Dedicated instance · Hosted in Germany · DPA included

Managed Authentik hosting
from German data centers.

Your own Authentik instance, operated rather than maintained by you. Single sign-on, MFA and user management for your applications, without anyone on your side looking after PostgreSQL, Redis and worker containers.

  • Dedicated instance, not a shared tenant
  • No per-user fees
  • Data processing agreement included
  • Cancel monthly
GDPR-compliant
8 Regions Worldwide
Open Source & auditable
24/7 Monitoring
ISO 27001 data centers, plus BSI C5 in DE

What Authentik is built for

An identity provider is the place where your people sign in once and get into everything afterwards. Authentik is the open source version of that.

  1. 01

    Instead of maintaining separate accounts in every application, there is one directory. Whoever is disabled there is locked out everywhere, immediately and verifiably. That is the point where identity management stops being a convenience topic and becomes a question of access control.

  2. 02

    Authentik speaks the protocols that matter: OAuth2 and OpenID Connect for modern applications, SAML 2.0 for everything that grew historically inside companies, and an LDAP outpost for software that speaks neither. Through the application proxy, even applications without any login of their own can be protected.

  3. 03

    Compared to the commercial vendors, the difference is less about features than about billing. Okta, Auth0 and Entra charge per user, and the invoice grows with the team. Authentik is open source under the MIT licence; there is no user licence that scales.

What your instance can do

The full scope of the open source version. None of it is locked behind a plan with us.

Single sign-on

One login for every application, via OAuth2, OpenID Connect, SAML 2.0 or proxy-based authentication. Federation to Google, Entra ID or GitHub included.

Multi-factor authentication

TOTP, WebAuthn and passkeys, plus email OTP. Optionally SMS via Twilio and Duo. Passkeys are the move away from SMS that Microsoft is making as well.

LDAP outpost

A full LDAP server as an outpost. It connects legacy applications that speak neither OIDC nor SAML, without touching their code.

SCIM provisioning

Users are created, updated and deactivated automatically in connected systems. The lifecycle runs through one place instead of ten interfaces.

RADIUS outpost

Authentication for VPN, Wi-Fi and switches against the same directory. No second user base for the network layer.

Application proxy

Applications without their own login get authentication placed in front of them. Internal tools become publishable without being rebuilt.

Configurable flows

Login, registration and password reset are assembled as a flow rather than programmed. Conditions such as mandatory MFA for certain groups are part of it.

Audit logs

Every authentication event is logged and can be exported, for example into a SIEM. For evidence under ISO 27001 or NIS2 that is the basis.

Your own branding

Login pages with your logo, your colours and your wording. Configured in the interface, no code changes involved.

Transparent pricing. No surprises.

Start your own instance in 5 minutes. No per-user fees in any plan.

Select Region

Support

S

Instance size
9,990.00per month

excl. VAT

  • 2 vCPU
  • 4 GB RAM
  • 80 GB NVMe
  • 20 TB traffic

Support: Standard

  • 24-hour response
  • Mon to Fri, 08:00 to 17:00 CET/CEST
  • Ticket system, intake by email
Get started

7-day trial. Credit card required, converts to a paid plan automatically, cancel monthly.

M

Instance size
14,990.00per month

excl. VAT

  • 4 vCPU
  • 8 GB RAM
  • 160 GB NVMe
  • 20 TB traffic

Support: Standard

  • 24-hour response
  • Mon to Fri, 08:00 to 17:00 CET/CEST
  • Ticket system, intake by email
Get started

7-day trial. Credit card required, converts to a paid plan automatically, cancel monthly.

L

Instance size
24,990.00per month

excl. VAT

  • 8 vCPU
  • 16 GB RAM
  • 320 GB NVMe
  • 20 TB traffic

Support: Standard

  • 24-hour response
  • Mon to Fri, 08:00 to 17:00 CET/CEST
  • Ticket system, intake by email
Get started

7-day trial. Credit card required, converts to a paid plan automatically, cancel monthly.

The instance is sized to your use case. When a size stops being enough, we move you up during operation. Outside Germany, size L has 6 instead of 8 vCPU; the other specs are identical.

Features

  • SSO via OIDC, OAuth2 and SAML 2.0
  • MFA: TOTP, WebAuthn and passkeys, email OTP
  • LDAP outpost for legacy applications
  • RADIUS outpost for VPN, Wi-Fi and switches
  • SCIM provisioning
  • Application proxy for apps without their own login
  • Remote access gateway for RDP, SSH and VNC
  • Flows, policies and user directory
  • Federation to Google, Entra ID and GitHub

Included in every size

  • Dedicated instance, no shared hosting
  • Users with no count limit
  • Subdomain included (*.authhost.de)
  • Your own domain possible
  • PostgreSQL included
  • 99.9 % availability commitment
  • Automatic backups and updates
  • 24/7 monitoring
  • Hosted in Germany
  • Data processing agreement included
  • No setup fee, cancel monthly

All prices are net, plus statutory VAT. This offer is directed exclusively at businesses within the meaning of § 14 German Civil Code, not at consumers.

What operations include

Running Authentik yourself is doable. What costs time is not the installation, it is everything after it.

