all the configuration of the Authentik, including username/authorization method, etc...?”

Allow groups to have multiple parent groups

A team organizes its directory as a DAG of groups; authentik only allows one parent per group. They currently manage the DAG externally and want to leave that setup, since binding central groups directly loses nested-group benefits.

Affects: Teams moving from AWS SSO with shared central groups

Permissions & securityBlocks work1 source2023-07

“The simplest solution would be to allow multiple parents on a single group”

Allow iframe embedding of protected apps and respect app CSP headers

Apps protected by authentik can no longer be embedded in a page such as Nextcloud external sites, even with a frame-ancestors header set. The user must open them in a new tab.

Affects: Nextcloud users embedding protected services

IntegrationsBlocks work1 source2023-05

“Currently it seems not to be possible to embed pages/services protected with Authentik as iframes in other pages”

LDAP group sync should support memberOf for nested groups

Locked: summary and evidence are part of Sprint Pass and Pro

IntegrationsBlocks work1 source2022-10
Log remote IP of failed logins so CrowdSec can parse them

Locked: summary and evidence are part of Sprint Pass and Pro

Permissions & securityBlocks work1 source2022-10
Logging out of the IdP should end sessions of proxied applications

Locked: summary and evidence are part of Sprint Pass and Pro

Permissions & securityBlocks work1 source2021-12
Support Redis Sentinel for highly available deployments

Locked: summary and evidence are part of Sprint Pass and Pro

Self-hosting & upgradesBlocks work1 source2021-08
Let authentik act as GitLab SSO for Mattermost Team Edition

Locked: summary and evidence are part of Sprint Pass and Pro

IntegrationsAnnoyance1 source2023-01
No documented bare-metal or LXC install

Locked: summary and evidence are part of Sprint Pass and Pro

Self-hosting & upgradesAnnoyance1 source2022-12
Add email-delivered one-time passcode stage

Locked: summary and evidence are part of Sprint Pass and Pro

Permissions & securityAnnoyance1 source2022-07
Allow a trusted network to bypass authentication

Locked: summary and evidence are part of Sprint Pass and Pro

Permissions & securityAnnoyance1 source2022-07
Client certificate authentication stage

Locked: summary and evidence are part of Sprint Pass and Pro

Permissions & securityAnnoyance1 source2022-05
Kerberos / Integrated Windows Authentication login

Locked: summary and evidence are part of Sprint Pass and Pro

IntegrationsAnnoyance1 source2022-04
More consistent and deeper UI branding, including hard-coded pages

Locked: summary and evidence are part of Sprint Pass and Pro

CustomizationAnnoyance1 source2022-02
Add Telegram as a social login provider

Locked: summary and evidence are part of Sprint Pass and Pro

IntegrationsAnnoyance1 source2022-02

Workarounds 0

Nothing recorded in this category yet.

Switching reasons 1

ItemAreaSeveritySupportLast seen
Creating one application needs too many separate objects, user went back to Zitadel

A homelab user found that adding a single application required configuring several linked pieces (flows, stages, providers, outposts) and clicked through defaults. They switched back to Zitadel for simpler app creation.

Affects: Solo self-hoster running one login for several services

UI & usabilityCauses churn1 source2024-09

“with Authentik I needed to configure like 3 three separate things to create a new "Application”