Risky Biz Soap Box: Run your own open source IDP with Authentik
Feb 14, 2025
auto_awesome
Fletcher Heisler, CEO of Authentik and a leader in open-source identity solutions, dives into the power of self-hosted identity management. He explains how users are reclaiming control from traditional SaaS providers like Okta. The discussion highlights Authentik's flexibility and adaptability for businesses, whether on-premises or in the cloud. Fletcher emphasizes user-driven development, security through transparency, and the importance of backup strategies, making a strong case for the future of open-source identity solutions.
Authentik empowers organizations by offering a customizable, self-hosted open-source identity provider solution that enhances control over identity management.
The open-source model of Authentik not only allows for rapid feature development based on user feedback but also ensures security through community involvement and code transparency.
Deep dives
Overview of Authentic's Unique Offering
Authentic operates as an Open Source based Identity Provider (IDP), providing a self-hosted solution that allows for extensive customization and flexibility compared to traditional IDPs like Okta. With its origins as an open-source project, Authentic enables users to modify the application to meet specific needs, offering features such as Docker or Kubernetes deployment, and one-click deployment on AWS. This flexibility is critical for enterprises requiring more than basic IDP functions, as many legacy solutions come with additional costs for essential features. Authentic aims to empower organizations by allowing them to take control of their identity management while supporting the public benefit mission behind the open-source project.
Solving Problems in the Mature IDP Market
The identity management market is characterized by established players with significant market share, creating a challenging environment for new entrants like Authentic. However, Authentic distinguishes itself by providing a fully customizable solution, addressing the growing need for flexible integrations and cost-effective alternatives. Companies often face issues with legacy IDPs that require extensive engineering efforts to adapt to specific needs, leading to increased operational costs. With Authentic, users are encouraged to tailor the solution to their specific requirements, which can include protocol integration and custom application handling without the cumbersome limitations typically seen in legacy systems.
Emerging Use Cases and Early Adopter Adoption
Early adopter traction for Authentic is seen in sectors such as emergency services, where reliable and resilient IDP solutions are crucial, especially in situations where connectivity is unreliable. Companies in Europe are also attracted to Authentic to mitigate privacy concerns related to US-based providers, as they can retain full control over their personal information and data management. Additionally, large enterprises are increasingly seeking to tailor existing setups to the specific workflows and requirements, benefiting from the ability to make incremental changes that are directly relevant to their operations. The open-source nature allows for rapid feature development and the incorporation of client feedback into native offerings.
Navigating Features, Security, and Code Reviews
The open-source model not only supports feature updates based on user requests but also enhances security through transparency, as users are encouraged to conduct code reviews and contribute to improvements. Authentic balances the necessity of customization with security best practices, vetting potential features before merging community requests to avoid vulnerabilities. Concerns about merging features that could compromise security, like SMS for 2FA, prompt ongoing discussions around reasonable limits for customization while providing enough flexibility for users. This rigorous approach ensures that customers can adapt the platform to their needs without sacrificing security or introducing risks associated with poorly vetted changes.
In this SoapBox edition of the show Patrick Gray chats to Fletcher Heisler, the CEO of open-source identity provider Authentik.
The whole idea of Authentik is you can take control of an essential IT and security function: identity. Because Authentik is open source it’s extremely flexible, and if you’re running it yourself, you get to decide where your IDP should sit in your architecture. You can run it on prem if you’re an emergency call centre or you’re operating an airgapped network, or you can spin it up in your cloud environment if you’re a typical enterprise.
Fletcher talks through the reasons Authentik users are decoupling themselves from the major SaaS Identity Providers, and the flexibility that comes from being able to assemble exactly what you need.