Back to articles
Technology Insight

Self-Hosting Penpot with Authentik SSO: Building a Secure, Open-Source Collaborative Design Server

May 30, 2026

Introduction

In the modern digital product development lifecycle, collaborative design tools have become indispensable. While proprietary cloud platforms have dominated the market, enterprises and privacy-conscious organizations increasingly seek self-hosted alternatives. Penpot has emerged as the premier open-source, web-based design and prototyping platform that bridges the gap between designers and developers using open web standards like SVG.

However, deploying a collaborative tool for a team requires robust user management. Securing your infrastructure with a centralized Identity Provider (IdP) is critical. This guide provides a comprehensive, step-by-step technical walkthrough on self-hosting Penpot on a Virtual Private Server (VPS) and integrating it with Authentik, an advanced open-source Single Sign-On (SSO) solution, using OpenID Connect (OIDC).

Why Combine Penpot and Authentik?

Deploying Penpot independently is highly effective, but managing isolated user databases across multiple self-hosted tools quickly introduces administrative overhead and security vulnerabilities. By layering Authentik over Penpot, you unlock enterprise-level advantages:

  • Centralized Identity Management: Provision, de-provision, and audit user access from a single dashboard.
  • Enhanced Security: Enforce Multi-Factor Authentication (MFA), password complexities, and conditional access policies before users ever reach the design environment.
  • Seamless User Experience: Designers and stakeholders log in via a single click using existing corporate credentials.
---

Prerequisites and System Architecture

Before initiating the deployment, ensure your environment meets the following baseline requirements:

  • VPS Specifications: A minimum of 2 vCPUs, 4GB RAM (8GB recommended for larger teams), and 20GB of SSD storage running Ubuntu 22.04 LTS or later.
  • Domain Names: Two registered domains or subdomains pointed via A/AAAA records to your VPS IP address (e.g., design.yourcompany.com for Penpot and auth.yourcompany.com for Authentik).
  • Installed Software: Docker Engine (v20.10+) and Docker Compose (v2.0+) configured on the host machine.
  • Reverse Proxy: An operational Nginx, Traefik, or Caddy instance to handle SSL termination. This guide assumes Nginx or automated Let's Encrypt certificates via Docker.
---

Step 1: Deploying Authentik SSO

If you do not already have an active Authentik instance, it must be deployed first to generate the necessary OIDC credentials. Create a dedicated directory and download the official docker-compose manifest.

1.1 Environment Setup

Run the following commands on your VPS terminal:

mkdir -p /opt/authentik && cd /opt/authentik
curl -sO [https://goauthentik.io/docker-compose.yml](https://goauthentik.io/docker-compose.yml)

Generate a secure secret key and database password, then write them to an .env file:

echo "AUTHENTIK_SECRET_KEY=$(openssl rand -base64 36)" >> .env
echo "AUTHENTIK_POSTGRESQL__PASSWORD=$(openssl rand -base64 18)" >> .env

1.2 Launching the Services

Execute docker compose up -d to start the Authentik frontend, backend, worker, and PostgreSQL/Redis dependencies. Access the initialization portal at http://:9000/if/flow/initial-setup/ to create your administrative account and configure your core domain (e.g., auth.yourcompany.com).

---

Step 2: Configuring the OIDC Provider in Authentik

With Authentik running, we must construct the cryptographic pipeline that allows Penpot to delegate authentication requests safely.

  1. Log into the Authentik Admin Interface and navigate to Applications > Providers.
  2. Click Create, select OAuth2/OpenID Provider, and click Next.
  3. Configure the Provider settings with precision:
    • Name: Penpot Authentication
    • Authentication Flow: default-authentication-flow (or your custom login flow)
    • Authorization Flow: default-provider-authorization-implicit-consent
    • Client Type: Confidential
    • Redirect URIs: [https://design.yourcompany.com/api/auth/oauth/authentik/callback](https://design.yourcompany.com/api/auth/oauth/authentik/callback)
  4. Save the provider. Note down the generated Client ID and Client Secret; these are vital for the Penpot configuration.
  5. Navigate to Applications > Applications, click Create, assign a name (e.g., "Penpot Design Portal"), enter a slug (penpot), and bind it to the Provider you just created.
Security Tip: Ensure the Redirect URI precisely matches your Penpot domain and uses HTTPS. Mixed content or HTTP endpoints will cause modern browsers to block OIDC callbacks due to strict SameSite cookie policies.
---

Step 3: Deploying Penpot via Docker Compose

Penpot utilizes a multi-container architecture consisting of a frontend server, a backend API service, an asynchronous task worker, a PostgreSQL database, and a Redis instance for caching. We will build a customized docker-compose.yml tailored for OIDC integration.

