Okta → authentik
What it saves, what actually moves, what you rebuild — and the thing that catches people.
What it costs, and what it saves
As listed on okta.com/pricing on 2026-10-03, Okta Workforce Identity Starter is $6 per user per month and Essentials is $17 per user per month (Core Essentials $14, sales-assisted; Professional and Enterprise are quote-only). All suites are billed annually with a $1,500 annual contract minimum. For 100 workforce users that is $7,200 a year on Starter or $20,400 on Essentials (our arithmetic). authentik's open-source edition has no licence fee, as listed on goauthentik.io/pricing the same day. Its Enterprise tier is $5 per internal user per month billed annually ($6,000 a year for 100 users), plus $0.02 per external user per month, with service accounts free; Enterprise Plus starts at $20k a year. Self-hosting adds a server with at least 2 CPU cores and 2 GB RAM (authentik's stated minimum), a PostgreSQL database, backups and the staff time to run an always-on identity service. None of that is included above.
Moves cleanly
User profiles and group memberships move cleanly. authentik's SCIM source lets Okta push users and groups straight into authentik, provided your Okta plan includes provisioning; the pricing page lists Lifecycle Management under Essentials. SAML and OIDC applications move protocol for protocol. An authentik SAML provider can import a service provider's metadata, and OIDC clients get a new issuer URL, client ID and secret. Outbound SCIM provisioning to downstream apps has a direct counterpart in authentik's SCIM provider, which syncs changes as they happen and runs a full sync every hour.
You rebuild
Passwords do not move. Okta has no standard password-hash export: its support article describes hash export only in a limited number of cases, for moves to Auth0. Enrolled MFA factors do not move either: Okta Verify enrolments and passkeys stay behind, and every user enrols new TOTP or WebAuthn factors in authentik. Sign-on policies, per-app attribute statements, Okta Workflows and hooks are rebuilt as authentik flows, stages, policies and property mappings.
What Okta costs you today
Priced per monthly active user, per product, with most features sold separately: single sign-on around $2/user/month, MFA around $3, lifecycle management around $4, and API access management on top. A mid-sized company assembling the pieces it actually needs typically lands between $6 and $11 per user per month, with annual minimums. Figures checked 2026-08-03; identity pricing is heavily negotiated, so treat these as a starting point.
What actually holds you in
High, and it is the integrations rather than the users. User records and group memberships export via SCIM and the API. What does not move is the hundreds of application connections, the provisioning rules, the MFA enrolments people have on their phones, and the conditional-access policies built over years. Re-enrolling every employee in MFA is the step that makes identity migrations painful, and it is unavoidable. Plan for a parallel run, not a cutover.
What you are moving to
authentik was built on the premise that Keycloak is more than most companies need and harder than most can run. It covers SSO, MFA, SAML, OIDC, LDAP outposts and a genuinely good flow builder for custom login journeys, with a clean interface and a Docker Compose deployment. Around 23k stars. The licence is worth stating precisely: the core is MIT, the `website/` directory is CC BY-SA, and enterprise features sit under a separate commercial licence — so it is MIT-with-carve-outs rather than plainly MIT.
Free and self-hostable for the open core. Enterprise tier is commercial.
authentik strengths
- By far the easiest of these to stand up and keep running
- Flow builder makes custom login journeys genuinely configurable
- Modern interface a small team can navigate without training
- Docker Compose deployment; sensible defaults
What you give up
- Enterprise features are carved out of the MIT core
- Younger and smaller than Keycloak
- Single-vendor governance rather than a foundation
- Fewer third-party integrations
The migration, step by step
- 1Inventory Okta: for every SAML/OIDC app, record its ACS or redirect URLs, NameID format, attribute statements and assigned groups. Also record MFA and sign-on policies and any Workflows or hooks. Mark the apps that accept only one identity provider at a time.
- 2Deploy authentik on its own hostname (at least 2 CPU cores and 2 GB RAM, PostgreSQL, backups on). Keep two local admin accounts and their recovery codes outside SSO. Bring users and groups across with authentik's SCIM source fed by Okta, or with a scripted import.
- 3Parallel run: add Okta as a SAML or OIDC source in authentik so users sign in through Okta once and get an authentik account. On authentik Enterprise, the Source stage can do this inside a flow. During this period, set the MFA validation stage's 'not configured' action to Configure so first-time users enrol a new factor instead of being denied.
- 4Move apps one at a time, low-risk first. Import each app's SP metadata into an authentik SAML provider, or create an OIDC provider, and test with a pilot group. Then switch the app's IdP settings, keeping the old Okta values written down so you can switch back.
- 5Settle passwords before Okta goes away. Either send authentik password-reset emails, or, if your Okta subscription includes the LDAP Interface, use an authentik LDAP source with 'update internal password on login'. The second option stores each password as its owner signs in; test it against your Okta MFA policy first.
- 6Cut over when every app authenticates against authentik and the Okta source shows no remaining logins. Remove the Okta source from authentik's flows, revoke the SCIM token Okta used, export the Okta records you must keep for audit, and let the contract end at renewal.
The gotcha
Users lock themselves out on the first day because nothing they enrolled in Okta comes with them. There are no password hashes: Okta's own support article limits hash export to some transitions to Auth0. There are no Okta Verify enrolments, and no passkeys either. The W3C WebAuthn spec scopes each credential to the relying party that registered it, so a passkey made for your Okta domain cannot sign in to authentik's domain. If authentik's MFA validation stage is set to Deny when a user has no authenticator, every first login after cutover fails, so use Configure until enrolment is done. The second trap is cost. The Source stage is authentik's documented way to authenticate against Okta mid-migration and keep the returned attributes, and it is an Enterprise feature. Budget a licence for the migration months, or plan a reset-based cutover on the free edition. Imported password hashes (the 2026.5 set_password_hash API) also do not help, because Okta will not give you hashes to import.
When to stay on Okta
Stay on Okta if you use what its higher tiers bundle: Adaptive MFA, Privileged Access, Lifecycle Management, Access Governance and Workflows. Also stay if nobody on your team can run, patch, monitor and back up an identity server around the clock. A self-hosted identity provider that goes down locks every user out of every connected app at once, and on Okta that operational load and its on-call duty sit with the vendor.
More Layer 3 migrations
Figures verified 2026-08-03 against vendor pricing pages. Prices change and migrations differ by estate — treat the cost delta as a starting model, not a quote. Rankings and recommendations here are merit-only; affiliate income never changes a verdict. See our methodology.