English الإنجليزية Japanese اليابانية Korean الكورية Chinese (Simplified) الصينية (مبسطة) Chinese (Traditional) الصينية (التقليدية) Auto-detect اكتشاف تلقائي Label for the auto-detect locale option in language selection dropdown Select language اختر اللغة Label for the language selection dropdown () () Locale option label showing the localized language name along with the native language name in parentheses. Dismiss رفض Connection error, reconnecting... خطأ في الاتصال، جارٍ إعادة الاتصال... An unknown error occurred حدث خطأ غير معروف Please check the browser console for more details. يرجى التحقق من وحدة تحكم المتصفح لمزيد من التفاصيل. Status messages رسائل الحالة Settings الإعدادات Stop impersonation إيقاف انتحال الهوية Admin مدير Home الرئيسية authentik Logo شعار authentik Collapse navigation طيّ التنقل Expand navigation توسيع التنقل User interface واجهة المستخدم Loading... جارٍ التحميل... Application تطبيق Logins عمليات تسجيل الدخول Failed to fetch فشل في الجلب FIPS Status حالة FIPS OK موافق FIPS compliance: passing امتثال FIPS: اجتياز Unverified غير مُتحقَّق منه FIPS compliance: unverified امتثال FIPS: غير مُتحقَّق منه Show less إظهار أقل Show more إظهار المزيد UID المعرّف الفريد Name الاسم App التطبيق Model Name اسم النموذج Message رسالة Subject الموضوع From من To إلى Context السياق User مستخدم Changes made: التغييرات المُجراة: Key المفتاح Previous value القيمة السابقة New value القيمة الجديدة - - Added ID تم إضافة المعرِّف Removed ID تم إزالة المعرِّف Cleared تم المسح Affected model: النموذج المتأثر: Authorized application: التطبيق المصرَّح به: Using flow باستخدام التدفق Email info: معلومات البريد الإلكتروني: Secret: السر: Exception استثناء Open issue on GitHub... فتح مشكلة على GitHub... Expression تعبير Binding ربط Request طلب Object كائن Result النتيجة Passing اجتياز Messages الرسائل New version available يتوفر إصدار جديد Using source باستخدام المصدر Attempted to log in as محاولة تسجيل الدخول باسم No additional data available. لا توجد بيانات إضافية متاحة. Loading جاري التحميل no tabs defined لا توجد علامات تبويب محددة Details التفاصيل : : Required مطلوب There was an error submitting the form. حدث خطأ عند إرسال النموذج. Close dialog إغلاق الحوار API Access وصول API App password كلمة مرور التطبيق Recovery الاسترداد Verification التحقق Unknown intent غرض غير معروف Login تسجيل الدخول Failed login فشل تسجيل الدخول Logout تسجيل الخروج User was written to تمت الكتابة إلى المستخدم Suspicious request طلب مشبوه Password set تم تعيين كلمة المرور Secret was viewed تم عرض السر Secret was rotated تم تدوير السر Invitation used تم استخدام الدعوة Application authorized تم تفويض التطبيق Source linked تم ربط المصدر Impersonation started بدأ انتحال الهوية Impersonation ended انتهى انتحال الهوية Flow execution تنفيذ التدفق Policy execution تنفيذ السياسة Policy exception استثناء السياسة Property Mapping exception استثناء تعيين الخصائص System task execution تنفيذ مهمة النظام System task exception استثناء مهمة النظام General system exception استثناء عام للنظام Configuration error خطأ في الإعداد Model created تم إنشاء النموذج Model updated تم تحديث النموذج Model deleted تم حذف النموذج Email sent تم إرسال البريد الإلكتروني Update available يتوفر تحديث Alert تنبيه Notice ملاحظة Warning تحذير Unknown severity خطورة غير معروفة Static tokens الرموز الثابتة TOTP Device جهاز TOTP A code has been sent to your address: تم إرسال رمز إلى عنوانك: A code has been sent to your email address. تم إرسال رمز إلى عنوان بريدك الإلكتروني. A one-time use code has been sent to you via SMS text message. تم إرسال رمز للاستخدام مرة واحدة إليك عبر رسالة نصية SMS. Open your authenticator app to retrieve a one-time use code. افتح تطبيق المصادق للحصول على رمز للاستخدام مرة واحدة. Enter a one-time recovery code for this user. أدخل رمز استرداد لمرة واحدة لهذا المستخدم. Enter the code from your authenticator device. أدخل الرمز من جهاز المصادق الخاص بك. Internal داخلي External خارجي Service account حساب الخدمة Service account (internal) حساب الخدمة (داخلي) Remove item إزالة العنصر table pagination table pagination - of - of Go to previous page الانتقال إلى الصفحة السابقة Go to next page الانتقال إلى الصفحة التالية This field is required. هذا الحقل مطلوب. Search... بحث... Search بحث Query suggestions اقتراحات الاستعلام Query input إدخال الاستعلام Table Search بحث الجدول Clear search مسح البحث Sort by "" رتب حسب "" Failed to fetch objects. فشل في جلب الكائنات. Select "" row تحديد الصف "" Collapse row طيّ الصف Expand row توسيع الصف Refresh تحديث actions actions Select all rows on page ( of selected) تحديد جميع الصفوف في الصفحة ( من محددة) Last refreshed آخر تحديث table جدول Table content محتوى الجدول Column actions إجراءات العمود Anonymous user مستخدم مجهول On behalf of نيابة عن Authenticated as تمت المصادقة باسم Recent events الأحداث الأخيرة Events الأحداث Action الإجراء Creation Date تاريخ الإنشاء Client IP عنوان IP العميل No Events found. لم يتم العثور على أحداث. No matching events could be found. لم يتم العثور على أحداث مطابقة. System Status حالة النظام Embedded outpost is not configured correctly. لم يتم تكوين النقطة الخارجية المدمجة بشكل صحيح. Check outposts. تحقق من النقاط الخارجية. HTTPS is not detected correctly لم يتم اكتشاف HTTPS بشكل صحيح Server and client are further than 5 seconds apart. Server and client are further than 5 seconds apart. Everything is ok. Everything is ok. Version الإصدار Based on Based on is available! is available! An outpost is on an incorrect version! An outpost is on an incorrect version! Up-to-date! Up-to-date! Latest version unknown Latest version unknown Workers العمال No workers connected. Background tasks will not run. No workers connected. Background tasks will not run. Worker with incorrect version connected. Worker with incorrect version connected. Failed to fetch data. Failed to fetch data. Chart Chart Event volume chart Event volume chart Authorizations Authorizations Successful Logins Successful Logins Failed Logins Failed Logins Cancel إلغاء Synchronization status chart Synchronization status chart SCIM Provider SCIM Provider Google Workspace Provider Google Workspace Provider Microsoft Entra Provider Microsoft Entra Provider LDAP Source LDAP Source Kerberos Source Kerberos Source Healthy سليم Failed فشل Unsynced / N/A Unsynced / N/A Outpost status chart Outpost status chart Healthy outposts Healthy outposts Outdated outposts Outdated outposts Unhealthy outposts Unhealthy outposts Operation failed to complete Operation failed to complete Quick actions Quick actions Not found Not found The URL "" was not found. The URL "" was not found. Return home Return home Skip to content Skip to content Create a new application Create a new application Check the logs Check the logs Explore integrations Explore integrations Manage users Manage users Check the release notes Check the release notes Overview نظرة عامة Outpost status Outpost status Sync status Sync status Logins and authorizations over the last week (per 8 hours) Logins and authorizations over the last week (per 8 hours) Apps with most usage Apps with most usage Welcome, Welcome, Welcome Welcome General system status General system status Objects created Objects created Users created per day in the last month Users created per day in the last month Users created Users created Logins per day in the last month Logins per day in the last month Failed Logins per day in the last month Failed Logins per day in the last month Failed logins فشل عمليات الدخول User Statistics إحصائيات المستخدمين Yes نعم No لا No log messages. لا توجد رسائل سجل. Timestamp الطابع الزمني Attributes الخصائص Time الوقت Level المستوى Event حدث Logger Logger Not used by any other object. Not used by any other object. () () Delete حذف deleted deleted ID ID Successfully deleted Successfully deleted Delete Delete Are you sure you want to delete ? Are you sure you want to delete ? No form found No form found Form actions Form actions Submit action Submit action Cancel action Cancel action Successfully updated schedule. Successfully updated schedule. Crontab Crontab Paused Paused Pause this schedule Pause this schedule Failed to fetch objects: Failed to fetch objects: Successfully assigned permission. Successfully assigned permission. Role دور Assign Assign Assign permission to role Assign permission to role Permission(s) Permission(s) Permission صلاحية Superuser مستخدم متميز Model Model Select permissions to assign Select permissions to assign Add إضافة Permissions to add Permissions to add Select permissions Select permissions Assigned to role Assigned to role Assign permission Assign permission Role doesn't have view permission so description cannot be retrieved. Role doesn't have view permission so description cannot be retrieved. Permissions set on roles which affect this object. Permissions set on roles which affect this object. Assigned global permissions Assigned global permissions Assigned object permissions Assigned object permissions Permissions assigned to this role which affect all object instances of a given type. Permissions assigned to this role which affect all object instances of a given type. Close إغلاق Permissions الصلاحيات Waiting to run Waiting to run Consumed Consumed Pre-processing Pre-processing Running يعمل Post-processing Post-processing Successful ناجح Error خطأ Unknown غير معروف Running tasks Running tasks Queued tasks Queued tasks Successful tasks Successful tasks Error tasks Error tasks Task مهمة Queue قائمة الانتظار Retries Retries Planned execution time Planned execution time Last