Authentik is an open source identity provider that gives your applications single sign-on (SSO) through OpenID Connect, OAuth2, SAML, LDAP and a forward-auth proxy. In this tutorial you will deploy Authentik on Ubuntu 24.04 with Docker Compose, publish it on its own subdomain over HTTPS with Nginx and Let's Encrypt, create the first administrator, and register an application that signs users in with OpenID Connect.

Prerequisites

To follow this guide you need:

  • A server running Ubuntu 24.04 LTS with at least 2 vCPUs and 2 GB of RAM (4 GB is more comfortable), for example a CubePath VPS.
  • A non-root user with sudo privileges.
  • A domain with a DNS A record for the subdomain Authentik will use, such as auth.your_domain, pointing to your_server_ip.
  • Ports 22, 80 and 443 reachable from the Internet.

Throughout the guide, replace auth.your_domain with your real hostname.

Step 1 - Installing Docker Engine and Docker Compose

Authentik is distributed as container images and its supported single-server install is Docker Compose. Install Docker Engine and the Compose plugin from Docker's official repository.

Add Docker's GPG key:

sudo apt update
sudo apt install -y ca-certificates curl
sudo install -m 0755 -d /etc/apt/keyrings
sudo curl -fsSL https://download.docker.com/linux/ubuntu/gpg -o /etc/apt/keyrings/docker.asc
sudo chmod a+r /etc/apt/keyrings/docker.asc

Add the repository and install the packages:

echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/ubuntu $(. /etc/os-release && echo "$VERSION_CODENAME") stable" | sudo tee /etc/apt/sources.list.d/docker.list > /dev/null
sudo apt update
sudo apt install -y docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin

Confirm that Docker and Compose are available:

sudo docker compose version
Docker Compose version v2.x.x

Step 2 - Downloading the Authentik Compose file

Create a directory for the deployment and download the official Compose file maintained by the Authentik project:

sudo mkdir -p /opt/authentik
cd /opt/authentik
sudo curl -fsSL -o docker-compose.yml https://goauthentik.io/docker-compose.yml

The file defines a PostgreSQL database, the Authentik server (web interface and API) and the worker (background tasks). Take a moment to read it with less docker-compose.yml so you know what will run on your server. Do not edit it: keep your settings in a separate .env file so upgrades only require replacing docker-compose.yml.

Step 3 - Generating secrets and the environment file

Authentik needs a database password and a secret key used to sign sessions and tokens. Generate both with openssl and write them to /opt/authentik/.env:

echo "PG_PASS=$(openssl rand -base64 36 | tr -d '\n')" | sudo tee /opt/authentik/.env > /dev/null
echo "AUTHENTIK_SECRET_KEY=$(openssl rand -base64 60 | tr -d '\n')" | sudo tee -a /opt/authentik/.env > /dev/null

By default the Compose file publishes Authentik on ports 9000 (HTTP) and 9443 (HTTPS) on every interface. Because Nginx will terminate TLS in front of it, bind Authentik to localhost only and disable anonymous error reporting:

sudo tee -a /opt/authentik/.env > /dev/null <<'EOF'
COMPOSE_PORT_HTTP=127.0.0.1:9000
COMPOSE_PORT_HTTPS=127.0.0.1:9443
AUTHENTIK_ERROR_REPORTING__ENABLED=false
EOF
sudo chmod 600 /opt/authentik/.env

Check the result:

sudo cat /opt/authentik/.env
PG_PASS=Qm3v...
AUTHENTIK_SECRET_KEY=h7Zp...
COMPOSE_PORT_HTTP=127.0.0.1:9000
COMPOSE_PORT_HTTPS=127.0.0.1:9443
AUTHENTIK_ERROR_REPORTING__ENABLED=false

Step 4 - Starting Authentik

Pull the images and start the stack in the background:

cd /opt/authentik
sudo docker compose pull
sudo docker compose up -d

The first start runs the database migrations, which can take a minute or two. Check that all containers are running and healthy:

sudo docker compose ps
NAME                      IMAGE                                   STATUS
authentik-postgresql-1    docker.io/library/postgres:16-alpine    Up 2 minutes (healthy)
authentik-server-1        ghcr.io/goauthentik/server:2025.x.x     Up 2 minutes (healthy)
authentik-worker-1        ghcr.io/goauthentik/server:2025.x.x     Up 2 minutes (healthy)

Older Authentik releases also run a redis container; that is expected if your Compose file includes it. Then query the liveness endpoint locally:

curl -sI http://127.0.0.1:9000/-/health/live/ | head -n 1
HTTP/1.1 204 No Content

If a container keeps restarting, read its logs with sudo docker compose logs server or sudo docker compose logs worker.

