Skip to main content

Manage licenses and billing

Use Enterprise > Licenses in the authentik Admin interface to manage installed keys and check user capacity and expiry. Use the Customer Portal to purchase or renew subscriptions, retrieve keys, and manage billing and organization access.

For your first license, follow Get started with authentik Enterprise.

Manage licenses

An authentik Enterprise license is bound to one Install ID and defines an expiry date and separate capacity for internal and external users. You can install multiple active licenses for the same Install ID; authentik adds their user capacities together.

In the Admin interface, navigate to Enterprise > Licenses to view:

  • The Install ID for the current deployment.
  • Forecasts for internal and external user counts.
  • The latest expiry date, combined status, and total user capacity of installed licenses.
  • The name, capacity, and expiry date of each license.

License validation and user counting happen locally. The deployment does not need internet access. See air-gapped licensing for transferring keys into a disconnected deployment.

Update a license key

When a renewal or capacity change provides a replacement key, retrieve it from the license's Details in the Customer Portal. Transfer it into your environment if needed, then update authentik:

  1. Navigate to Enterprise > Licenses.
  2. Edit the license that the new key replaces.
  3. Paste the replacement into License key.
  4. Click Save Changes.

Verify the new expiry date and capacity on the Licenses page. Renewing the subscription in the Customer Portal does not update the key stored in your deployment; install the replacement key before the old one expires.

Remove a license

Select a license on the Licenses page and click Delete. Removing an active license immediately removes its capacity from the combined license total. Install any replacement key before deleting the old key to avoid an unintended capacity violation.

About users and licenses

authentik counts active internal and external users separately. Disabled users, the anonymous user, and service accounts, including agent accounts, do not consume licensed capacity.

  • An internal user can access the authentik application dashboard and user settings. Employees and other members of your organization are typically internal users.
  • An external user cannot access the application dashboard or user settings. Customers, partners, volunteers, and contractors who use authentik only to access another application can be external users.

You configure a user's type on the user account. To send external users directly to an application after authentication, configure the brand's default application.

Either user type exceeding its licensed capacity triggers capacity enforcement. Unused internal capacity does not cover excess external users, and unused external capacity does not cover excess internal users.

Expand license capacity

To add capacity, either purchase another license for the same Install ID or open a support ticket to change an existing subscription. Multiple active licenses add together, but their billing and renewal dates can differ.

Use the forecasts on Enterprise > Licenses as planning estimates. Before purchasing, compare the proposed capacity with the current counts for both user types.

License expiry and capacity enforcement

authentik checks expiry dates and active user counts locally, including in air-gapped environments. The combined expiry is the latest expiry date among installed licenses. Only unexpired licenses contribute user capacity. When one of several licenses expires, the remaining licenses must still cover both user types.

authentik displays warnings and eventually restricts changes when licensing requirements are not met:

Conditionauthentik behavior
The combined license expiry is within two weeksAdministrators see an expiry warning.
The combined license has expiredAdministrators see an expired-license warning, unless a capacity threshold below takes precedence.
User capacity is exceeded and the last valid usage record is over two weeks oldAdministrators see a user-capacity warning.
User capacity is exceeded and the last valid usage record is over four weeks oldThe Admin and User interfaces display the user-capacity warning.
The combined license expired over six weeks ago, or capacity is exceeded and the last valid usage record is over six weeks oldThe deployment enters read-only mode.

Capacity thresholds use the last recorded valid status, not the date a key was installed. If the deployment has no valid usage record and its users exceed the licensed capacity, it can enter read-only mode immediately. Purchase enough capacity for both user types before installing the first key.

In read-only mode:

  • Users can continue to authenticate and authorize access to applications.
  • Administrators can read configuration but cannot change most objects.
  • Administrators can still install, update, or remove licenses.
  • Administrators can still update or delete users to restore licensed capacity.

After you install a valid license, renew an expired license, or reduce the relevant user count, authentik returns to standard read-write operation and removes the associated warning.

License status is cached and usage is recorded periodically. Open Enterprise > Licenses to refresh the combined status after correcting the license or user counts.

Manage an organization

A Customer Portal organization contains its members, licenses, subscriptions, and billing information.

Create an organization

  1. Log in to the Customer Portal.
  2. On the My organizations page, click Create an organization.
  3. Enter the organization name and notification email address.
  4. Click Create.

To delete an organization, contact [email protected].

Manage organization members

Customer Portal membership controls access to license keys and billing. It does not grant access to the authentik Admin interface.

  • A Member can view the organization's licenses and license keys.
  • An Owner has Member access and can invite or remove members, purchase or renew licenses, and edit the organization.

To invite a member:

  1. On My organizations, select the organization.
  2. Under Pending invitations, enter the person's email address and select a role.
  3. Click Invite.

The person becomes a member after accepting the invitation from their email.

To remove a member, open the organization, find the person under Membership, and click Remove.

Purchase a license

Before purchasing a license, copy the authentik deployment's Install ID.

  1. Log in to the Customer Portal and select the organization that will own the license.
  2. Click Purchase license.
  3. Enter the required internal and external user capacity.
  4. Enter the Install ID.
  5. Optionally, change the license name. The Customer Portal and authentik Admin interface use this name to identify the license.
  6. Click Continue.
  7. Enter the payment details, then click Pay and subscribe.

After the payment is validated, the license appears on the organization page. Click Details next to the license to copy its key, then install the license key in authentik.

For a trial, Enterprise Plus, invoice billing, or a custom purchase, contact [email protected].

Manage billing

  1. In the Customer Portal, navigate to Organizations > My organizations.
  2. Select the organization.
  3. Click Manage Billing.

The billing page lets an organization owner update billing details and tax information, add payment methods, review invoices and payments, and manage subscriptions.

Cancel a subscription

On the billing page, select the subscription and click Cancel subscription. The associated license remains valid through the end of the current billing period and does not renew automatically.

Canceling a subscription does not remove its license key from authentik. See License expiry and capacity enforcement to understand what happens after the license expires.