3.1 The Compose Configuration

Create a directory at /opt/penpot and generate your deployment manifest:version: "3.5" services: penpot-postgres: image: postgres:15-alpine restart: always volumes: - penpot_postgres_data:/var/lib/postgresql/data environment: - POSTGRES_DB=penpot - POSTGRES_USER=penpot - POSTGRES_PASSWORD=secure_db_password_here penpot-redis: image: redis:7-alpine restart: always penpot-backend: image: penpotapp/backend:latest restart: always volumes: - penpot_assets:/opt/data depends_on: - penpot-postgres - penpot-redis environment: - PENPOT_DATABASE_URI=postgresql://penpot:secure_db_password_here@penpot-postgres/penpot - PENPOT_REDIS_URI=redis://penpot-redis:6379/0 - PENPOT_PUBLIC_URI=[https://design.yourcompany.com](https://design.yourcompany.com) ## OIDC Authentication Configurations ## - PENPOT_OAUTH_AUTHENTIK_CLIENT_ID=your_authentik_client_id_here - PENPOT_OAUTH_AUTHENTIK_CLIENT_SECRET=your_authentik_client_secret_here - PENPOT_OAUTH_AUTHENTIK_AUTH_URI=[https://auth.yourcompany.com/application/o/authorize/](https://auth.yourcompany.com/application/o/authorize/) - PENPOT_OAUTH_AUTHENTIK_TOKEN_URI=[https://auth.yourcompany.com/application/o/token/](https://auth.yourcompany.com/application/o/token/) - PENPOT_OAUTH_AUTHENTIK_USER_INFO_URI=[https://auth.yourcompany.com/application/o/userinfo/](https://auth.yourcompany.com/application/o/userinfo/) - PENPOT_OAUTH_AUTHENTIK_ROLES_KEY=roles ## Registration Control ## - PENPOT_REGISTRATION_ENABLED=false penpot-frontend: image: penpotapp/frontend:latest restart: always ports: - "8080:80" depends_on: - penpot-backend volumes: - penpot_assets:/opt/data volumes: penpot_postgres_data: penpot_assets:

3.2 Disabling Standard Registration

Notice the flag PENPOT_REGISTRATION_ENABLED=false in the backend environment definitions. This is a critical security measure. By disabling public registrations, you guarantee that only users authorized inside your Authentik directory can provision accounts on your Penpot server, creating a closed corporate ecosystem.

---

Step 4: Executing the Deployment and Verification

With the environment file populated with your authenticating domain records and cryptographic keys, pull and deploy the images:

cd /opt/penpot
docker compose pull
docker compose up -d

Monitor the orchestration process with docker compose logs -f backend to confirm database migrations complete without errors.

Testing the Authentication Pipeline

Open an incognito browser window and navigate to [https://design.yourcompany.com](https://design.yourcompany.com). You will be greeted by the Penpot login screen, which now prominently displays a "Login with Authentik" option. Clicking this button redirects your browser to auth.yourcompany.com. Upon inputting valid credentials and completing any required MFA steps, Authentik securely hands off a token package to Penpot, instantly launching you into your workspace.

---

Conclusion

By self-hosting Penpot and integrating it natively with Authentik SSO, you achieve a sophisticated enterprise design environment that balances creative freedom with meticulous data governance. Your team retains absolute ownership over their intellectual property, design assets, and user data, while benefiting from top-tier security engineering. Maintain your infrastructure through scheduled backups of the Docker volumes, and regularly audit your Authentik logs to verify continuous system integrity.

Self-Hosting Penpot with Authentik SSO: Building a Secure, Open-Source Collaborative Design Server | DPTCloud