How to Install Authentik on Your Synology NAS

How to Install Authentik on Your Synology NAS

Authentik is an open-source and self-hosted identity provider designed to unify authentication, authorization, and access management across multiple applications through a centralized single sign-on experience. The platform functions as a privacy-focused alternative to commercial cloud identity providers by allowing users to host and control their data on private infrastructure. It supports major modern and legacy authentication standards including OpenID Connect, SAML, LDAP, RADIUS, and SCIM to bridge communication between diverse systems. In this step by step guide I will show you how to install AuthentikĀ on your Synology NAS using Docker & Portainer.

šŸ’”Note: This guide works perfectly with the latest Authentik v2026.8.0 release.

  • STEP 1

Please Support My work by Making a Donation.

  • STEP 2

InstallĀ Portainer using my step by step guide. If you already have Portainer installed on your Synology NAS, skip this STEP. Attention: Make sure you have installed the latest Portainer version.

  • STEP 3

Make sure you have a synology.me Wildcard Certificate. Follow my guide to get a Wildcard Certificate. If you already have a synology.me Wildcard certificate, skip this STEP.

  • STEP 4

Go toĀ Control PanelĀ /Ā Login PortalĀ /Ā AdvancedĀ Tab / clickĀ Reverse Proxy. Follow the instructions in the image below.

Authentik Synology NAS Set up 1

  • STEP 5

Now click the ā€œCreateā€ button. Follow the instructions in the image below.

Authentik Synology NAS Set up 2

  • STEP 6

After you click the Create button, the window below will open. Follow the instructions in the image below.

On the General area, set the Reverse Proxy Name description: type in Authentik. After that, add the following instructions:

Source:
Protocol:Ā HTTPS
Hostname: authentik.yourname.synology.me
Port:Ā 443

Check Enable HSTS

Destination:
Protocol:Ā HTTP
Hostname:Ā localhost
Port:Ā 9700

Authentik Synology NAS Set up 3

  • STEP 7

On the Reverse Proxy Rules click the Custom HeaderĀ tab. ClickĀ CreateĀ and then, from the drop-down menu, clickĀ WebSocket. After you click on WebSocket, two Header Names and two Values will be automatically added. ClickĀ Save. Follow the instructions in the image below.

Synology Proxy WebSocket

  • STEP 8

Go to Control Panel / Network / Connectivity tab/ Check Enable HTTP/2 then click Apply. Follow the instructions in the image below.

Authentik Synology NAS Set up 4

  • STEP 9

Go to Control Panel / Security / Advanced tab/ Check Enable HTTP CompressionĀ then click Apply. Follow the instructions in the image below.

Authentik Synology NAS Set up 5

  • STEP 10

Go toĀ File StationĀ and open the docker folder. Inside the docker folder, create one new folder and name itĀ authentik. Follow the instructions in the image below.
Note: Be careful to enter only lowercase, not uppercase letters.

Authentik Synology NAS Set up 6 new 2027

  • STEP 11

Now create five new folders inside the authentikĀ folder that you have previously created at STEP 10. Name them certs, data, db, redis, templates. Follow the instructions in the image below.
Note: Be careful to enter only lowercase, not uppercase letters.

Authentik Synology NAS Set up 7

  • STEP 12

Follow my step by step guide on how to activate SMTP for your Gmail account. This step is mandatory. Note: If you don’t want to use the easiest way for SMTP with Google and you already have SMTP details from your own Mail Server, you can just skip this STEP and use your personalized email SMTP details instead.

  • STEP 13

Log into Portainer using your username and password. On the left sidebar in Portainer, click onĀ HomeĀ thenĀ Live connect. Follow the instructions in the image below.

Portainer Add Stack NAS 1

  • STEP 14

In the Name field type in authentik. Follow the instructions in the image below.

Note: Copy Paste the code below in the Portainer Stacks Web editor.

services:
  db:
    image: postgres:18-alpine
    container_name: Authentik-DB
    security_opt:
      - no-new-privileges:true
    healthcheck:
      test: ["CMD", "pg_isready", "-q", "-d", "authentik", "-U", "authentikuser"]
      timeout: 45s
      interval: 10s
      retries: 10
    environment:
      POSTGRES_DB: authentik
      POSTGRES_USER: authentikuser
      POSTGRES_PASSWORD: authentikpass
    volumes:
      - /volume1/docker/authentik/db:/var/lib/postgresql:rw
    restart: on-failure:5

