Self-Hosting Penpot with Authentik SSO: Building a Secure, Open-Source Collaborative Design Server
Introduction
In the modern digital product development lifecycle, collaborative design tools have become indispensable. While proprietary cloud platforms have dominated the market, enterprises and privacy-conscious organizations increasingly seek self-hosted alternatives. Penpot has emerged as the premier open-source, web-based design and prototyping platform that bridges the gap between designers and developers using open web standards like SVG.
However, deploying a collaborative tool for a team requires robust user management. Securing your infrastructure with a centralized Identity Provider (IdP) is critical. This guide provides a comprehensive, step-by-step technical walkthrough on self-hosting Penpot on a Virtual Private Server (VPS) and integrating it with Authentik, an advanced open-source Single Sign-On (SSO) solution, using OpenID Connect (OIDC).
Why Combine Penpot and Authentik?
Deploying Penpot independently is highly effective, but managing isolated user databases across multiple self-hosted tools quickly introduces administrative overhead and security vulnerabilities. By layering Authentik over Penpot, you unlock enterprise-level advantages:
- Centralized Identity Management: Provision, de-provision, and audit user access from a single dashboard.
- Enhanced Security: Enforce Multi-Factor Authentication (MFA), password complexities, and conditional access policies before users ever reach the design environment.
- Seamless User Experience: Designers and stakeholders log in via a single click using existing corporate credentials.
Prerequisites and System Architecture
Before initiating the deployment, ensure your environment meets the following baseline requirements:
- VPS Specifications: A minimum of 2 vCPUs, 4GB RAM (8GB recommended for larger teams), and 20GB of SSD storage running Ubuntu 22.04 LTS or later.
- Domain Names: Two registered domains or subdomains pointed via A/AAAA records to your VPS IP address (e.g.,
design.yourcompany.comfor Penpot andauth.yourcompany.comfor Authentik). - Installed Software: Docker Engine (v20.10+) and Docker Compose (v2.0+) configured on the host machine.
- Reverse Proxy: An operational Nginx, Traefik, or Caddy instance to handle SSL termination. This guide assumes Nginx or automated Let's Encrypt certificates via Docker.
Step 1: Deploying Authentik SSO
If you do not already have an active Authentik instance, it must be deployed first to generate the necessary OIDC credentials. Create a dedicated directory and download the official docker-compose manifest.
1.1 Environment Setup
Run the following commands on your VPS terminal:
mkdir -p /opt/authentik && cd /opt/authentik
curl -sO [https://goauthentik.io/docker-compose.yml](https://goauthentik.io/docker-compose.yml)Generate a secure secret key and database password, then write them to an .env file:
echo "AUTHENTIK_SECRET_KEY=$(openssl rand -base64 36)" >> .env
echo "AUTHENTIK_POSTGRESQL__PASSWORD=$(openssl rand -base64 18)" >> .env1.2 Launching the Services
Execute docker compose up -d to start the Authentik frontend, backend, worker, and PostgreSQL/Redis dependencies. Access the initialization portal at http:// to create your administrative account and configure your core domain (e.g., auth.yourcompany.com).
Step 2: Configuring the OIDC Provider in Authentik
With Authentik running, we must construct the cryptographic pipeline that allows Penpot to delegate authentication requests safely.
- Log into the Authentik Admin Interface and navigate to Applications > Providers.
- Click Create, select OAuth2/OpenID Provider, and click Next.
- Configure the Provider settings with precision:
- Name: Penpot Authentication
- Authentication Flow: default-authentication-flow (or your custom login flow)
- Authorization Flow: default-provider-authorization-implicit-consent
- Client Type: Confidential
- Redirect URIs:
[https://design.yourcompany.com/api/auth/oauth/authentik/callback](https://design.yourcompany.com/api/auth/oauth/authentik/callback)
- Save the provider. Note down the generated Client ID and Client Secret; these are vital for the Penpot configuration.
- Navigate to Applications > Applications, click Create, assign a name (e.g., "Penpot Design Portal"), enter a slug (
penpot), and bind it to the Provider you just created.