updated Last updated Status الحالة Actions الإجراءات Row Actions Row Actions Show only standalone tasks Show only standalone tasks Exclude successful tasks Exclude successful tasks Retry task Retry task Current execution logs Current execution logs Previous executions logs Previous executions logs Schedule Schedule Next run Next run Last status Last status Show only standalone schedules Show only standalone schedules Run scheduled task now Run scheduled task now Update Schedule Update Schedule Edit تعديل Tasks المهام Schedules Schedules System Tasks System Tasks Long-running operations which authentik executes in the background. Long-running operations which authentik executes in the background. Next التالي Back رجوع Wizard steps Wizard steps Wizard navigation Wizard navigation New application New application Create a new application and configure a provider for it. Create a new application and configure a provider for it. Any policy must match to grant access Any policy must match to grant access All policies must match to grant access All policies must match to grant access An application name is required An application name is required Not a valid URL Not a valid URL Not a valid slug Not a valid slug Configure the Application Configure the Application Type an application name... Type an application name... Application Name Application Name Slug المعرف المختصر Internal application name used in URLs. Internal application name used in URLs. Group مجموعة e.g. Collaboration, Communication, Internal, etc. e.g. Collaboration, Communication, Internal, etc. Optionally enter a group name. Applications with identical groups are shown grouped together. Optionally enter a group name. Applications with identical groups are shown grouped together. Policy engine mode وضع محرك السياسة UI Settings UI Settings Launch URL رابط التشغيل https://... https://... If left empty, authentik will try to extract the launch URL based on the selected provider. If left empty, authentik will try to extract the launch URL based on the selected provider. Open in new tab فتح في علامة تبويب جديدة Select all rows Select all rows Bind existing policy/group/user Bind existing policy/group/user Order Order Enabled مُفعَّل Timeout Timeout Configure Bindings Configure Bindings Policy Policy Group Group User User Configure Policy/User/Group Bindings Configure Policy/User/Group Bindings These policies control which users can access this application. These policies control which users can access this application. No bound policies. No bound policies. No policies are currently bound to this object. No policies are currently bound to this object. Bind policy/group/user Bind policy/group/user Configure Policy Bindings Configure Policy Bindings Pass Pass Don't Pass Don't Pass Edit Binding Edit Binding Save Binding Save Binding Create a Policy/User/Group Binding Create a Policy/User/Group Binding Policy سياسة Negates the outcome of the binding. Messages are unaffected. Negates the outcome of the binding. Messages are unaffected. Enterprise only Enterprise only Learn more about the enterprise license. Learn more about the enterprise license. Apply changes Apply changes UNNAMED UNNAMED Wizard content Wizard content Finish إنهاء Icon Icon Choose a Provider Choose a Provider Please choose a provider type before proceeding. Please choose a provider type before proceeding. Choose a Provider Type Choose a Provider Type Certificate شهادة Select a certificate... Select a certificate... Authentication المصادقة Authorization التفويض Enrollment التسجيل Invalidation الإبطال Stage Configuration Stage Configuration Unenrollment إلغاء التسجيل Unknown designation Unknown designation Stacked Stacked Content left Content left Content right Content right Sidebar left Sidebar left Sidebar right Sidebar right Unknown layout Unknown layout Select a flow... Select a flow... Add All Available Add All Available Remove All Available Remove All Available Remove إزالة Remove All Remove All Pagination Pagination Available options Available options Selected options Selected options Search ... Search ... (Format: hours=-1;minutes=-2;seconds=-3). (Format: hours=-1;minutes=-2;seconds=-3). (Format: hours=1;minutes=2;seconds=3). (Format: hours=1;minutes=2;seconds=3). The following keywords are supported: The following keywords are supported: Cached binding Cached binding Flow is executed and session is cached in memory. Flow is executed when session expires Flow is executed and session is cached in memory. Flow is executed when session expires Direct binding Direct binding Always execute the configured bind flow to authenticate the user Always execute the configured bind flow to authenticate the user Cached querying Cached querying The outpost holds all users and groups in-memory and will refresh every 5 Minutes The outpost holds all users and groups in-memory and will refresh every 5 Minutes Direct querying Direct querying Always returns the latest data, but slower than cached querying Always returns the latest data, but slower than cached querying When enabled, code-based multi-factor authentication can be used by appending a semicolon and the TOTP code to the password. This should only be enabled if all users that will bind to this provider have a TOTP device configured, as otherwise a password may incorrectly be rejected if it contains a semicolon. When enabled, code-based multi-factor authentication can be used by appending a semicolon and the TOTP code to the password. This should only be enabled if all users that will bind to this provider have a TOTP device configured, as otherwise a password may incorrectly be rejected if it contains a semicolon. The certificate for the above configured Base DN. As a fallback, the provider uses a self-signed certificate. The certificate for the above configured Base DN. As a fallback, the provider uses a self-signed certificate. DNS name for which the above configured certificate should be used. The certificate cannot be detected based on the base DN, as the SSL/TLS negotiation happens before such data is exchanged. DNS name for which the above configured certificate should be used. The certificate cannot be detected based on the base DN, as the SSL/TLS negotiation happens before such data is exchanged. The start for uidNumbers, this number is added to the user.Pk to make sure that the numbers aren't too low for POSIX users. Default is 2000 to ensure that we don't collide with local users uidNumber The start for uidNumbers, this number is added to the user.Pk to make sure that the numbers aren't too low for POSIX users. Default is 2000 to ensure that we don't collide with local users uidNumber The start for gidNumbers, this number is added to a number generated from the group.Pk to make sure that the numbers aren't too low for POSIX groups. Default is 4000 to ensure that we don't collide with local groups or users primary groups gidNumber The start for gidNumbers, this number is added to a number generated from the group.Pk to make sure that the numbers aren't too low for POSIX groups. Default is 4000 to ensure that we don't collide with local groups or users primary groups gidNumber Provider Name Provider Name Type a provider name... Type a provider name... Configure how the outpost authenticates requests. Configure how the outpost authenticates requests. Configure how the outpost queries the core authentik server's users. Configure how the outpost queries the core authentik server's users. Code-based MFA Support Code-based MFA Support Flow settings Flow settings Flow used for users to authenticate. Flow used for users to authenticate. Flow used for unbinding users. Flow used for unbinding users. Protocol settings Protocol settings Base DN Base DN LDAP DN under which bind requests and search requests can be made. LDAP DN under which bind requests and search requests can be made. Configure LDAP Provider Configure LDAP Provider Show field content Show field content Hide field content Hide field content Add entry Add entry Strict Strict Regex Regex URL URL Confidential Confidential Confidential clients are capable of maintaining the confidentiality of their credentials such as client secrets Confidential clients are capable of maintaining the confidentiality of their credentials such as client secrets Public Public Public clients are incapable of maintaining the confidentiality and should use methods like PKCE. Public clients are incapable of maintaining the confidentiality and should use methods like PKCE. Back-channel Back-channel Server-to-server logout notifications Server-to-server logout notifications Front-channel Front-channel Browser iframe logout notifications Browser iframe logout notifications Based on the User's hashed ID Based on the User's hashed ID Based on the User's ID Based on the User's ID Based on the User's UUID Based on the User's UUID Based on the User's username Based on the User's username Based on the User's Email Based on the User's Email This is recommended over the UPN mode. This is recommended over the UPN mode. Based on the User's UPN Based on the User's UPN Requires the user to have a 'upn' attribute set, and falls back to hashed user ID. Use this mode only if you have different UPN and Mail domains. Requires the user to have a 'upn' attribute set, and falls back to hashed user ID. Use this mode only if you have different UPN and Mail domains. Each provider has a different issuer, based on the application slug Each provider has a different issuer, based on the application slug Same identifier is used for all providers Same identifier is used for all providers To allow any redirect URI, set the mode to Regex and the value to ".