Skip to main content

Download the authentik Agent

authentik: 2025.12.0+

The authentik Agent is a service that you install on Linux, macOS, and Windows devices to enable device compliance, local device login, SSH authentication, and CLI application authentication. The downloads on this page always provide the latest release.

Download for macOS or Windows​

info

Downloading the installer is only the first step. To create an enrollment token, install the package, and join the device to an authentik domain, follow the macOS or Windows deployment guide. For more than a handful of devices, use MDM or automated deployment instead.

Install on Linux​

On Linux, install the authentik Agent from the authentik package repository rather than downloading a file.

  1. Open a Terminal session and install the required GPG key:
curl -fsSL https://pkg.goauthentik.io/keys/gpg-key.asc | sudo gpg --dearmor -o /usr/share/keyrings/authentik-keyring.gpg
  1. Add the repository:
echo "deb [signed-by=/usr/share/keyrings/authentik-keyring.gpg] https://pkg.goauthentik.io stable main" | sudo tee /etc/apt/sources.list.d/authentik.list
  1. Update your repositories and install the authentik Agent packages:
sudo apt update
sudo apt install authentik-cli authentik-agent authentik-sysd
  1. (Optional) To enable SSH server authentication and local device login, install two additional packages:
sudo apt install libnss-authentik libpam-authentik
info

To join the device to an authentik domain and configure NSS and PAM, continue with the Linux deployment guide.

Verify the installation​

Check the version of all installed authentik components by running the following command:

ak version

You should see a response that starts with authentik CLI v<version_number>.

Next steps​