Get started with authentik Enterprise
Enable authentik Enterprise by installing a license key in the Admin interface. authentik Enterprise uses the same installation process and container images as the open source version; you do not need to reinstall authentik or deploy a separate Enterprise service.
authentik validates licenses locally. Installing and using a license does not require internet access. For an offline deployment, see air-gapped licensing.
Before you begin
You need a running, supported version of authentik and administrator access to its Admin interface. For a new deployment, install authentik first.
If you already have a license key for this deployment, skip to install the license key.
1. Copy the Install ID
A license is bound to an authentik deployment by its Install ID.
- Log in to the authentik Admin interface.
- Navigate to Enterprise > Licenses.
- Copy the value under Your Install ID.
In a multi-tenant deployment, each tenant has its own Install ID and requires its own license.
2. Obtain a license key
To purchase a license, open the Customer Portal and select or create the organization that will own it. Provide the Install ID and the required internal and external user capacity. See Purchase a license for the checkout steps.
After purchase, open the license's Details in the Customer Portal and copy the license key. If another person manages your subscription, ask them for the key or access to the Customer Portal organization.
To request a trial or discuss an Enterprise Plus agreement, contact [email protected].
3. Install the license key
- In the Admin interface, navigate to Enterprise > Licenses.
- Click Install.
- Paste the complete license key into License key and submit the form.
- Check the installed license's user capacity and expiry date. Current license status shows the combined status and capacity of all active licenses for the deployment.
Enterprise features are available once the license is valid. Follow the feature documentation to configure them.
If the key is rejected
Check that you copied the complete key, that it has not expired, and that it was issued for the Install ID shown on this deployment. A key issued for another deployment will not work. Check the server's clock if an unexpired key is rejected.
If the license installs but its status shows a capacity problem, compare the active internal and external user counts with the licensed capacity for each type. See license status and enforcement, or contact Enterprise support.
Air-gapped environments
Use the same license installation steps in an air-gapped environment. Copy the Install ID from the deployment, obtain the license key on a connected system, and install it via the Enterprise > Licenses section of the admin interface.
The Customer Portal needs internet access to purchase or retrieve keys. Your authentik deployment does not contact it to install or validate a license, and there is no periodic online license check. Renewals follow the same transfer process; update the installed key before it expires.
For image preparation, outbound-connection settings, and the complete offline license procedure, see Air-gapped environments.
Next steps
- Configure the Enterprise features you need.
- Manage licenses and billing, including renewals and user capacity.
- Use Enterprise support for installation and configuration help.