*". Be aware of the possible security implications this can have. To allow any redirect URI, set the mode to Regex and the value to ".*". Be aware of the possible security implications this can have. Authorization flow Authorization flow Select an authorization flow... Select an authorization flow... Flow used when authorizing this provider. Flow used when authorizing this provider. Client ID معرّف العميل Client Secret سر العميل Redirect URIs/Origins (RegEx) Redirect URIs/Origins (RegEx) Logout URI Logout URI URI to send logout notifications to when users log out. Required for OpenID Connect Logout functionality. URI to send logout notifications to when users log out. Required for OpenID Connect Logout functionality. Logout Method Logout Method The logout method determines how the logout URI is called — back-channel (server-to-server) or front-channel (browser iframe). The logout method determines how the logout URI is called — back-channel (server-to-server) or front-channel (browser iframe). Signing Key Signing Key Select a signing key... Select a signing key... Key used to sign the tokens. Key used to sign the tokens. Advanced flow settings Advanced flow settings Select an authentication flow... Select an authentication flow... Flow used when a user access this provider and is not authenticated. Flow used when a user access this provider and is not authenticated. Select an invalidation flow... Select an invalidation flow... Flow used when logging out of this provider. Flow used when logging out of this provider. Advanced protocol settings Advanced protocol settings Configure how long access codes are valid for. Configure how long access codes are valid for. Configure how long access tokens are valid for. Configure how long access tokens are valid for. Configure how long refresh tokens are valid for. Configure how long refresh tokens are valid for. When renewing a refresh token, if the existing refresh token's expiry is within this threshold, the refresh token will be renewed. Set to seconds=0 to always renew the refresh token. When renewing a refresh token, if the existing refresh token's expiry is within this threshold, the refresh token will be renewed. Set to seconds=0 to always renew the refresh token. Scopes النطاقات Available Scopes Available Scopes Selected Scopes Selected Scopes Select which scopes can be used by the client. The client still has to specify the scope to access the data. Select which scopes can be used by the client. The client still has to specify the scope to access the data. Encryption Key Encryption Key Select an encryption key... Select an encryption key... Key used to encrypt the tokens. Only enable this if the application using this provider supports JWE tokens. Key used to encrypt the tokens. Only enable this if the application using this provider supports JWE tokens. authentik only supports RSA-OAEP-256 for encryption. authentik only supports RSA-OAEP-256 for encryption. Configure what data should be used as unique User Identifier. For most cases, the default should be fine. Configure what data should be used as unique User Identifier. For most cases, the default should be fine. Include claims in id_token Include claims in id_token Include User claims from scopes in the id_token, for applications that don't access the userinfo endpoint. Include User claims from scopes in the id_token, for applications that don't access the userinfo endpoint. Issuer mode Issuer mode Configure how the issuer field of the ID Token should be filled. Configure how the issuer field of the ID Token should be filled. Machine-to-Machine authentication settings Machine-to-Machine authentication settings Federated OIDC Sources Federated OIDC Sources Available Sources Available Sources Selected Sources Selected Sources JWTs signed by certificates configured in the selected sources can be used to authenticate to this provider. JWTs signed by certificates configured in the selected sources can be used to authenticate to this provider. Available Providers Available Providers Selected Providers Selected Providers JWTs signed by the selected providers can be used to authenticate to this provider. JWTs signed by the selected providers can be used to authenticate to this provider. Configure OAuth2 Provider Configure OAuth2 Provider Successfully updated provider. Successfully updated provider. Successfully created provider. Successfully created provider. An error occurred while updating the provider. An error occurred while updating the provider. An error occurred while creating the provider. An error occurred while creating the provider. HTTP-Basic Username Key HTTP-Basic Username Key User/Group Attribute used for the user part of the HTTP-Basic Header. If not set, the user's Email address is used. User/Group Attribute used for the user part of the HTTP-Basic Header. If not set, the user's Email address is used. HTTP-Basic Password Key HTTP-Basic Password Key User/Group Attribute used for the password part of the HTTP-Basic Header. User/Group Attribute used for the password part of the HTTP-Basic Header. Proxy الوكيل Forward auth (single application) Forward auth (single application) Forward auth (domain level) Forward auth (domain level) This provider will behave like a transparent reverse-proxy, except requests must be authenticated. If your upstream application uses HTTPS, make sure to connect to the outpost using HTTPS as well. This provider will behave like a transparent reverse-proxy, except requests must be authenticated. If your upstream application uses HTTPS, make sure to connect to the outpost using HTTPS as well. External host External host The external URL you'll access the application at. Include any non-standard port. The external URL you'll access the application at. Include any non-standard port. Internal host Internal host http(s)://... http(s)://... Upstream host that the requests are forwarded to. Upstream host that the requests are forwarded to. Internal host SSL Validation Internal host SSL Validation Validate SSL Certificates of upstream servers. Validate SSL Certificates of upstream servers. Use this provider with nginx's auth_request or traefik's forwardAuth. Each application/domain needs its own provider. Additionally, on each domain, /outpost.goauthentik.io must be routed to the outpost (when using a managed outpost, this is done for you). Use this provider with nginx's auth_request or traefik's forwardAuth. Each application/domain needs its own provider. Additionally, on each domain, /outpost.goauthentik.io must be routed to the outpost (when using a managed outpost, this is done for you). Use this provider with nginx's auth_request or traefik's forwardAuth. Only a single provider is required per root domain. You can't do per-application authorization, but you don't have to create a provider for each application. Use this provider with nginx's auth_request or traefik's forwardAuth. Only a single provider is required per root domain. You can't do per-application authorization, but you don't have to create a provider for each application. An example setup can look like this: An example setup can look like this: authentik running on auth.example.com authentik running on auth.example.com app1 running on app1.example.com app1 running on app1.example.com In this case, you'd set the Authentication URL to auth.example.com and Cookie domain to example.com. In this case, you'd set the Authentication URL to auth.example.com and Cookie domain to example.com. Authentication URL Authentication URL The external URL you'll authenticate at. The authentik core server should be reachable under this URL. The external URL you'll authenticate at. The authentik core server should be reachable under this URL. Cookie domain Cookie domain domain.tld domain.tld Set this to the domain you wish the authentication to be valid for. Must be a parent domain of the URL above. If you're running applications as app1.domain.tld, app2.domain.tld, set this to 'domain.tld'. Set this to the domain you wish the authentication to be valid for. Must be a parent domain of the URL above. If you're running applications as app1.domain.tld, app2.domain.tld, set this to 'domain.tld'. Token validity Token validity Configure how long tokens are valid for. Configure how long tokens are valid for. Additional scopes Additional scopes Additional scope mappings, which are passed to the proxy. Additional scope mappings, which are passed to the proxy. Unauthenticated URLs Unauthenticated URLs Unauthenticated Paths Unauthenticated Paths Regular expressions for which authentication is not required. Each new line is interpreted as a new expression. Regular expressions for which authentication is not required. Each new line is interpreted as a new expression. When using proxy or forward auth (single application) mode, the requested URL Path is checked against the regular expressions. When using forward auth (domain mode), the full requested URL including scheme and host is matched against the regular expressions. When using proxy or forward auth (single application) mode, the requested URL Path is checked against the regular expressions. When using forward auth (domain mode), the full requested URL including scheme and host is matched against the regular