Security Tip: Ensure the Redirect URI precisely matches your Penpot domain and uses HTTPS. Mixed content or HTTP endpoints will cause modern browsers to block OIDC callbacks due to strict SameSite cookie policies.---
Step 3: Deploying Penpot via Docker Compose
Penpot utilizes a multi-container architecture consisting of a frontend server, a backend API service, an asynchronous task worker, a PostgreSQL database, and a Redis instance for caching. We will build a customized docker-compose.yml tailored for OIDC integration.
3.1 The Compose Configuration
Create a directory at /opt/penpot and generate your deployment manifest:
version: "3.5"
services:
penpot-postgres:
image: postgres:15-alpine
restart: always
volumes:
- penpot_postgres_data:/var/lib/postgresql/data
environment:
- POSTGRES_DB=penpot
- POSTGRES_USER=penpot
- POSTGRES_PASSWORD=secure_db_password_here
penpot-redis:
image: redis:7-alpine
restart: always
penpot-backend:
image: penpotapp/backend:latest
restart: always
volumes:
- penpot_assets:/opt/data
depends_on:
- penpot-postgres
- penpot-redis
environment:
- PENPOT_DATABASE_URI=postgresql://penpot:secure_db_password_here@penpot-postgres/penpot
- PENPOT_REDIS_URI=redis://penpot-redis:6379/0
- PENPOT_PUBLIC_URI=[https://design.yourcompany.com](https://design.yourcompany.com)
## OIDC Authentication Configurations ##
- PENPOT_OAUTH_AUTHENTIK_CLIENT_ID=your_authentik_client_id_here
- PENPOT_OAUTH_AUTHENTIK_CLIENT_SECRET=your_authentik_client_secret_here
- PENPOT_OAUTH_AUTHENTIK_AUTH_URI=[https://auth.yourcompany.com/application/o/authorize/](https://auth.yourcompany.com/application/o/authorize/)
- PENPOT_OAUTH_AUTHENTIK_TOKEN_URI=[https://auth.yourcompany.com/application/o/token/](https://auth.yourcompany.com/application/o/token/)
- PENPOT_OAUTH_AUTHENTIK_USER_INFO_URI=[https://auth.yourcompany.com/application/o/userinfo/](https://auth.yourcompany.com/application/o/userinfo/)
- PENPOT_OAUTH_AUTHENTIK_ROLES_KEY=roles
## Registration Control ##
- PENPOT_REGISTRATION_ENABLED=false
penpot-frontend:
image: penpotapp/frontend:latest
restart: always
ports:
- "8080:80"
depends_on:
- penpot-backend
volumes:
- penpot_assets:/opt/data
volumes:
penpot_postgres_data:
penpot_assets:3.2 Disabling Standard Registration
Notice the flag PENPOT_REGISTRATION_ENABLED=false in the backend environment definitions. This is a critical security measure. By disabling public registrations, you guarantee that only users authorized inside your Authentik directory can provision accounts on your Penpot server, creating a closed corporate ecosystem.
Step 4: Executing the Deployment and Verification
With the environment file populated with your authenticating domain records and cryptographic keys, pull and deploy the images:
cd /opt/penpot
docker compose pull
docker compose up -dMonitor the orchestration process with docker compose logs -f backend to confirm database migrations complete without errors.
Testing the Authentication Pipeline
Open an incognito browser window and navigate to [https://design.yourcompany.com](https://design.yourcompany.com). You will be greeted by the Penpot login screen, which now prominently displays a "Login with Authentik" option. Clicking this button redirects your browser to auth.yourcompany.com. Upon inputting valid credentials and completing any required MFA steps, Authentik securely hands off a token package to Penpot, instantly launching you into your workspace.
Conclusion
By self-hosting Penpot and integrating it natively with Authentik SSO, you achieve a sophisticated enterprise design environment that balances creative freedom with meticulous data governance. Your team retains absolute ownership over their intellectual property, design assets, and user data, while benefiting from top-tier security engineering. Maintain your infrastructure through scheduled backups of the Docker volumes, and regularly audit your Authentik logs to verify continuous system integrity.
