Skip to content
Halo

Compare

Halo vs authentik

How Halo compares with authentik: both are self-hosted identity providers. authentik is built around flows and outposts. Halo is built around workforce access, reviews, and SSH.
vs

Halo and authentik

Choose Halo when

  • The people in the directory are your workforce, and you need reviews and lifecycle rules, not a proxy in front of every app.
  • You want SCIM in both directions under the Apache-2.0 licence, without an enterprise add-on.
  • SSH certificates for hosts are part of the access decision, not a separate project.

Choose authentik when

  • You need an LDAP outpost or a forward-auth proxy in front of applications that have no OpenID Connect.
  • You want to assemble sign-in from flows and blueprints.
  • You are fine with the enterprise licence for the features that sit outside the MIT core, including inbound SCIM.

authentik

Halo and authentik, row by row.

Feature comparison
CapabilityHaloauthentik
How you run it
LicenceApache-2.0MIT core
Self-hostedYou run itYou run it
Hosted serviceNoneEnterprise
Published releaseNot yet
Sign-in
Passkeys and security keys
OpenID Connect
SAML 2.0
Workforce access
Conditional accessPoliciesFlows
Requests, reviews, lifecycleIncludedNot the product
SSH certificatesBuilt in
SCIMIn and outSplit by licence
LDAPNot a directory serverOutpost

Drawn from public documentation. Halo has not published a release yet. Corrections belong in the issue tracker.