Casdoor vs. Authentik
Authentik and Casdoor are both popular choices for self-hosted single sign-on, from homelabs to company deployments. Both provide OIDC, SAML, LDAP access, and a web admin console. The main differences are the runtime, how login is modeled, and what is included in the open-source edition.
Summary
| Casdoor | Authentik | |
|---|---|---|
| Backend | Go, single binary | Python (Django) server and worker, with Go outposts |
| Database | MySQL, MariaDB, PostgreSQL, SQL Server, Oracle, SQLite, and others | PostgreSQL |
| License | Apache-2.0 | MIT for the core; some features require the paid Enterprise edition |
| Login modeling | Per-application sign-in and sign-up pages configured in the UI | Flows built from stages and policies |
| OAuth 2.0, OIDC, SAML | Yes | Yes |
| CAS | Built in | No |
| LDAP and RADIUS for legacy clients | Served by the Casdoor process | Served by separate outposts |
| Protecting apps without their own login | Sites reverse proxy, plus forward-auth integrations for Nginx, Traefik, and Envoy | Proxy provider with outposts |
| AI agents and MCP | Built-in MCP server; OAuth 2.1 authorization server for MCP | Standard OAuth |
Architecture and operations
Authentik runs a server container and a worker container backed by PostgreSQL. Features such as the LDAP provider, the RADIUS provider, and the proxy provider run as additional outpost containers that Authentik manages.
Casdoor is one Go process and a database. LDAP, RADIUS, CAS, SAML, and OIDC are all served by that process. For a quick look:
docker run -p 8000:8000 casbin/casdoor-all-in-one
Fewer moving parts matters most on small machines and when something breaks at night.
Flows versus pages
Authentik's central idea is the flow: an ordered list of stages (identification, password, MFA, consent, and so on) with policies bound to them. It is very flexible. You can express almost any login logic, and the cost is a model you need to learn before your first custom login works.
Casdoor is more direct. Each application has a sign-in page and a sign-up page. You pick the sign-in methods, the providers, the fields on the sign-up form, MFA rules, and the look of the page in the admin console. Most teams get the result they want faster, and there is less room to build something unusual.
Sign-in providers
Authentik supports the common social logins and generic OAuth, SAML, and LDAP sources.
Casdoor ships more than 70 OAuth providers, plus SAML, LDAP, and Web3 wallets. If your users sign in with WeChat, DingTalk, Lark, Alipay, or QQ, Casdoor supports them without extra work.
Reverse-proxy authentication
Authentik's proxy provider is well loved by homelab users: it puts a login in front of applications that have none.
Casdoor offers two routes to the same result. Sites is a built-in reverse proxy with TLS certificates and traffic rules. If you already run a proxy, use the integrations for Nginx, Traefik, or Envoy.
Licensing
Casdoor's repository is Apache-2.0 throughout.
Authentik's core is MIT-licensed, and a set of features is reserved for the Enterprise edition. Check Authentik's current pricing page for the list, because it changes between releases.
AI agents and MCP
Casdoor exposes its management API as an MCP server and acts as an OAuth 2.1 authorization server for third-party MCP servers, with Dynamic Client Registration, PKCE, and resource indicators. If you are putting authentication in front of MCP tools, this is ready to use.
When to choose which
Choose Authentik if you want to design login logic as flows with policies, or you already rely on its proxy outposts.
Choose Casdoor if you want a single small service, more built-in sign-in providers, a CAS server, a choice of databases, an Apache-2.0 license for every feature in the repository, or built-in MCP support.
See also the comparison overview.