expressions. Authentication settings Authentication settings Intercept header authentication Intercept header authentication When enabled, authentik will intercept the Authorization header to authenticate the request. When enabled, authentik will intercept the Authorization header to authenticate the request. Send HTTP-Basic Authentication Send HTTP-Basic Authentication Send a custom HTTP-Basic Authentication header based on values from authentik. Send a custom HTTP-Basic Authentication header based on values from authentik. Configure Proxy Provider Configure Proxy Provider Configure Remote Access Provider Configure Remote Access Provider Connection expiry Connection expiry Determines how long a session lasts before being disconnected and requiring re-authorization. Determines how long a session lasts before being disconnected and requiring re-authorization. Property mappings Property mappings Available Property Mappings Available Property Mappings Selected Property Mappings Selected Property Mappings Shared secret Shared secret Client Networks Client Networks Certificate used for EAP-TLS. Requires Mutual TLS Stage in authentication flow. Certificate used for EAP-TLS. Requires Mutual TLS Stage in authentication flow. Configure Radius Provider Configure Radius Provider Redirect إعادة التوجيه Post Post Sign assertions Sign assertions When enabled, the assertion element of the SAML response will be signed. When enabled, the assertion element of the SAML response will be signed. Sign responses Sign responses When enabled, the SAML response will be signed. When enabled, the SAML response will be signed. Sign logout requests Sign logout requests When enabled, SAML logout requests will be signed. When enabled, SAML logout requests will be signed. Front-channel (Iframe) Front-channel (Iframe) Front-channel (Native) Front-channel (Native) Back-channel (POST) Back-channel (POST) SLS Binding SLS Binding Determines how authentik sends the logout response back to the Service Provider. Determines how authentik sends the logout response back to the Service Provider. Method to use for logout when SLS URL is configured. Method to use for logout when SLS URL is configured. ACS URL ACS URL Service Provider Binding Service Provider Binding Determines how authentik sends the response back to the Service Provider. Determines how authentik sends the response back to the Service Provider. Issuer المُصدِر Audience الجمهور SLS URL SLS URL Optional Single Logout Service URL to send logout responses to. If not set, no logout response will be sent. Optional Single Logout Service URL to send logout responses to. If not set, no logout response will be sent. Signing Certificate Signing Certificate Certificate used to sign outgoing Responses going to the Service Provider. Certificate used to sign outgoing Responses going to the Service Provider. Verification Certificate Verification Certificate When selected, incoming assertion's Signatures will be validated against this certificate. To allow unsigned Requests, leave on default. When selected, incoming assertion's Signatures will be validated against this certificate. To allow unsigned Requests, leave on default. Encryption Certificate Encryption Certificate When selected, assertions will be encrypted using this keypair. When selected, assertions will be encrypted using this keypair. Available User Property Mappings Available User Property Mappings Selected User Property Mappings Selected User Property Mappings NameID Property Mapping NameID Property Mapping Configure how the NameID value will be created. When left empty, the NameIDPolicy of the incoming request will be respected. Configure how the NameID value will be created. When left empty, the NameIDPolicy of the incoming request will be respected. AuthnContextClassRef Property Mapping AuthnContextClassRef Property Mapping Configure how the AuthnContextClassRef value will be created. When left empty, the AuthnContextClassRef will be set based on which authentication methods the user used to authenticate. Configure how the AuthnContextClassRef value will be created. When left empty, the AuthnContextClassRef will be set based on which authentication methods the user used to authenticate. Assertion valid not before Assertion valid not before Configure the maximum allowed time drift for an assertion. Configure the maximum allowed time drift for an assertion. Assertion valid not on or after Assertion valid not on or after Assertion not valid on or after current time + this value. Assertion not valid on or after current time + this value. Session valid not on or after Session valid not on or after Session not valid on or after current time + this value. Session not valid on or after current time + this value. Default relay state Default relay state When using IDP-initiated logins, the relay state will be set to this value. When using IDP-initiated logins, the relay state will be set to this value. Default NameID Policy Default NameID Policy Persistent Persistent Email address Email address Windows Windows X509 Subject X509 Subject Transient Transient Configure the default NameID Policy used by IDP-initiated logins and when an incoming assertion doesn't specify a NameID Policy (also applies when using a custom NameID Mapping). Configure the default NameID Policy used by IDP-initiated logins and when an incoming assertion doesn't specify a NameID Policy (also applies when using a custom NameID Mapping). Digest algorithm Digest algorithm Signature algorithm Signature algorithm Configure SAML Provider Configure SAML Provider Token رمز Token to authenticate with. Token to authenticate with. OAuth Source OAuth Source Specify OAuth source used for authentication. Specify OAuth source used for authentication. OAuth Parameters OAuth Parameters Additional OAuth parameters, such as grant_type. Additional OAuth parameters, such as grant_type. SCIM base url, usually ends in /v2. SCIM base url, usually ends in /v2. Verify SCIM server's certificates Verify SCIM server's certificates Authentication Mode Authentication Mode Authenticate SCIM requests using a static token. Authenticate SCIM requests using a static token. Authenticate SCIM requests using OAuth. Authenticate SCIM requests using OAuth. Compatibility Mode Compatibility Mode Default افتراضي Default behavior. Default behavior. AWS AWS Altered behavior for usage with Amazon Web Services. Altered behavior for usage with Amazon Web Services. Slack Slack Altered behavior for usage with Slack. Altered behavior for usage with Slack. Salesforce Salesforce Altered behavior for usage with Salesforce. Altered behavior for usage with Salesforce. Alter authentik's behavior for vendor-specific SCIM implementations. Alter authentik's behavior for vendor-specific SCIM implementations. Enable dry-run mode Enable dry-run mode When enabled, mutating requests will be dropped and logged instead. When enabled, mutating requests will be dropped and logged instead. User filtering User filtering Exclude service accounts Exclude service accounts Only sync users within the selected group. Only sync users within the selected group. Attribute mapping Attribute mapping User Property Mappings User Property Mappings Property mappings used to user mapping. Property mappings used to user mapping. Group Property Mappings Group Property Mappings Available Group Property Mappings Available Group Property Mappings Selected Group Property Mappings Selected Group Property Mappings Property mappings used to group creation. Property mappings used to group creation. Sync settings Sync settings Page size Page size Controls the number of objects synced in a single task. Controls the number of objects synced in a single task. Page timeout Page timeout Timeout for synchronization of a single page. Timeout for synchronization of a single page. Configure SCIM Provider Configure SCIM Provider Configure Provider Configure Provider Type النوع None لا شيء strict strict regexp regexp Forward auth (domain-level) Forward auth (domain-level) Unknown proxy mode Unknown proxy mode Mode الوضع Internal Host Internal Host External Host External Host Basic-Auth Basic-Auth Unknown type Unknown type Redirect URIs عناوين URI لإعادة التوجيه Review and Submit Application Review and Submit Application There was an error in the application. There was an error in the application. Review the application. Review the application. There was an error in the provider. There was an error in the provider. Review the provider. Review the provider. There was an error. Please go back and review the application. There was an error. Please go back and review the application. There was an error: There was an error: Please go back and review the application. Please go back and review the application. There was an error creating the application, but no error message was sent. Please review the server logs. There was an error creating the application, but no error message was sent. Please review the server logs. Review the Application and Provider Review the Application and Provider Provider موفّر Your application has been saved Your application has been saved Saving application... Saving application... authentik was unable to complete this process. authentik was unable to complete this process. Don't show this message again. Don't show this message again. Successfully imported provider. Successfully imported provider. Metadata البيانات الوصفية Create إنشاء New Provider New Provider Open the wizard to