← Back to all sparks
A

authentik

INFRA · APIS
Velocity6.3

Open-source identity provider and single sign-on platform

Authentik 2026.8 ships Actors — programmable event hooks that turn it from a static identity provider into a runtime for auth logic.

identity-access-managementauthenticationopen-sourceenterprise-securitycloud-infrastructure
Current state
Authentik is an open-source identity and access management platform on a monthly calendar-versioned release cycle. The 2026.8.0 release introduced Actors — event-driven code execution hooks in the auth flow, analogous to Auth0 Actions or Okta Hooks — and an authentik Agent for domain join scenarios. Three supported branches (2026.2.x, 2026.5.x, 2026.8.x) are receiving concurrent security and bug fix patches, reflecting an active enterprise user base running different versions.
Where it's heading
Actors is the directional move that matters in 2026.8: it repositions authentik from a configuration-driven identity provider toward a programmable auth runtime. Teams that previously needed custom LDAP flows or complex blueprints can now write Actors that fire on auth events — closer to the Auth0 model. The parallel development of an authentik Agent (documented in 2026.8.0-rc7) suggests the team is also targeting domain-joined enterprise device scenarios, which would expand the addressable market from web app auth into endpoint identity.
Prediction
The next release cycle will likely expand Actor trigger types and add a marketplace or community library for common Actor patterns (e.g., risk-based auth, adaptive MFA). The Agent feature will mature with more domain join scenarios, positioning authentik as a self-hosted alternative to Microsoft Entra ID for organizations that want full sovereignty over their identity stack.

Recent moves

  1. 5d ago

    authentik 2026.8.2 patch release

    2026.8.2 is a patch release for the current stable branch — bug and security fixes cherry-picked from the development branch. Part of the steady maintenance cadence that keeps three concurrent versions supported simultaneously.

    View source ↗
  2. 5d ago

    authentik 2026.5.7 backport patch

    2026.5.7 backports CI and security-related fixes to the 2026.5 branch. Routine maintenance for organizations still on the May release; no new functionality.

    View source ↗
  3. 5d ago

    authentik 2026.2.7: container image hardening backport

    2026.2.7 removes curl and runit from the container image as a backport to the February branch — a container hardening measure that reduces attack surface for self-hosters who haven't migrated off the 2026.2 track.

    View source ↗
  4. 14d ago

    authentik 2026.8.1 patch release

    2026.8.1 is the first patch on the 2026.8 branch, landing two weeks after GA — a fast patch cycle consistent with the team's response to issues found by early adopters of the Actors feature and new Agent functionality.

    View source ↗
  5. 27d ago

    Release 2026.8.0

    ⚡ SPARK

    Authentik 2026.8.0 GA ships Actors — event-driven code execution that fires on authentication events — alongside Object Attributes and the authentik Agent for domain join scenarios. Actors is the capability that repositions authentik from a configuration-driven IdP into a programmable auth runtime, directly closing the capability gap with Auth0's Actions and Okta's Hooks.

    View source ↗
  6. 1mo ago

    authentik 2026.8.0-rc7 pre-release

    The RC7 pre-release build that first integrated Actors and Agent documentation into the 2026.8 branch. A pre-release checkpoint rather than a production-ready release; the GA in 2026.8.0 is what matters for users.

    View source ↗