  redis:
    image: redis:7-alpine
    container_name: Authentik-CACHE
    healthcheck:
      test: ["CMD-SHELL", "redis-cli ping || exit 1"]
    environment:
      REDIS_PASSWORD: mariushosting
    volumes:
      - /volume1/docker/authentik/redis:/data:rw
    command: ["redis-server", "--requirepass", "mariushosting"]
    restart: on-failure:5

  server:
    image: ghcr.io/goauthentik/server:2026.8
    container_name: Authentik-SERVER
    environment:
      AUTHENTIK_POSTGRESQL__HOST: db
      AUTHENTIK_POSTGRESQL__NAME: authentik
      AUTHENTIK_POSTGRESQL__USER: authentikuser
      AUTHENTIK_POSTGRESQL__PASSWORD: authentikpass
      AUTHENTIK_REDIS__HOST: redis
      AUTHENTIK_REDIS__PASSWORD: mariushosting
      AUTHENTIK_SECRET_KEY: dOxZYTTZgXKMHkqLBIQVImayQXAVWdzGBPuFJKggzcgvgPJPXpWzqzKaUOIOGGIr
      AUTHENTIK_BOOTSTRAP_PASSWORD: mariushosting
      AUTHENTIK_EMAIL__HOST: smtp.gmail.com
      AUTHENTIK_EMAIL__USERNAME: Your-own-gmail-address
      AUTHENTIK_EMAIL__PASSWORD: Your-own-app-password
      AUTHENTIK_EMAIL__FROM: Your-own-gmail-address
      AUTHENTIK_HOST: authentik.yourname.synology.me
      AUTHENTIK_WEB__BASE_URL: https://authentik.yourname.synology.me
      COLORBT_SHOW_HIDDEN: 1
    ports:
      - 9700:9000
      - 9743:9443
    volumes:
      - /volume1/docker/authentik/data:/data:rw
      - /volume1/docker/authentik/templates:/templates:rw
    command: server
    depends_on:
      db:
        condition: service_healthy
    restart: on-failure:5

  worker:
    image: ghcr.io/goauthentik/server:2026.8
    container_name: Authentik-WORKER
    user: 0:0
    environment:
      AUTHENTIK_POSTGRESQL__HOST: db
      AUTHENTIK_POSTGRESQL__NAME: authentik
      AUTHENTIK_POSTGRESQL__USER: authentikuser
      AUTHENTIK_POSTGRESQL__PASSWORD: authentikpass
      AUTHENTIK_REDIS__HOST: redis
      AUTHENTIK_REDIS__PASSWORD: mariushosting
      AUTHENTIK_SECRET_KEY: dOxZYTTZgXKMHkqLBIQVImayQXAVWdzGBPuFJKggzcgvgPJPXpWzqzKaUOIOGGIr
      AUTHENTIK_BOOTSTRAP_PASSWORD: mariushosting
      AUTHENTIK_EMAIL__HOST: smtp.gmail.com
      AUTHENTIK_EMAIL__USERNAME: Your-own-gmail-address
      AUTHENTIK_EMAIL__PASSWORD: Your-own-app-password
      AUTHENTIK_EMAIL__FROM: Your-own-gmail-address
      AUTHENTIK_HOST: authentik.yourname.synology.me
      AUTHENTIK_WEB__BASE_URL: https://authentik.yourname.synology.me
      COLORBT_SHOW_HIDDEN: 1
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock
      - /volume1/docker/authentik/data:/data:rw
      - /volume1/docker/authentik/certs:/certs:rw
      - /volume1/docker/authentik/templates:/templates:rw
    command: worker
    depends_on:
      db:
        condition: service_healthy
    restart: on-failure:5

Note: Before you paste the code above in the Web editor area below, change the values for REDIS_PASSWORDĀ and AUTHENTIK_REDIS__PASSWORD. Check the orange colors in the code. mariushosting is an example for a redis password. The password should be the same for REDIS_PASSWORD, AUTHENTIK_REDIS__PASSWORD and in the redis command part.
Note: Before you paste the code above in the Web editor area below, change the value for AUTHENTIK_SECRET_KEY. (Generate your own Random 64 length AUTHENTIK_SECRET_KEY.)
Note: Before you paste the code above in the Web editor area below, change the value for AUTHENTIK_BOOTSTRAP_PASSWORD. mariushosting is an example for a password. You will need this password later at STEP 19.
Note: Before you paste the code above in the Web editor area below, change the value for AUTHENTIK_EMAIL__USERNAMEĀ and type in your own Gmail address. STEP 12.
Note: Before you paste the code above in the Web editor area below, change the value for AUTHENTIK_EMAIL__PASSWORDĀ and type in your own Gmail app password. STEP 12. āš ļøWarning: Do NOT confuse with your own Gmail password. This is the Gmail APP password.
Note: Before you paste the code above in the Web editor area below, change the value for AUTHENTIK_EMAIL__FROMĀ and type in your own Gmail address. STEP 12.
Note: Before you paste the code above in the Web editor area below, change the value for AUTHENTIK_HOSTĀ and type in your own synology.me DDNS withoutĀ https:// at the beginning that you have previously created at STEP 6.
Note: Before you paste the code above in the Web editor area below, change the value for AUTHENTIK_WEB__BASE_URLĀ and type in your own synology.me DDNS withĀ https:// at the beginning that you have previously created at STEP 6.