create a new provider. Open the wizard to create a new provider. Credentials Credentials Google Cloud credentials file. Google Cloud credentials file. Delegated Subject Delegated Subject Email address of the user the actions of authentik will be delegated to. Email address of the user the actions of authentik will be delegated to. Default group email domain Default group email domain Default domain that is used to generate a group's email address. Can be customized using property mappings. Default domain that is used to generate a group's email address. Can be customized using property mappings. User deletion action User deletion action User is deleted User is deleted Suspend تعليق User is suspended, and connection to user in authentik is removed. User is suspended, and connection to user in authentik is removed. Do Nothing Do Nothing The connection is removed but the user is not modified The connection is removed but the user is not modified Determines what authentik will do when a User is deleted. Determines what authentik will do when a User is deleted. Group deletion action Group deletion action Group is deleted Group is deleted The connection is removed but the group is not modified The connection is removed but the group is not modified Determines what authentik will do when a Group is deleted. Determines what authentik will do when a Group is deleted. Client ID for the app registration. Client ID for the app registration. Client secret for the app registration. Client secret for the app registration. Tenant ID Tenant ID ID of the tenant accounts will be synced into. ID of the tenant accounts will be synced into. Delete authorization on disconnect Delete authorization on disconnect When enabled, connection authorizations will be deleted when a client disconnects. This will force clients with flaky internet connections to re-authorize the endpoint. When enabled, connection authorizations will be deleted when a client disconnects. This will force clients with flaky internet connections to re-authorize the endpoint. Connection settings. Connection settings. Key used to sign the events. Key used to sign the events. Event Retention Event Retention Determines how long events are stored for. If an event could not be sent correctly, its expiration is also increased by this duration. Determines how long events are stored for. If an event could not be sent correctly, its expiration is also increased by this duration. Providers الموفّرون Provide support for protocols like SAML and OAuth to assigned applications. Provide support for protocols like SAML and OAuth to assigned applications. Provider Search Provider Search Provider(s) Provider(s) Assigned to application Assigned to application Assigned to application (backchannel) Assigned to application (backchannel) Provider not assigned to any application. Provider not assigned to any application. Successfully triggered sync. Successfully triggered sync. Log messages Log messages Override dry-run mode Override dry-run mode When enabled, this sync will still execute mutating requests regardless of the dry-run mode in the provider. When enabled, this sync will still execute mutating requests regardless of the dry-run mode in the provider. Sync مزامنة Sync Group Sync Group Google Workspace Group(s) Google Workspace Group(s) Sync User Sync User Google Workspace User(s) Google Workspace User(s) Username اسم المستخدم Current status Current status Sync is currently running. Sync is currently running. Sync is not currently running. Sync is not currently running. Last successful sync Last successful sync No successful sync found. No successful sync found. Last sync status Last sync status Changelog Changelog Provisioned Users Provisioned Users Provisioned Groups Provisioned Groups Warning: Provider is not assigned to an application as backchannel provider. Warning: Provider is not assigned to an application as backchannel provider. Dry-run Dry-run Update Google Workspace Provider Update Google Workspace Provider Either input a full URL, a relative path, or use 'fa://fa-test' to use the Font Awesome icon "fa-test". Either input a full URL, a relative path, or use 'fa://fa-test' to use the Font Awesome icon "fa-test". Path template for users created. Use placeholders like `%(slug)s` to insert the source slug. Path template for users created. Use placeholders like `%(slug)s` to insert the source slug. Successfully updated application. Successfully updated application. Successfully created application. Successfully created application. Using this form will only create an Application. In order to authenticate with the application, you will have to manually pair it with a Provider. Using this form will only create an Application. In order to authenticate with the application, you will have to manually pair it with a Provider. Select a provider that this application should use. Select a provider that this application should use. Backchannel Providers Backchannel Providers Select backchannel providers which augment the functionality of the main provider. Select backchannel providers which augment the functionality of the main provider. Add provider Add provider UI settings UI settings Icon أيقونة Publisher الناشر Description الوصف Create Application Create Application Warning: Provider is not used by any Outpost. Warning: Provider is not used by any Outpost. Assigned to application Assigned to application Update LDAP Provider Update LDAP Provider How to connect How to connect Connect to the LDAP Server on port 389: Connect to the LDAP Server on port 389: Check the IP of the Kubernetes service, or Check the IP of the Kubernetes service, or The Host IP of the docker host The Host IP of the docker host Bind DN Bind DN Bind Password Bind Password Your authentik password Your authentik password Search base Search base Microsoft Entra Group(s) Microsoft Entra Group(s) Microsoft Entra User(s) Microsoft Entra User(s) Update Microsoft Entra Provider Update Microsoft Entra Provider Preview معاينة Warning: Provider is not used by an Application. Warning: Provider is not used by an Application. OpenID Configuration URL OpenID Configuration URL OpenID Configuration Issuer OpenID Configuration Issuer Authorize URL Authorize URL Token URL Token URL Userinfo URL Userinfo URL Logout URL Logout URL JWKS URL JWKS URL JWT payload JWT payload Preview for user Preview for user Nginx (Ingress) Nginx (Ingress) Nginx (Proxy Manager) Nginx (Proxy Manager) Nginx (standalone) Nginx (standalone) Traefik (Ingress) Traefik (Ingress) Traefik (Compose) Traefik (Compose) Traefik (Standalone) Traefik (Standalone) Caddy (Standalone) Caddy (Standalone) Update Proxy Provider Update Proxy Provider Protocol Settings Protocol Settings Allowed Redirect URIs Allowed Redirect URIs Setup Setup No additional setup is required. No additional setup is required. Connection Token(s) Connection Token(s) Endpoint نقطة نهاية Successfully updated endpoint. Successfully updated endpoint. Successfully created endpoint. Successfully created endpoint. Protocol Protocol RDP RDP SSH SSH VNC VNC Host Host Hostname/IP to connect to. Optionally specify the port. Hostname/IP to connect to. Optionally specify the port. Maximum concurrent connections Maximum concurrent connections Maximum concurrent allowed connections to this endpoint. Can be set to -1 to disable the limit. Maximum concurrent allowed connections to this endpoint. Can be set to -1 to disable the limit. Advanced settings Advanced settings Search for users by username or display name... Search for users by username or display name... Search Users Search Users Select Users Select Users Active نشط Last login آخر تسجيل دخول Select users Select users Confirm تأكيد Successfully updated group. Successfully updated group. Successfully created group. Successfully created group. Type a group name... Type a group name... Group Name Group Name Superuser Privileges Superuser Privileges Whether users added to this group will have superuser privileges. Whether users added to this group will have superuser privileges. Roles الأدوار Available Roles Available Roles Selected Roles Selected Roles Select roles to grant this groups' users' permissions from the selected roles. Select roles to grant this groups' users' permissions from the selected roles. Set custom attributes using YAML or JSON. Set custom attributes using YAML or JSON. Successfully updated binding. Successfully updated binding. Successfully created binding. Successfully created binding. Result used when policy execution fails. Result used when policy execution fails. Successfully updated policy. Successfully updated policy. Successfully created policy. Successfully created policy. A policy used for testing. Always returns the same result as specified below after waiting a random duration. A policy used for testing. Always returns the same result as specified below after waiting a random duration. Execution logging Execution logging When this option is enabled, all executions of this policy will be logged. By default, only execution errors are logged. When this option is enabled, all executions of this policy will be logged. By default, only execution errors are logged. Policy-specific settings Policy-specific settings Pass policy? Pass policy? Wait (min) Wait (min) The policy takes a random time to execute. This controls the minimum time it will take. The policy takes a random time to execute. This controls the minimum time it will take. Wait (max) Wait (max) Matches an event against a set of criteria. If any of the configured values match, the policy passes. Matches an event against a set of criteria. If any of the configured values match, the policy passes. Match created events with this action type. When left empty, all action types will be matched. Match created events with this action type. When left empty, all action types will be matched. Matches Event's Client IP (strict matching, for network matching use an Expression Policy). Matches Event's Client IP (strict matching, for network matching use an Expression Policy). Match events created by selected application. When left empty, all applications are matched. Match events created by selected application. When left empty, all applications are matched. Match events created by selected model. When left empty, all models are matched. Match events created by selected model. When left empty, all models are matched. Checks if the request's user's password has been changed in the last x days, and denys based on settings. Checks if the request's user's password has been changed in the last x days, and denys based on settings. Maximum age (in days) Maximum age (in days) Only fail the policy, don't invalidate user's password Only fail the policy, don't invalidate user's password Executes the python snippet to determine whether to allow or deny a request. Executes the python snippet to determine whether to allow or deny a request. Expression using Python. Expression using Python. See documentation for a list of all variables. See documentation for a list of all variables. Ensure the user satisfies requirements of geography or network topology, based on IP address. If any of the configured values match, the policy passes. Ensure the user satisfies requirements of geography or network topology, based on IP address. If any of the configured values match, the policy passes. Distance settings Distance settings Check historical distance of logins Check historical distance of logins When this option enabled, the GeoIP data of the policy request is compared to the specified number of historical logins. When this option enabled, the GeoIP data of the policy request is compared to the specified number of historical logins. Maximum distance Maximum distance Maximum distance a login attempt is allowed from in kilometers. Maximum distance a login attempt is allowed from in kilometers. Distance tolerance Distance tolerance Tolerance in checking for distances in kilometers. Tolerance in checking for distances in kilometers. Historical Login Count Historical Login Count Amount of previous login events to check against. Amount of previous login events to check against. Check impossible travel Check impossible travel When this option enabled, the GeoIP data of the policy request is compared to the specified number of historical logins and if the travel would have been possible in the amount of time since the previous event. When this option enabled, the GeoIP data of the policy request is compared to the specified number of historical logins and if the travel would have been possible in the amount of time since the previous event. Impossible travel tolerance Impossible travel tolerance Static rule settings Static rule settings ASNs ASNs List of autonomous system numbers. Comma separated. E.g. 13335, 15169, 20940 List of autonomous system numbers. Comma separated. E.g. 13335, 15169, 20940 Countries Countries Available Countries Available Countries Selected Countries Selected Countries Static rules Static rules Minimum length Minimum length Minimum amount of Uppercase Characters Minimum amount of Uppercase Characters Minimum amount of Lowercase Characters Minimum amount of Lowercase Characters Minimum amount of Digits Minimum amount of Digits Minimum amount of Symbols Characters Minimum amount of Symbols Characters Error message Error message Symbol charset Symbol charset Characters which are considered as symbols. Characters which are considered as symbols. HaveIBeenPwned settings HaveIBeenPwned settings Allowed count Allowed count Allow up to N occurrences in the HIBP database. Allow up to N occurrences in the HIBP database. zxcvbn settings zxcvbn settings Score threshold Score threshold If the password's score is less than or equal this value, the policy will fail. If the password's score is less than or equal this value, the policy will fail. Checks the value from the policy request against several rules, mostly used to ensure password strength. Checks the value from the policy request against several rules, mostly used to ensure password strength. Password field Password field Field key to check, field keys defined in Prompt stages are available. Field key to check, field keys defined in Prompt stages are available. Check static rules Check static rules Check haveibeenpwned.com Check haveibeenpwned.com For more info see: For more info see: Check zxcvbn Check zxcvbn Password strength estimator created by Dropbox, see: Password strength estimator created by Dropbox, see: Allows/denys requests based on the users and/or the IPs reputation. Allows/denys requests based on the users and/or the IPs reputation. Invalid login attempts will decrease the score for the client's IP, and the username they are attempting to login as, by one. Invalid login attempts will decrease the score for the client's IP, and the username they are attempting to login as, by one. The policy passes when the reputation score is below the threshold, and doesn't pass when either or both of the selected options are equal or above the threshold. The policy passes when the reputation score is below the threshold, and doesn't pass when either or both of the selected options are equal or above the threshold. Check IP Check IP Check Username Check Username Threshold Threshold Ensure that the user's new password is different from their previous passwords. The number of past passwords to check is configurable. Ensure that the user's new password is different from their previous passwords. The number of past passwords to check is configurable. Number of previous passwords to check Number of previous passwords to check Create Binding Create Binding Members الأعضاء Warning: Adding the user to the selected group(s) will give them superuser permissions. Warning: Adding the user to the selected group(s) will give them superuser permissions. Company employees with access to the full enterprise feature set. Company employees with access to the full enterprise feature set. External consultants or B2C customers without access to enterprise features. External consultants or B2C customers without access to enterprise features. Machine-to-machine authentication or other automations. Machine-to-machine authentication or other automations. Successfully created user and added to group Successfully created user and added to group Successfully created user. Successfully created user. The user's primary identifier used for authentication. 150 characters or fewer. The user's primary identifier used for authentication. 150 characters or fewer. Display Name Display Name Type an optional display name... Type an optional display name... The user's display name. The user's display name. User type User type Internal Service account Internal Service account Managed by authentik and cannot be assigned manually. Managed by authentik and cannot be assigned manually. Email Address Email Address Type an optional email address... Type an optional email address... Whether this user is active and allowed to authenticate. Setting this to inactive can be used to temporarily disable a user without deleting their account. Whether this user is active and allowed to authenticate. Setting this to inactive can be used to temporarily disable a user without deleting their account. Path Path Type a path for the user... Type a path for the user... Paths can be used to organize users into folders depending on which source created them or organizational structure. Paths can be used to organize users into folders depending on which source created them or organizational structure. Paths may not start or end with a slash, but they can contain any other character as path segments. The paths are currently purely used for organization, it does not affect their permissions, group memberships, or anything else. Paths may not start or end with a slash, but they can contain any other character as path segments. The paths are currently purely used for organization, it does not affect their permissions, group memberships, or anything else. Edit Policy Edit Policy Edit Group Edit Group Edit User Edit User Policy binding(s) Policy binding(s) No Policies bound. No Policies bound. Policy actions Policy actions The currently selected policy engine mode is : The currently selected policy engine mode is : Endpoint(s) Endpoint(s) These bindings control which users will have access to this endpoint. Users must also have access to the application. These bindings control which users will have access to this endpoint. Users must also have access to the application. Connections الاتصالات Update RAC Provider Update RAC Provider Endpoints نقاط النهاية Update Radius Provider Update Radius Provider Download تنزيل Copy download URL Copy download URL Download signing certificate Download signing certificate Related objects Related objects Update SAML Provider Update SAML Provider SAML Configuration SAML Configuration EntityID/Issuer EntityID/Issuer