Skip to main content

Manage secrets

authentik: 2026.11.0+

Each task on this page requires specific secret permissions. Being able to edit a provider or source doesn't let you read or replace its credential. See Secret permissions.

Create a secret​

To create a secret before you configure the object that uses it:

  1. In the Admin interface, go to System > Secrets and click New Secret.
  2. Enter a Name that describes the credential's purpose, such as Production LDAP bind password. Anyone who can see the secret can see its name, so don't include the credential itself.
  3. Select a Type. See Secret types.
  4. Enter or upload the value:
    • For a Text secret, enter the value issued by the other system, or leave Value empty to have authentik generate one. A generated value uses ASCII letters and digits, and has the length in Length, or the Default token length system setting if you leave it empty.
    • For a JSON secret, paste the JSON or YAML object.
    • For a File secret, select the file under File.
  5. Click Create Secret.

To create a secret while you configure an object, click Create secret beside the object's secret picker and follow the same steps. authentik saves the secret immediately, so it remains under System > Secrets even if you cancel the surrounding form.

Reuse a secret​

To use an existing secret, search for it by name in the object's secret picker, select it, and save the object. The object references the secret; it doesn't copy the value.

For example, two email stages that log in to the same SMTP account can share one SMTP password secret. Replacing that secret's value changes the password for both stages.

Use separate secrets when credentials need to change independently or need different permissions.

If a secret is missing from the picker, check that its type fits the field and that you have permission to view it.

Replace a value​

When another system issues a new password, token, or credential file, enter it in authentik:

  1. Go to System > Secrets and click the edit icon on the secret's row.
  2. For a Text or JSON secret, click Modify and enter the New value. For a File secret, upload the New file. Leaving the field empty keeps the current value.
  3. Click Save Changes.

Every object that uses the secret switches to the new value. To change the credential of only one object, create a separate secret and select it on that object instead.

authentik records the replacement as a secret_rotate event.

Rotate a secret​

Rotating replaces the value of a Text secret with a new value that authentik generates. The new value is at least as long as the current one and at least the Default token length, so a 128-character OAuth2 client secret stays 128 characters. Rotation is manual. authentik doesn't rotate secrets on a schedule.

warning

Rotation changes the value in authentik only. It doesn't update the clients or external systems that use the credential.

Rotate only secrets that authentik issues, such as an OAuth2 client secret, a proxy cookie secret, or a RADIUS shared secret, and then update the clients that use them. If another system issued the credential, such as an LDAP bind password, a Duo API key, or an SMTP password, rotating it breaks the integration until that system accepts the new value. To change these credentials, replace the value instead.

  1. Go to System > Secrets, or open a form that uses the secret.
  2. Click Rotate secret on the secret's row or beside the secret picker.
  3. Click Rotate to confirm.

The new value takes effect immediately, even if you then cancel the surrounding form. If you have the View secret's value permission, authentik shows the new value so that you can copy it to the clients that use it.

Every object that uses the secret switches to the new value, and connected outposts receive it automatically. Some objects need extra care:

  • OAuth2/OpenID providers: clients that still send the old client secret are rejected. If the provider has no signing key, ID tokens signed with the old value no longer validate.
  • Proxy providers: rotating a cookie secret signs out every user of the providers that use it. The confirmation dialog warns about this when a proxy provider uses the secret. Cookie secrets must be at least 32 bytes long.
  • RADIUS providers: RADIUS clients that still use the old shared secret are rejected.

authentik records each rotation as a secret_rotate event.

Delete a secret​

authentik prevents you from deleting a secret that an object still references, and the delete confirmation lists the objects that use it. Deleting an object doesn't delete its secret, because other objects can reuse it.

  1. Change each object that uses the secret to another secret, clear the field if it is optional, or delete the object.
  2. Go to System > Secrets, select the secret, and click Delete.
  3. Confirm the deletion.