goauthentik / goauthentik/authentik

Inter Brand/Domain Authentication

Open
#13,717 0 comments 4 reactions 0 assignees View on GitHub
question
Dominant language
Python
Stars
25.6k
Forks
2k
Avg merge
1d 2h
Merged PRs (30d)
651

Description

**Describe your question/**
How to authenticate between Brands/Domains on the same Authentik instance

**Relevant info**
I have multiple clients, each client has his own set of applications under a Application Group.
Each client auth.domain is pointed to an Authentik Brand.
Some applications are shared between clients, so when a client is authenticated with his domain/brand, example auth.domain1 and he is accessing a shared application on auth.domain2 he is asked to re-authenticate with that domain ( auth.domain2 ), how can i allow him to sign in to the shared app without re-authentication?

Additionally, i have noticed that shared application using SAML provider does not have this issue, and the user does not need to re-authenticate across domains/brands.
Application thats uses openID requires re-authentication

Apologies if this seems a basic question, i am new to Authentik and IdP in general, appreciate your feedback

Thank you

- authentik version: 2025.2.2
- Deployment: docker-compose

Contributor guide

Open the contributing guide

Research direction

No file, test, or entry point is named. Start by reviewing the brand and domain configuration for the shared application, then compare the SAML provider behavior with the OpenID flow described for authentik 2025.2.2. Done means documenting whether cross-brand OpenID authentication can reuse an existing session and which configuration or limitation explains the re-authentication.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker-compose
Domain
authentication, authorization
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.