SSO URL (IdP-initiated Login) SSO URL (IdP-initiated Login) SAML Metadata SAML Metadata Example SAML attributes Example SAML attributes NameID attribute NameID attribute SCIM Group(s) SCIM Group(s) SCIM User(s) SCIM User(s) Update SCIM Provider Update SCIM Provider Send us feedback! Send us feedback! SSF URL SSF URL No assigned application No assigned application Streams Streams Applications التطبيقات External applications that use as an identity provider via protocols like OAuth2 and SAML. All applications are shown here, even ones you cannot access. External applications that use as an identity provider via protocols like OAuth2 and SAML. All applications are shown here, even ones you cannot access. Application Icon Application Icon Provider Type Provider Type Applications Documentation Applications Documentation Application(s) Application(s) Application icon for "" Application icon for "" Update Application Update Application Edit "" Edit "" Open "" Open "" Open فتح Successfully cleared application cache Successfully cleared application cache Failed to delete application cache Failed to delete application cache Clear cache Clear cache Clear Application cache Clear Application cache Are you sure you want to clear the application cache? This will cause all policies to be re-evaluated on their next usage. Are you sure you want to clear the application cache? This will cause all policies to be re-evaluated on their next usage. Successfully sent test-request. Successfully sent test-request. Successfully updated entitlement. Successfully updated entitlement. Successfully created entitlement. Successfully created entitlement. Application entitlement(s) Application entitlement(s) Update Entitlement Update Entitlement These bindings control which users have access to this entitlement. These bindings control which users have access to this entitlement. No app entitlements created. No app entitlements created. This application does currently not have any application entitlements defined. This application does currently not have any application entitlements defined. Create Entitlement Create Entitlement Create entitlement Create entitlement Failed to fetch application "". Failed to fetch application "". Warning: Application is not used by any Outpost. Warning: Application is not used by any Outpost. Related ذو صلة Check access Check access Check Check Test اختبار Launch Launch Logins over the last week (per 8 hours) Logins over the last week (per 8 hours) Application entitlements Application entitlements These entitlements can be used to configure user access in this application. These entitlements can be used to configure user access in this application. Policy / Group / User Bindings Policy / Group / User Bindings Loading application... Loading application... Successfully updated device. Successfully updated device. Device name... Device name... Device name Device name Device Group Device Group Connector setup Connector setup Copy نسخ Download the latest package from here: Download the latest package from here: Afterwards, select the enrollment token you want to use: Afterwards, select the enrollment token you want to use: macOS macOS Linux Linux Configured connector does not support setup. Configured connector does not support setup. No connectors configured. Navigate to connectors in the sidebar and create a connector. No connectors configured. Navigate to connectors in the sidebar and create a connector. Unix Unix BSD BSD Android Android iOS iOS Devices الأجهزة OS OS Endpoint Devices are in preview. Endpoint Devices are in preview. Total devices Total devices Total count of devices across all groups Total count of devices across all groups Unreachable devices Unreachable devices Devices that authentik hasn't received information about in 24h. Devices that authentik hasn't received information about in 24h. Outdated agents Outdated agents Devices running an outdated version of an agent Devices running an outdated version of an agent Update Device Update Device Endpoint Device(s) Endpoint Device(s) Device Device Loading device... Loading device... Device details Device details Hostname Hostname Serial number Serial number Operating system Operating system Firewall enabled Firewall enabled Hardware Hardware Manufacturer Manufacturer CPU CPU x x Memory الذاكرة Disk encryption Disk encryption Users / Groups Users / Groups Processes Processes Connector name Connector name Flow used for users to authorize. Flow used for users to authorize. Certificate used for signing device compliance challenges. Certificate used for signing device compliance challenges. Session duration Session duration Configure how long an authenticated session is valid for. Configure how long an authenticated session is valid for. Terminate authenticated sessions on token expiry Terminate authenticated sessions on token expiry Refresh interval Refresh interval Interval how frequently the agent tries to update its config. Interval how frequently the agent tries to update its config. Unix settings Unix settings NSS User ID offset NSS User ID offset NSS Group ID offset NSS Group ID offset Connectors are required to create devices. Depending on connector type, agents either directly talk to them or they talk to and external API to create devices. Connectors are required to create devices. Depending on connector type, agents either directly talk to them or they talk to and external API to create devices. Connectors Connectors Connector(s) Connector(s) Successfully updated token. Successfully updated token. Successfully created token. Successfully created token. Expires on Expires on Token name Token name Expiring Expiring Expires? Expires? Expiry date Expiry date Enrollment Token(s) Enrollment Token(s) Copy token نسخ الرمز Enrollment Tokens Enrollment Tokens Device access groups Device access groups Create groups of devices to manage access. Create groups of devices to manage access. Device Group(s) Device Group(s) Successfully updated source. Successfully updated source. Successfully created source. Successfully created source. Link users on unique identifier Link users on unique identifier Link to a user with identical email address. Can have security implications when a source doesn't validate email addresses Link to a user with identical email address. Can have security implications when a source doesn't validate email addresses Use the user's email address, but deny enrollment when the email address already exists Use the user's email address, but deny enrollment when the email address already exists Link to a user with identical username. Can have security implications when a username is used with another source Link to a user with identical username. Can have security implications when a username is used with another source Use the user's username, but deny enrollment when the username already exists Use the user's username, but deny enrollment when the username already exists Unknown user matching mode Unknown user matching mode Link to a group with identical name. Can have security implications when a group is used with another source Link to a group with identical name. Can have security implications when a group is used with another source Use the group's name, but deny enrollment when the name already exists Use the group's name, but deny enrollment when the name already exists Promoted Promoted When enabled, this source will be displayed as a prominent button on the login page, instead of a small icon. When enabled, this source will be displayed as a prominent button on the login page, instead of a small icon. Update internal password on login Update internal password on login When the user logs in to authentik using this source password backend, update their credentials in authentik. When the user logs in to authentik using this source password backend, update their credentials in authentik. Sync users Sync users User password writeback User password writeback Enable this option to write password changes made in authentik back to Kerberos. Ignored if sync is disabled. Enable this option to write password changes made in authentik back to Kerberos. Ignored if sync is disabled. Realm settings Realm settings Realm Realm Kerberos 5 configuration Kerberos 5 configuration Kerberos 5 configuration. See man krb5.conf(5) for configuration format. If left empty, a default krb5.conf will be used. Kerberos 5 configuration. See man krb5.conf(5) for configuration format. If left empty, a default krb5.conf will be used. User matching mode User matching mode Group matching mode Group matching mode Sync connection settings Sync connection settings KAdmin type KAdmin type MIT krb5 kadmin MIT krb5 kadmin Heimdal kadmin Heimdal kadmin Sync principal Sync principal Principal used to authenticate to the KDC for syncing. Principal used to authenticate to the KDC for syncing. Sync password Sync password Password used to authenticate to the KDC for syncing. Optional if Sync keytab or Sync credentials cache is provided. Password used to authenticate to the KDC for syncing. Optional if Sync keytab or Sync credentials cache is provided. Sync keytab Sync keytab Keytab used to authenticate to the KDC for syncing. Optional if Sync password or Sync credentials cache is provided. Must be base64 encoded or in the form TYPE:residual. Keytab used to authenticate to the KDC for syncing. Optional if Sync password or Sync credentials cache is provided. Must be base64 encoded or in the form