Back to articles
Technology Insight

Self-Hosting Penpot with Authentik SSO on a VPS: The Ultimate Guide to Secure, Open-Source Collaborative Design

May 30, 2026

Introduction: Why Self-Host Your Design Infrastructure?

In the modern digital landscape, design collaboration is a core pillar of product development. While proprietary SaaS platforms have long dominated the market, concerns regarding data sovereignty, escalating licensing costs, and vendor lock-in have driven enterprises toward open-source alternatives. Enter Penpot, the premier open-source, web-based design and prototyping platform that utilizes open standards like SVG.

However, deploying a collaborative tool in an enterprise environment requires robust security and centralized user management. By pairing Penpot with Authentik, an advanced open-source Identity Provider (IdP), you can achieve seamless Single Sign-On (SSO) authentication. This guide provides an exhaustive, production-ready blueprint for deploying Penpot integrated with Authentik SSO on a Virtual Private Server (VPS).

Prerequisites and System Architecture

Before initiating the deployment, ensure your environment meets the following technical requirements:

  • A Linux VPS: Running Ubuntu 22.04 LTS or 24.04 LTS with at least 4 vCPUs, 8GB RAM, and 50GB of SSD storage.
  • Domain Names: Two registered domains or subdomains pointing to your VPS IP address (e.g., design.yourcompany.com for Penpot and auth.yourcompany.com for Authentik).
  • Software Dependencies: Docker Engine (v24.0+) and Docker Compose (v2.0+) installed on the host system.
  • Network Accessibility: Ports 80 (HTTP) and 443 (HTTPS) must be open and unblocked by firewalls (UFW/Security Groups).
Note: A reverse proxy such as Nginx, Traefik, or Caddy is highly recommended to handle SSL termination and route traffic efficiently to the Docker containers.

Step 1: Deploying and Configuring Authentik

Authentik will serve as the centralized authentication authority. To deploy Authentik via Docker Compose, navigate to your directory of choice and create a dedicated folder structure.

1.1 Create the Authentik Compose File

Download the official docker-compose template or create one structured to utilize PostgreSQL and Redis. Your configuration should isolate Authentik within a dedicated Docker bridge network.

1.2 Generate Secret Keys

Run the following commands to generate secure passwords and the core secret key required by Authentik:

openssl rand -base64 36
echo "AUTHENTIK_SECRET_KEY=$(openssl rand -hex 32)" >> .env

Once your .env file is configured with database credentials and secret keys, initialize the database and spin up the containers using:

docker compose up -d

Navigate to [https://auth.yourcompany.com/if/admin/#/initial-setup](https://auth.yourcompany.com/if/admin/#/initial-setup) to create your administrative account and log into the Authentik Admin Interface.

Step 2: Configuring the OIDC Provider in Authentik

Penpot connects to external identity providers using the OpenID Connect (OIDC) protocol. We must define Penpot as an Application and a Provider within Authentik.

  1. Navigate to Applications > Providers in the Authentik admin sidebar and click Create.
  2. Select OAuth2/OpenID Provider and configure the following parameters:
    • Name: Penpot Authentication
    • Authentication flow: default-authentication-flow
    • Authorization flow: default-authorization-flow
    • Client Type: Confidential
    • Redirect URIs: [https://design.yourcompany.com/api/auth/oauth/authentik/callback](https://design.yourcompany.com/api/auth/oauth/authentik/callback)
  3. Save the configuration and take note of the generated Client ID and Client Secret.
  4. Go to Applications > Applications, click Create, name it "Penpot", assign it the provider you just created, and save.

Step 3: Deploying Penpot with Docker Compose

Penpot consists of several microservices: the frontend, backend, asynchronous worker, Redis for caching, and PostgreSQL for persistent storage. We will configure Penpot to disable standard registration and force OIDC authentication through Authentik.

3.1 The Penpot Configuration (docker-compose.yaml)

Create a dedicated directory for Penpot and pull the official docker-compose file. Modify the environment variables within your configuration file to integrate the Authentik credentials:

PENPOT_PUBLIC_URI=[https://design.yourcompany.com](https://design.yourcompany.com)

# Enable Registration & Login via OIDC
PENPOT_REGISTRATION_ENABLED=true
PENPOT_FLAGS="enable-login-with-oidc enable-registration-with-oidc"

# OIDC Configurations linked to Authentik
PENPOT_OIDC_CLIENT_ID=your_authentik_client_id_here
PENPOT_OIDC_CLIENT_SECRET=your_authentik_client_secret_here
PENPOT_OIDC_BASE_URI=[https://auth.yourcompany.com/application/o/penpot/](https://auth.yourcompany.com/application/o/penpot/)
PENPOT_OIDC_USERINFO_URI=[https://auth.yourcompany.com/application/o/userinfo/](https://auth.yourcompany.com/application/o/userinfo/)

# Optional: Disable Password-Based Login for Security
PENPOT_LOGIN_WITH_PASSWORD_ENABLED=false

Execute docker compose up -d to pull the official Penpot images and launch the design suite backend ecosystem.

Step 4: Nginx Reverse Proxy and SSL Integration

To securely route traffic over HTTPS, we deploy Nginx to act as the reverse proxy for both applications. Ensure your Let's Encrypt certificates are obtained via Certbot prior to finalizing the configuration files.

Example Nginx Blocks for Routing

The configuration ensures that websockets, vital for Penpot’s real-time collaborative features, function correctly:

server {
    listen 443 ssl http2;
    server_name design.yourcompany.com;

    ssl_certificate /etc/letsencrypt/live/[design.yourcompany.com/fullchain.pem](https://design.yourcompany.com/fullchain.pem);
    ssl_certificate_key /etc/letsencrypt/live/[design.yourcompany.com/privkey.pem](https://design.yourcompany.com/privkey.pem);

    location / {
        proxy_pass [http://127.0.0.1:6060](http://127.0.0.1:6060); # Penpot Frontend port
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;

        # Websocket support
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
    }
}

Reload Nginx using nginx -s reload to enforce the secure endpoints.

Step 5: Validation and Production Hardening

With both platforms configured, navigate to your Penpot domain: [https://design.yourcompany.com](https://design.yourcompany.com). You will be greeted with a "Login with Authentik" prompt. Clicking this button redirects you to your Authentik domain, verifies your corporate credentials, and securely logs you back into your workspace within Penpot.

Production Best Practices

  • Automated Backups: Implement cron jobs to execute pg_dump on the PostgreSQL containers daily, backing up critical vector assets and user states to remote S3-compatible storage.
  • Resource Limits: Impose strict limits on Penpot’s Docker containers within the compose file to prevent a rogue rendering thread from overwhelming the VPS CPU.
  • Security Policies: Enforce Multi-Factor Authentication (MFA) within Authentik to seamlessly guarantee that all access to the Penpot platform is tightly guarded.

Conclusion

By self-hosting Penpot alongside Authentik SSO, your organization secures a powerful, scalable, and independent collaborative design pipeline. You eliminate recurring per-user SaaS license fees while keeping critical intellectual property—your design files and user credentials—entirely within your private cloud infrastructure. This robust setup balances agility and ultimate enterprise control.

Self-Hosting Penpot with Authentik SSO on a VPS: The Ultimate Guide to Secure, Open-Source Collaborative Design | DPTCloud