AuthentikSSO: one login for store and panel
Customers sign in through your identity provider – authentik, Keycloak, Zitadel, Pocket ID or any OIDC provider. Safer, simpler, managed in one place.
Features
Ready-made presets
authentik, Keycloak, Zitadel and Pocket ID out of the box, plus generic OIDC with discovery.
Single logout
Signing out of Paymenter also ends the session at the identity provider.
Pterodactyl and Pelican
Optionally create or link matching panel accounts on login, including a connection test.
Central security
Two-factor sign-in, password rules and lockouts are managed in one place.
Privacy-aware debugging
Debug logs mask personal data automatically.
Ready in a few steps
-
1
Create a provider
Set up an OAuth2/OpenID provider in your identity provider.
-
2
Connect the extension
Enter discovery URL, client ID and secret.
-
3
Test
Sign in with a test account – done.
Frequently asked questions
Paymenter 1.5.8 or newer. The exact compatibility is listed in the changelog of each release.
No. All Holzmodem extensions work without changing the Paymenter core and without extra Composer packages, so Paymenter updates stay possible.
Any provider that speaks OpenID Connect with discovery. authentik, Keycloak, Zitadel and Pocket ID have ready-made presets.
Yes: our guide “Single sign-on with authentik” walks you through the setup step by step.
Questions about AuthentikSSO?
Ask a question