goauthentik / goauthentik/authentik
Inter Brand/Domain Authentication
- Dominant language
- Python
- Stars
- 25.6k
- Forks
- 2k
- Avg merge
- 1d 2h
- Merged PRs (30d)
- 651
Description
**Describe your question/**
How to authenticate between Brands/Domains on the same Authentik instance
**Relevant info**
I have multiple clients, each client has his own set of applications under a Application Group.
Each client auth.domain is pointed to an Authentik Brand.
Some applications are shared between clients, so when a client is authenticated with his domain/brand, example auth.domain1 and he is accessing a shared application on auth.domain2 he is asked to re-authenticate with that domain ( auth.domain2 ), how can i allow him to sign in to the shared app without re-authentication?
Additionally, i have noticed that shared application using SAML provider does not have this issue, and the user does not need to re-authenticate across domains/brands.
Application thats uses openID requires re-authentication
Apologies if this seems a basic question, i am new to Authentik and IdP in general, appreciate your feedback
Thank you
- authentik version: 2025.2.2
- Deployment: docker-compose
Contributor guide
Research direction
No file, test, or entry point is named. Start by reviewing the brand and domain configuration for the shared application, then compare the SAML provider behavior with the OpenID flow described for authentik 2025.2.2. Done means documenting whether cross-brand OpenID authentication can reuse an existing session and which configuration or limitation explains the re-authentication.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker-compose
- Domain
- authentication, authorization
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100