Back to articles
Technology Insight

Centralized Identity Management: Implementing Authentik with OpenID Connect (OIDC) for Coolify Security

June 2, 2026

Introduction: The Imperative of Centralized Authentication in Modern DevOps

In the contemporary cloud-native landscape, agility and security must evolve in tandem. Coolify has emerged as a premier self-hosted Platform-as-a-Service (PaaS) alternative, empowering organizations to manage applications, databases, and services with unprecedented autonomy. However, as infrastructure scales, decentralized user management quickly becomes a critical liability. Relying on isolated, local credentials across multiple Coolify instances and connected environments introduces significant security overhead, limits visibility, and elevates the risk of unauthorized access.

To mitigate these risks, enterprise DevOps teams are shifting toward unified Identity and Access Management (IAM) architectures. By integrating Authentik—an open-source, versatile identity provider—with Coolify using OpenID Connect (OIDC), organizations can establish a centralized authentication layer. This integration not only streamlines the user experience through Single Sign-On (SSO) but also enforces rigorous security postures, including Multi-Factor Authentication (MFA) and granular access policies, effectively advancing your infrastructure toward a Zero-Trust architecture.

Architectural Overview: Authentik, Coolify, and OIDC

Before diving into the technical configurations, it is essential to understand how these components interact within an OIDC federation:

  • Coolify (The Relying Party / Client): Acts as the service provider where your applications and infrastructure reside. Instead of authenticating users locally, it delegates credential verification to Authentik.
  • Authentik (The Identity Provider / IdP): The centralized authority responsible for authenticating users, enforcing security policies (like MFA), and issuing secure tokens.
  • OpenID Connect (OIDC): An identity layer built on top of the OAuth 2.0 framework. It utilizes JSON Web Tokens (JWT) to securely transmit user profile claims (such as username, email, and group memberships) from Authentik to Coolify.

When a user attempts to log into Coolify, they are redirected to Authentik. Upon successful authentication, Authentik passes an identity token back to Coolify, which validates the token and grants appropriate access. This workflow ensures that sensitive credentials never touch the application layer directly.

Step 1: Preparing Your Authentik Environment

To begin, log into your Authentik administrative dashboard. Our first objective is to create a dedicated Provider and an associated Application that will handle the OIDC handshake with Coolify.

1.1 Create the OIDC Provider

Navigate to Applications > Providers and click Create. Select OAuth2/OpenID Provider from the list and configure the following parameters:

  • Name: Coolify-OIDC-Provider
  • Authentication Flow: Select your default authentication flow (typically default-authentication-flow).
  • Authorization Flow: Select your default authorization flow.
  • Client Type: Confidential (This ensures that authorization codes are exchanged securely using a Client Secret).
  • Redirect URIs: Enter your Coolify instance's specific callback URL. For Coolify, this typically follows the structure:
    [https://coolify.yourdomain.com/login/webhooks/oauth/authentik/callback](https://coolify.yourdomain.com/login/webhooks/oauth/authentik/callback)
    Note: Replace coolify.yourdomain.com with your actual Coolify domain, and ensure the provider name matches the path slug if required by your specific routing layout.

Once saved, note down the generated Client ID and Client Secret. These credentials are vital for the Coolify configuration phase.

1.2 Create and Bind the Authentik Application

Navigate to Applications > Applications and click Create. This step exposes the provider to your users via the Authentik interface.

  1. Set the Name to Coolify Production PaaS.
  2. Set the Slug to coolify-production.
  3. In the Provider dropdown, select the Coolify-OIDC-Provider you created in the previous step.
  4. Configure UI settings such as logos or launch URLs according to your organization's branding guidelines, then click Create.

Step 2: Configuring OIDC Provider Settings within Coolify

With Authentik ready, navigate to your Coolify Instance Settings as an administrator. Coolify natively supports OIDC integration via environment variables or its UI-based authentication configuration panel, depending on your version deployment.

Access the Security / Authentication tab in Coolify and enable OAuth/OIDC. Fill in the following schema fields with the data from your Authentik instance:

  • Provider Name: authentik
  • Client ID: [Paste the Client ID from Authentik]
  • Client Secret: [Paste the Client Secret from Authentik]
  • Base URL / Issuer URL: [https://authentik.yourdomain.com/application/o/coolify-production/](https://authentik.yourdomain.com/application/o/coolify-production/)
    (This URL tells Coolify where to locate the OpenID Connect discovery document at .well-known/openid-configuration)
Security Tip: Always ensure both Authentik and Coolify are operating strictly over HTTPS. OIDC transmissions pass sensitive JWT tokens that are vulnerable to interception over unencrypted HTTP channels.

Step 3: Implementing Advanced Security Policies

Merely connecting Coolify to Authentik fulfills the convenience of SSO, but the primary business objective is robust security. Authentik allows you to inject advanced policy checks into the authentication lifecycle before a token is issued.

Enforcing Multi-Factor Authentication (MFA)

To protect your core infrastructure from credential-stuffing attacks, you should enforce MFA for anyone accessing Coolify. Within Authentik, navigate to your Flows section and edit your authentication flow. Bind an MFA Validation Stage (supporting Time-based One-Time Passwords (TOTP) or WebAuthn/FIDO2 hardware keys). By implementing this policy at the IdP level, you guarantee that even if a developer's primary password is compromised, your Coolify control plane remains secure.

Role-Based Access Control (RBAC) and Group Mapping

Not every user in your organization should possess full administrative rights over your PaaS clusters. Authentik allows you to pass group memberships via OIDC scopes (such as the openid, profile, and email scopes). You can map specific Authentik groups (e.g., DevOps-Admins, Frontend-Developers) to Coolify roles. This limits access scope, ensuring developers can only view or modify the specific applications, environments, or servers allocated to their team.

Step 4: Testing and Validation

Before rolling out the change to your wider engineering organization, perform a structured verification workflow:

  1. Open an isolated, incognito browser window and navigate to your Coolify login portal.
  2. Verify that a new option—Login with Authentik—is visible.
  3. Click the option; you should be smoothly redirected to your Authentik login subdomain.
  4. Log in using an Authentik account, complete the MFA challenge, and authorize the application if prompted.
  5. Confirm that Authentik correctly signs the token and routes you back to the Coolify dashboard with the appropriate user profile attributes generated.

Conclusion: A Resilient, Centralized Future

Integrating Authentik with Coolify using OpenID Connect represents a major advancement in securing your self-hosted infrastructure. By centralizing identity verification, you eliminate the risks associated with fragmented credential management, streamline onboarding and offboarding processes, and gain granular control over access. As infrastructure complexity grows, anchoring your ecosystem with robust, interoperable IAM standards like OIDC ensures that your platform remains agile, secure, and compliant with modern enterprise standards.

Centralized Identity Management: Implementing Authentik with OpenID Connect (OIDC) for Coolify Security | DPTCloud