Step 5 - Publishing Authentik over HTTPS with Nginx

Install Nginx and Certbot, and allow web traffic through UFW:

sudo apt install -y nginx certbot python3-certbot-nginx
sudo ufw allow OpenSSH
sudo ufw allow 'Nginx Full'
sudo ufw enable

Create a server block for Authentik:

sudo nano /etc/nginx/sites-available/authentik

Paste the following configuration. Authentik uses WebSockets for outposts and the admin interface, so the Upgrade and Connection headers are required:

upstream authentik {
    server 127.0.0.1:9000;
    keepalive 10;
}

map $http_upgrade $connection_upgrade_keepalive {
    default upgrade;
    ''      '';
}

server {
    listen 80;
    listen [::]:80;
    server_name auth.your_domain;

    location / {
        proxy_pass http://authentik;
        proxy_http_version 1.1;
        proxy_set_header Host $host;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection $connection_upgrade_keepalive;
    }
}

Enable the site, test the syntax and reload Nginx:

sudo ln -s /etc/nginx/sites-available/authentik /etc/nginx/sites-enabled/
sudo nginx -t
sudo systemctl reload nginx
nginx: the configuration file /etc/nginx/nginx.conf syntax is ok
nginx: configuration file /etc/nginx/nginx.conf test is successful

Request a Let's Encrypt certificate. Certbot adds the listen 443 ssl directives and an HTTP to HTTPS redirect to the same file:

sudo certbot --nginx -d auth.your_domain

Verify that Authentik answers through Nginx with a valid certificate:

curl -sI https://auth.your_domain/-/health/live/ | head -n 1
HTTP/2 204

Step 6 - Creating the administrator account

Open the initial setup flow in your browser. The trailing slash is required:

https://auth.your_domain/if/flow/initial-setup/

Enter an email address and a strong password for the default administrator, akadmin. After submitting the form you land in the user interface; click Admin interface to open the administration area.

Two recommended follow-ups from the admin interface:

  • Enable multi-factor authentication for akadmin under Settings > MFA Devices in the user interface.
  • Create a personal admin user in Directory > Users, add it to the authentik Admins group, and stop using akadmin day to day.

Step 7 - Connecting an application with OpenID Connect

As an example, register an application that supports OpenID Connect (Grafana, Nextcloud, Gitea, Proxmox VE and most modern web apps do). You need the application's redirect (callback) URI, which its documentation provides, for example https://app.your_domain/login/generic_oauth.

  1. In the admin interface go to Applications > Applications and click Create with provider.
  2. Give the application a Name (for example My App) and note its Slug (my-app).
  3. Choose OAuth2/OpenID Provider as the provider type.
  4. Select the default-provider-authorization-implicit-consent authorization flow (or the explicit consent flow if you want users to approve access).
  5. Leave Client type as Confidential, and add a Redirect URI with mode Strict and your application's callback URL.
  6. Copy the generated Client ID and Client Secret, then click Submit.

Every OIDC application in Authentik gets its own discovery document. Check that it is published:

curl -s https://auth.your_domain/application/o/my-app/.well-known/openid-configuration | python3 -m json.tool | head -n 5
{
    "issuer": "https://auth.your_domain/application/o/my-app/",
    "authorization_endpoint": "https://auth.your_domain/application/o/authorize/",
    "token_endpoint": "https://auth.your_domain/application/o/token/",
    "userinfo_endpoint": "https://auth.your_domain/application/o/userinfo/",

In your application's OIDC settings, enter the issuer (or discovery) URL, the client ID and the client secret, and request the scopes openid email profile. Log out of Authentik, open the application and choose its SSO login: you should be redirected to Authentik, and back to the application once you sign in.

Step 8 - Upgrading Authentik

Authentik publishes new releases regularly and upgrades are done by replacing the Compose file. Read the release notes first, since some versions include breaking changes, and only upgrade one major release at a time.

cd /opt/authentik
sudo curl -fsSL -o docker-compose.yml https://goauthentik.io/docker-compose.yml
sudo docker compose pull
sudo docker compose up -d

Your .env file is kept, and the database migrations run automatically on start. Before upgrading, back up the database:

sudo docker compose exec -T postgresql pg_dump -U authentik -d authentik | gzip > ~/authentik-$(date +%F).sql.gz

Troubleshooting

502 Bad Gateway from Nginx. The containers are not ready or not listening on 127.0.0.1:9000. Run sudo docker compose ps and sudo ss -tlnp | grep 9000, and check sudo docker compose logs server.

"Redirect URI Error" when signing in to an application. The redirect URI sent by the application does not exactly match the one saved in the provider, including scheme, port and trailing slash. Copy the value from the error page into the provider's Redirect URIs field.

Login loops or wrong URLs behind the proxy. Make sure Nginx sends the Host and X-Forwarded-Proto headers shown in Step 5, so Authentik builds https:// URLs with the public hostname.

Emails are not sent. Authentik only sends email (recovery, verification) after you configure SMTP with the AUTHENTIK_EMAIL__HOST, AUTHENTIK_EMAIL__PORT, AUTHENTIK_EMAIL__USERNAME, AUTHENTIK_EMAIL__PASSWORD, AUTHENTIK_EMAIL__USE_TLS and AUTHENTIK_EMAIL__FROM variables in .env, followed by sudo docker compose up -d. You can test it with sudo docker compose exec worker ak test_email you@your_domain.

Conclusion

You now have Authentik running on Ubuntu 24.04 behind Nginx with a Let's Encrypt certificate, a protected administrator account, and an application signing users in through OpenID Connect. From here you can add SAML providers for applications that only speak SAML, deploy an LDAP outpost for legacy services, or put internal tools without their own login behind Authentik's proxy provider with Nginx auth_request.