Authentik Synology NAS Set up 8

  • STEP 15

Scroll down on the page until you see a button called Deploy the stack. Click on it. Follow the instructions in the image below. The installation process can take up to a few minutes. It will depend on your Internet speed connection.

Authentik Synology NAS Set up 9

  • STEP 16

If everything goes right, you will see this message at the top right of your screen: ā€œSuccess Stack successfully deployedā€œ.

Portainer Success Stack NAS

  • STEP 17

🟢Please Support My work by Making a Donation. Almost 99,9% of the people that install something using my guidesĀ forget to support my work, or justĀ ignoreĀ STEP 1. I’ve been very honest about this aspect of my work since the beginning: I don’t run any ADS, I don’t require subscriptions, paid or otherwise, I don’t collect IPs, emails, and I don’t have any referral links from Amazon or other merchants. I also don’t have any POP-UPs or COOKIES. I have repeatedly been told over the years how much I have contributed to the community. It’s something I love doing and have been honest about my passion since the beginning. But I also Need The Community to Support me Back to be able to continue doing this work.

  • STEP 18

Now open your browser and type in your HTTPS/SSL certificate like this https://authentik.yourname.synology.me that you have previously created at STEP 6. In my case it’s https://authentik.mariushosting.synology.me If everything goes right, you will see the Authentik Login page. Type in akadmin as the default username, then click Log in. Follow the instructions in the image below.

āš ļøWarning: the default Username is akadmin

Authentik Synology NAS Set up 10

  • STEP 19

Type in your own AUTHENTIK_BOOTSTRAP_PASSWORD that you have previously added at STEP 14. Click Continue. Follow the instructions in the image below.

Authentik Synology NAS Set up 11

  • STEP 20

At the top right of the page, click Admin interface. Follow the instructions in the image below.

Authentik Synology NAS Set up 12

  • STEP 21

On the left sidebar, under System, click Settings. In the Base URL area, type in your own domain name or synology reverse proxy with https:// at the beginning. Switch ON the following options:

  • Allow users to change name
  • Allow users to change email
  • Allow users to change username

Click Save changes. Follow the instructions in the image below.

Authentik Synology NAS Set up 13

  • STEP 22

At the top right of the page, click the gear icon. Change your default Username and Email with your own credentials then click Save. Follow the instructions in the image below.

Authentik Synology NAS Set up 14

  • STEP 23

Your Authentik Admin Dashboard at a glance! Click Create new application to add your first app.

Authentik Synology NAS Set up 15 new 2027

Enjoy Authentik!

šŸ†˜TROUBLESHOOTING

If you encounter issues by using this container, make sure to check out the Common Docker issuesĀ article.

Note: Can I run Docker on my Synology NAS?Ā See the supported models.
Note: How to Back Up Docker Containers on your Synology NAS.
Note: Find outĀ how to update the Authentik container with the latest image.
Note: How to Free Disk Space on Your NAS if You Run Docker.
Note: How to Schedule Start & Stop For Docker Containers.
Note: How to Activate Email Notifications.
Note: How to Add Access Control Profile on Your NAS.
Note: How to Change Docker Containers Restart Policy.
Note: How to Use Docker Containers With VPN.
Note: Convert Docker Run Into Docker Compose.
Note: How to Clean Docker.
Note: How to Clean Docker Automatically.
Note: Best Practices When Using Docker and DDNS.
Note: Some Docker Containers Need WebSocket.
Note: Find out the Best NAS Models For Docker.
Note: Activate Gmail SMTP For Docker Containers.

This post was updated on Wednesday / August 26th, 2026 at 2:05 AM

No sponsors, no corporations, no ads, no subscriptions, no membership tiers, no referral links, no pop-ups, no cookies, no tracking code. Just pure guides for the community from Marius.