Single sign-on
one login covering all your self-hosted apps

// screenshot of authelia.com ↗
Authelia is an authentication and authorization server providing SSO and 2FA for self-hosted apps. Acts as a forward-auth provider in front of reverse proxies (nginx, Traefik, Caddy) — protect any app with SSO without modifying the app itself.
Authelia is an authentication and authorization server providing SSO and 2FA for self-hosted apps. Acts as a forward-auth provider in front of reverse proxies (nginx, Traefik, Caddy) — protect any app with SSO without modifying the app itself.
For self-hosters with 10+ apps who want one login covering everything (Authelia + reverse proxy = OAuth-style SSO for non-OAuth apps), Authelia is the lightweight answer.
Concrete scenarios where teams pick Authelia over the SaaS alternative.
one login covering all your self-hosted apps
TOTP, WebAuthn, mobile push
per-app access control
provide OIDC for apps that support it
failed-login throttling
If your team profile matches one of these, Authelia is a strong fit out of the box.
with 10+ apps wanting unified auth
requiring central auth control
running employee self-service
building secure home infrastructure
needing audit-able auth
When evaluating self-hosted options for this category, here are the dimensions on which Authelia consistently lands above the alternatives.
The stack you'll plug Authelia into — services, protocols, and adjacent apps in the BluixApps catalog.
authelia/authelia:4.38 (release-tagged)Operational guidance from running this in production — what to do before you scale, what to lock down, what surprises people.
9091:9091 · authelia/authelia:latest