Back to articles
Technology Insight

Securing Enterprise Document Workflows: Deploying Multi-User Stirling-PDF with Authentik OIDC on a Corporate VPS

May 27, 2026

Introduction: The Hidden Data Risks in Corporate Document Processing

In modern corporate environments, the accounting and finance departments serve as the central hub for sensitive information. From quarterly balance sheets and tax filings to payroll records and vendor contracts, nearly every critical document is processed, stored, and shared in PDF format. However, a significant operational vulnerability often goes unnoticed: the widespread reliance on public, third-party online PDF conversion utilities.

When employees upload confidential financial statements to free online PDF editors to merge pages or recognize text via OCR, corporate data leaves the company’s secure perimeter. This practice introduces severe compliance risks, potentially violating data protection regulations such as GDPR or local financial privacy laws. To mitigate these risks without hindering administrative efficiency, forward-thinking enterprises are turning to self-hosted alternatives. This technical guide details how to deploy Stirling-PDF (Multi-User Enterprise Edition) on a virtual private server (VPS), fully integrated with Authentik OIDC (OpenID Connect) for centralized single sign-on (SSO) and robust identity management.

Why Stirling-PDF and Authentik?

Before diving into the deployment architecture, it is essential to understand why this specific software stack represents the gold standard for corporate document management:

  • Stirling-PDF: A powerful, lightweight, self-hosted web application that mirrors all the functionalities of premium PDF suites. It allows users to split, merge, convert, re-organize, sign, and encrypt PDF files entirely within your own infrastructure. No data ever leaves your server.
  • Multi-User Functionality: Unlike standard open-source tools, the multi-user iteration allows corporate IT to isolate user spaces, track usage, and manage specific feature access permissions.
  • Authentik OIDC: An open-source Identity Provider (IdP) that unifies corporate authentication. By integrating Stirling-PDF with Authentik via OpenID Connect, enterprise users can log in using their existing corporate credentials, enabling automated onboarding, role-based access control (RBAC), and multi-factor authentication (MFA).
---

System Architecture and Prerequisites

To ensure optimal performance and security for an accounting department of 20 to 100 users, the following infrastructure baseline is recommended:

  • Hardware (VPS): 4 vCPUs, 8GB RAM, and 100GB NVMe SSD storage (OCR processing is CPU and RAM intensive).
  • Operating System: Ubuntu 22.04 LTS or Ubuntu 24.04 LTS.
  • Containerization: Docker Engine v24+ and Docker Compose v2.20+.
  • Networking: A fully qualified domain name (FQDN) mapped to the VPS IP address (e.g., pdf.yourcompany.com) and an SSL certificate managed via a reverse proxy like Nginx Proxy Manager or Traefik.
Security Note: Always ensure that your VPS firewall (e.g., UFW) blocks all unnecessary public ports, exposing only ports 80 (HTTP) and 443 (HTTPS) to the public internet.
---

Step-by-Step Deployment Guide

Step 1: Preparing the Docker Compose Environment

To maintain an organized infrastructure, we will use Docker Compose to orchestrate Stirling-PDF and its associated database. Connect to your VPS via SSH and execute the following commands to set up the directory structure:

mkdir -p /opt/stirling-pdf/config
cd /opt/stirling-pdf

Next, create a docker-compose.yml file. This configuration utilizes the official Stirling-PDF multi-user image and links it to a secure backend environment.

version: '3.8'

services:
  stirling-pdf:
    image: frooodle/s-pdf:latest
    container_name: stirling-pdf
    ports:
      - "8080:8080"
    volumes:
      - /opt/stirling-pdf/trainingData:/usr/share/tessdata
      - /opt/stirling-pdf/extraConfigs:/configs
      - /opt/stirling-pdf/logs:/logs
    environment:
      - DOCKER_ENABLE_SECURITY=true
      - SECURITY_ENABLE_OIDC=true
      - SECURITY_OIDC_ISSUER_URI=[https://auth.yourcompany.com/application/o/stirling-pdf/](https://auth.yourcompany.com/application/o/stirling-pdf/)
      - SECURITY_OIDC_CLIENT_ID=stirling-pdf-client-id
      - SECURITY_OIDC_CLIENT_SECRET=your_super_secret_client_key
      - SECURITY_OIDC_USER_NAME_KEY=preferred_username
      - SYSTEM_DEFAULT_LOCALE=en_GB
    restart: always

Step 2: Configuring Authentik as the Identity Provider

With the environment variables declared in the Docker Compose file, you must now configure the corresponding application and provider inside your Authentik administrative dashboard.

  1. Log in to Authentik: Navigate to your Authentik instance (e.g., [https://auth.yourcompany.com](https://auth.yourcompany.com)) and open the Admin Interface.
  2. Create a Provider: Go to Applications > Providers and click Create. Select OAuth2/OpenID Provider.
  3. Configure Provider Settings:
    • Name: Stirling-PDF Provider
    • Authentication flow: Select your default authorization flow.
    • Authorization flow: Select your explicit consent or implicit flow.
    • Client Type: Confidential
    • Redirect URIs: Enter [https://pdf.yourcompany.com/login/oauth2/code/oidc](https://pdf.yourcompany.com/login/oauth2/code/oidc)
  4. Create an Application: Navigate to Applications > Applications and click Create. Name it "Stirling-PDF", assign it a slug (e.g., stirling-pdf), and link it to the provider you created in the previous step.
  5. Retrieve Credentials: Copy the generated Client ID and Client Secret from the provider configuration page and update the respective fields in your VPS docker-compose.yml file.

Step 3: Launching the Application and Configuring Reverse Proxy

Once the environment variables are correctly aligned between Authentik and the Stirling-PDF container, launch the service by executing:

docker compose up -d

Verify that the container is running optimally by inspecting the logs: docker compose logs -f stirling-pdf. To expose the application securely to your accounting department, route your domain (pdf.yourcompany.com) through your enterprise reverse proxy, enforcing an upstream destination of http://localhost:8080 and enabling Let's Encrypt SSL certificates.

---

Optimizing Stirling-PDF for Corporate Accounting Workflows

Deploying the software is only the first phase. To maximize productivity within the finance department, specific configurations should be fine-tuned:

Advanced Optical Character Recognition (OCR)

Accounting teams continuously manage scanned invoices and receipts that lack searchable text layers. Stirling-PDF integrates Tesseract OCR natively. To ensure high-accuracy text extraction for localized invoicing, download the necessary language training data files (.traineddata) and place them directly into the /opt/stirling-pdf/trainingData directory. The application will automatically detect and enable these languages in the user interface.

Enforcing Data Retention Rules

To adhere to strict financial auditing standards, it is paramount that documents do not linger on the server indefinitely. Stirling-PDF processes files in-memory or via temporary directories. Ensure your configuration sets a aggressive cleanup interval for system storage, minimizing the application's data footprint and eliminating residual risks of data exposure in the event of a system compromise.

---

Conclusion: Balancing Security with Employee Productivity

Implementing a self-hosted, multi-user Stirling-PDF instance integrated with Authentik OIDC delivers an enterprise-grade document solution that satisfies both the compliance mandates of chief information security officers (CISOs) and the daily operational needs of accounting teams. By migrating document manipulation workflows away from public clouds and onto private infrastructure, organizations retain absolute ownership of their financial data, streamline credential management, and foster an efficient, secure digital workplace.

Securing Enterprise Document Workflows: Deploying Multi-User Stirling-PDF with Authentik OIDC on a Corporate VPS | DPTCloud