Download the authentik Agent
authentik: 2025.12.0+
The authentik Agent is a service that you install on Linux, macOS, and Windows devices to enable device compliance, local device login, SSH authentication, and CLI application authentication. The downloads on this page always provide the latest release.
Download for macOS or Windows
Downloading the installer is only the first step. To create an enrollment token, install the package, and join the device to an authentik domain, follow the macOS or Windows deployment guide. For more than a handful of devices, use MDM or automated deployment instead.
Install on Linux
On Linux, install the authentik Agent from the authentik package repository rather than downloading a file.
- Debian-based
- Red Hat-based
- Open a Terminal session and install the required GPG key:
curl -fsSL https://pkg.goauthentik.io/keys/gpg-key.asc | sudo gpg --dearmor -o /usr/share/keyrings/authentik-keyring.gpg
- Add the repository:
echo "deb [signed-by=/usr/share/keyrings/authentik-keyring.gpg] https://pkg.goauthentik.io stable main" | sudo tee /etc/apt/sources.list.d/authentik.list
- Update your repositories and install the authentik Agent packages:
sudo apt update
sudo apt install authentik-cli authentik-agent authentik-sysd
- (Optional) To enable SSH server authentication and local device login, install two additional packages:
sudo apt install libnss-authentik libpam-authentik
- Open a Terminal session and run the following command to add the authentik repo and associated GPG key:
# This overwrites any existing configuration in /etc/yum.repos.d/authentik.repo
cat <<EOF | sudo tee /etc/yum.repos.d/authentik.repo
[authentik]
name=authentik
baseurl=https://pkg.goauthentik.io
enabled=1
gpgcheck=1
gpgkey=https://pkg.goauthentik.io/keys/gpg-key.asc
EOF
- Install the authentik Agent packages:
sudo yum install -y authentik-cli authentik-agent authentik-sysd
- (Optional) To enable SSH server authentication and local device login, install two additional packages:
sudo yum install -y libnss-authentik libpam-authentik
To join the device to an authentik domain and configure NSS and PAM, continue with the Linux deployment guide.
Verify the installation
Check the version of all installed authentik components by running the following command:
ak version
You should see a response that starts with authentik CLI v<version_number>.
Next steps
- Configure your authentik deployment to support the authentik Agent. This is required before a device can enroll.
- Deploy the Agent on Linux, macOS, or Windows.
- Deploy at scale with MDM and automation tools.
- Review the release notes for the latest changes.