Identity and access

LDAP and Active Directory sign-in

Sign in against LDAP or Active Directory and use directory groups for grants, with no OIDC provider needed.

What it is

People sign in with their directory username and password against LDAP, Active Directory, OpenLDAP, FreeIPA or an Authentik outpost. Group membership comes from memberOf or a group search.

Why you want it

Some networks have a directory but no OIDC provider, especially on-premises and air-gapped sites. LDAP lets them use directory groups for grants without standing up an IdP.

How it works

  • ldap:// or ldaps:// URL with an optional service-account bind
  • Configurable user filter, email, name and group attributes
  • Group lookup from memberOf or a search filter such as (member={dn})
  • One directory per gateway; a test endpoint validates the settings

See it on your own network.

The Community edition is free for up to 25 people. The 30-day Business trial unlocks every Business feature.