specification: API Commons Plans specificationVersion: '0.1' schema: https://raw.githubusercontent.com/api-evangelist/interface-research/main/schema/api-commons.yml#/$defs/Plans provider: Authentik providerId: authentik generated: '2026-09-04' method: searched source: https://goauthentik.io/pricing modified: '2026-09-04' created: '2026-05-04' plan_count: 3 billing_model: per-user subscription for the product; the REST API is NOT separately metered or priced description: 'Authentik Security prices the authentik PRODUCT, not API calls. authentik is self-hosted open-source software: the full REST API (1,193 operations) ships in the free Open Source tier with no request quota, no per-call charge and no API-specific plan, because the operator runs the server on their own infrastructure. What the paid tiers buy is enterprise FEATURES and support, several of which happen to add API surface (agent accounts, privileged access management, the SSF provider, Google Workspace and Microsoft Entra providers). Prices below are verbatim from the pricing page.' notes: - The pricing FAQ states plainly that Authentik Security does not offer a hosted version of authentik, so there is no SaaS API endpoint to meter. - Support is tiered separately from features. Open Source gets "No support" (community Discord and GitHub Discussions only); Enterprise gets ticket-based support for subscriptions over $1k; Enterprise Plus gets dedicated support and contractual SLAs. - Service accounts are explicitly free of charge on the Enterprise tier — relevant to agent/automation use, since an agent account is a kind of service account. plans: - id: authentik-open-source name: Open Source type: free price: '0.00' currency: USD billing_period: none description: For homelab users and simple use cases. The full self-hosted authentik server, including the complete /api/v3 REST API. included: - Supports OIDC, SAML, LDAP, SCIM, RADIUS, Kerberos and Proxy - OpenID Certified™ for OpenID Connect - Web-based RDP/SSH access - OAuth 2.0 token exchange and key-bound ID tokens - Multi-account switching - Custom object attributes for users, groups and more - Covers B2B and B2C use cases - AKQL search query language (open-sourced in release 2026.5) support: Community Discord. No support. api_quota: none — self-hosted, bounded only by the operator's own infrastructure signup: https://docs.goauthentik.io/install-config/ - id: authentik-enterprise name: Enterprise type: paid price: '5.00' currency: USD billing_period: month unit: internal user billing_note: Billed annually. No cost for service accounts. overage: label: External users price: '0.02' currency: USD unit: external user period: month definition: 'An external user is typically a customer, partner or client accessing your digital services. External users cannot access the application dashboard and only use authentik in the background to provide SSO to applications.' description: For access to enterprise functionality. Everything in Open Source, plus the licensed feature set. included: - Privileged Access Management - Agent accounts for non-human identity - Google Workspace integration - Microsoft Entra ID integration - Client certificate authentication (mTLS) - Chrome Enterprise Device Trust connector - Shared Signals Framework (ABM) support - Password history compliance checks - Enhanced audit logging for compliance - Scheduled user offboarding - Embed external OAuth/SAML sources - OAuth2 authentication in SCIM - Windows local device login - Self-hosted event maps - Exportable CSV reports - RADIUS EAP-TLS - Advanced device compliance (in development) support: Ticket-based support for subscriptions over $1k. api_quota: none — self-hosted signup: https://customers.goauthentik.io - id: authentik-enterprise-plus name: Enterprise Plus type: enterprise price: '20000' price_qualifier: Starting at $20k annually currency: USD billing_period: year description: For custom contracts and expert support. Everything in Enterprise, plus commercial terms. included: - Billing and purchase via invoice - Dedicated, customized support and SLAs - Volume discounts at thousands of users - Support for multi-instance deployments - FIPS compliance for FedRAMP requirements support: Dedicated, customized support and contractual SLAs. api_quota: none — self-hosted signup: Schedule a call (contact sales) maintainers: - FN: Kin Lane email: kin@apievangelist.com