Updates across the stack

Authentik ships monthly. What gets patched is the application, PostgreSQL, Redis and the worker containers, not just the obvious piece.

Automatic backups

Backups run automatically and stay in the same region as the instance. An identity provider without a working restore is a single point of failure.

24/7 monitoring

Availability and system metrics are monitored continuously. When login fails, everything on your side stops, which makes this the most critical component in the house.

99.9 % SLA

The 99.9 % availability commitment applies to every size. Support responds within 24 hours, 4 hours or 30 minutes, depending on the tier.

Your own domain and certificates

A subdomain under authhost.de is included, your own domain with your own certificate on request. The login page then carries your name.

No lock-in

Authentik is MIT licensed. A complete export including the database is available at any time, and the path back to self-operation stays open.

Have it operated, run it yourself, or rent per user

Three routes to the same goal. This table also says when renting the operation is the wrong call.

authhostSelf-operatedPer-user SaaS
Entry costFrom 99.90 € per monthServer plus setupPer user per month
Ongoing operationsWith the providerYour own teamWith the provider
Cost as you growFlat per planFlatGrows with every user
InstanceDedicatedDedicatedShared tenant
Place of processingGermany, 7 further regionsYour data centreProvider region
Availability commitment99.9 %Your ownPer provider
FitsProduction without an ops teamTeams with their own ops crewSmall teams with a stable headcount

Honestly: if you already have a team that runs PostgreSQL, Redis and containers in their sleep, self-operation is cheaper on paper. And at five users, per-user SaaS beats any flat rate. Renting the operation pays off in between, and the tipping point against per-user models sits at roughly 15 to 25 users depending on the vendor.

Data location and processing

The German region runs in data centers with ISO 27001 and BSI C5, the other seven regions in data centers with ISO 27001 and SOC 2 Type II. Germany is the default region.

An identity provider holds personal data by definition: names, email addresses, group memberships and the full login history. That makes you the controller and us the processor. A data processing agreement under Article 28 GDPR is part of every plan and also governs who can access your instance administratively, and under which conditions.

Inside the EU, Germany and the Netherlands avoid a third-country transfer entirely. Outside the EU the choice of region becomes a compliance decision, one we walk through with you before you start.

How you get to your instance

From signup to the first connected application it takes four steps.

  1. 1

    Start the instance

    Pick plan and region, the instance is provisioned. The trial runs for 7 days and a credit card is required at signup.

  2. 2

    Create or connect users

    Create users manually, import them from an existing source, or federate to Entra ID, Google or an existing LDAP directory.

  3. 3

    Connect the first application

    Create a provider, put client ID and secret into the application, done. For applications without their own login, the application proxy takes over.

  4. 4

    Hand over operations

    After the trial the instance converts automatically to the selected plan. Updates, backups and monitoring are ours from then on.

Frequently asked questions about managed Authentik hosting

What does managed Authentik hosting cost?+

The price comes from two choices: instance size and support tier. The smallest size costs 99.90 € per month net in Germany, with 2 vCPU, 4 GB RAM, 80 GB NVMe and 20 TB of traffic. Size M is 149.90 €, size L is 249.90 €. The Business support tier adds 100 €, Enterprise adds 350 €. Billing is per plan, not per user. There is no setup fee and no minimum term.

How many users does a plan support?+

Authentik itself has no user limit; there is no licence counting seats. The constraint is how the instance is sized: CPU, memory and above all login volume. That is why the plans state the specification rather than a guessed user count. When a size stops carrying the load, we move you up during operation.

Can I migrate my existing Authentik instance?+

Yes. It is the same software, so users, groups, providers, applications and flows carry over. The usual route is a database dump of your existing instance which we import; afterwards you only adjust the redirect URIs in the connected applications. We help with larger estates.

Do I get a data processing agreement?+

Yes, included in every plan. Request it in the portal or by email and you get it ready to sign. It covers subject matter, duration, nature and purpose of the processing, the categories of data subjects and the technical and organisational measures.

Which applications can I connect?+

Anything speaking OAuth2, OpenID Connect or SAML 2.0, which covers the large majority of modern software. For legacy applications there is the LDAP outpost, for network gear the RADIUS outpost, and for applications with no login at all the application proxy. In practice, little is left that cannot be connected.

What happens if Authentik goes down?+

Then nobody gets into the connected applications, which is the uncomfortable truth about centralised login. That is why every size carries a 99.9 % availability commitment, plus 24/7 monitoring. For emergencies, keep a local break-glass administrator in your critical systems; we recommend that regardless of provider.

Where is the data stored?+

In the default configuration, Germany, in data centers with ISO 27001 and BSI C5. Seven further regions are available. This covers the instance itself, the PostgreSQL database holding users and login history, and the automatic backups.

What happens after the trial?+

The trial runs for 7 days. A credit card is required at signup, and when it ends the trial converts automatically into the selected paid plan. If you do not want to continue, cancel in the portal beforehand.

Have Authentik operated for you

Start the 7-day trial, or discuss up front which applications and user sources you want to connect. A credit card is required at signup, and the trial converts automatically into the selected plan afterwards.