TYPE:residual. Sync credentials cache Sync credentials cache Credentials cache used to authenticate to the KDC for syncing. Optional if Sync password or Sync keytab is provided. Must be in the form TYPE:residual. Credentials cache used to authenticate to the KDC for syncing. Optional if Sync password or Sync keytab is provided. Must be in the form TYPE:residual. SPNEGO settings SPNEGO settings SPNEGO server name SPNEGO server name Force the use of a specific server name for SPNEGO. Must be in the form HTTP@domain Force the use of a specific server name for SPNEGO. Must be in the form HTTP@domain SPNEGO keytab SPNEGO keytab Keytab used for SPNEGO. Optional if SPNEGO credentials cache is provided. Must be base64 encoded or in the form TYPE:residual. Keytab used for SPNEGO. Optional if SPNEGO credentials cache is provided. Must be base64 encoded or in the form TYPE:residual. SPNEGO credentials cache SPNEGO credentials cache Credentials cache used for SPNEGO. Optional if SPNEGO keytab is provided. Must be in the form TYPE:residual. Credentials cache used for SPNEGO. Optional if SPNEGO keytab is provided. Must be in the form TYPE:residual. Kerberos Attribute mapping Kerberos Attribute mapping Property mappings for user creation. Property mappings for user creation. Property mappings for group creation. Property mappings for group creation. Flow to use when authenticating existing users. Flow to use when authenticating existing users. Enrollment flow Enrollment flow Flow to use when enrolling new users. Flow to use when enrolling new users. Additional settings Additional settings User path User path Login password is synced from LDAP into authentik automatically. Enable this option only to write password changes in authentik back to LDAP. Login password is synced from LDAP into authentik automatically. Enable this option only to write password changes in authentik back to LDAP. Sync groups Sync groups Delete Not Found Objects Delete Not Found Objects Delete authentik users and groups which were previously supplied by this source, but are now missing from it. Delete authentik users and groups which were previously supplied by this source, but are now missing from it. Connection settings Connection settings Server URI Server URI Specify multiple server URIs by separating them with a comma. Specify multiple server URIs by separating them with a comma. Enable StartTLS Enable StartTLS To use SSL instead, use 'ldaps://' and disable this option. To use SSL instead, use 'ldaps://' and disable this option. Use Server URI for SNI verification Use Server URI for SNI verification Required for servers using TLS 1.3+ Required for servers using TLS 1.3+ TLS Verification Certificate TLS Verification Certificate TLS Client authentication certificate TLS Client authentication certificate Client certificate keypair to authenticate against the LDAP Server's Certificate. Client certificate keypair to authenticate against the LDAP Server's Certificate. Bind CN Bind CN LDAP Attribute mapping LDAP Attribute mapping Parent group for all the groups imported from LDAP. Parent group for all the groups imported from LDAP. Additional User DN Additional User DN Additional user DN, prepended to the Base DN. Additional user DN, prepended to the Base DN. Additional Group DN Additional Group DN Additional group DN, prepended to the Base DN. Additional group DN, prepended to the Base DN. User object filter User object filter Consider Objects matching this filter to be Users. Consider Objects matching this filter to be Users. Group object filter Group object filter Consider Objects matching this filter to be Groups. Consider Objects matching this filter to be Groups. Group membership field Group membership field Field which contains members of a group. The value of this field is matched against User membership attribute. Field which contains members of a group. The value of this field is matched against User membership attribute. User membership attribute User membership attribute Attribute which matches the value of Group membership field. Attribute which matches the value of Group membership field. Lookup using user attribute Lookup using user attribute Field which contains DNs of groups the user is a member of. This field is used to lookup groups from users, e.g. 'memberOf'. To lookup nested groups in an Active Directory environment use 'memberOf:1.2.840.113556.1.4.1941:'. Field which contains DNs of groups the user is a member of. This field is used to lookup groups from users, e.g. 'memberOf'. To lookup nested groups in an Active Directory environment use 'memberOf:1.2.840.113556.1.4.1941:'. Object uniqueness field Object uniqueness field Field which contains a unique Identifier. Field which contains a unique Identifier. HTTP Basic Auth HTTP Basic Auth Include the client ID and secret as request parameters Include the client ID and secret as request parameters Plain Plain S256 S256 URL settings URL settings Authorization URL Authorization URL URL the user is redirect to to consent the authorization. URL the user is redirect to to consent the authorization. Access token URL Access token URL URL used by authentik to retrieve tokens. URL used by authentik to retrieve tokens. Profile URL Profile URL URL used by authentik to get user information. URL used by authentik to get user information. Request token URL Request token URL URL used to request the initial token. This URL is only required for OAuth 1. URL used to request the initial token. This URL is only required for OAuth 1. OIDC Well-known URL OIDC Well-known URL OIDC well-known configuration URL. Can be used to automatically configure the URLs above. OIDC well-known configuration URL. Can be used to automatically configure the URLs above. OIDC JWKS URL OIDC JWKS URL JSON Web Key URL. Keys from the URL will be used to validate JWTs from this source. JSON Web Key URL. Keys from the URL will be used to validate JWTs from this source. OIDC JWKS OIDC JWKS Raw JWKS data. Raw JWKS data. PKCE Method PKCE Method Configure Proof Key for Code Exchange for this source. Configure Proof Key for Code Exchange for this source. Authorization code authentication method Authorization code authentication method How to perform authentication during an authorization_code token request flow How to perform authentication during an authorization_code token request flow Consumer key Consumer key Also known as Client ID. Also known as Client ID. Consumer secret Consumer secret Also known as Client Secret. Also known as Client Secret. Additional scopes to be passed to the OAuth Provider, separated by space. To replace existing scopes, prefix with *. Additional scopes to be passed to the OAuth Provider, separated by space. To replace existing scopes, prefix with *. OAuth Attribute mapping OAuth Attribute mapping Load servers Load servers Re-authenticate with Plex Re-authenticate with Plex Allow friends to authenticate via Plex, even if you don't share any servers Allow friends to authenticate via Plex, even if you don't share any servers Allowed servers Allowed servers Select which server a user has to be a member of to be allowed to authenticate. Select which server a user has to be a member of to be allowed to authenticate. Plex Attribute mapping Plex Attribute mapping Verify Assertion Signature Verify Assertion Signature When enabled, authentik will look for a Signature inside of the Assertion element. When enabled, authentik will look for a Signature inside of the Assertion element. Verify Response Signature Verify Response Signature When enabled, authentik will look for a Signature inside of the Response element. When enabled, authentik will look for a Signature inside of the Response element. SSO URL SSO URL URL that the initial Login request is sent to. URL that the initial Login request is sent to. SLO URL SLO URL Optional URL if the IDP supports Single-Logout. Optional URL if the IDP supports Single-Logout. Binding Type Binding Type Redirect binding Redirect binding Post-auto binding Post-auto binding Post binding but the request is automatically sent and the user doesn't have to confirm. Post binding but the request is automatically sent and the user doesn't have to confirm. Post binding Post binding Signing keypair Signing keypair Keypair which is used to sign outgoing requests. Leave empty to disable signing. Keypair which is used to sign outgoing requests. Leave empty to disable signing. Allow IDP-initiated logins Allow IDP-initiated logins Allows authentication flows initiated by the IdP. This can be a security risk, as no validation of the request ID is done. Allows authentication flows initiated by the IdP. This can be a security risk, as no validation of the request ID is done. NameID Policy NameID Policy Delete temporary users after Delete temporary users after Time offset when temporary users should be deleted. This only applies if your IDP uses the NameID Format 'transient', and the user doesn't log out manually. Time offset when temporary users should be deleted. This only applies if your IDP uses the NameID Format 'transient', and the user doesn't log out manually. When selected, encrypted assertions will be decrypted using this keypair. When selected, encrypted assertions will be decrypted using this keypair. SAML Attribute mapping SAML Attribute mapping Pre-authentication flow Pre-authentication flow Flow used before authentication. Flow used before authentication. SCIM Attribute mapping SCIM Attribute mapping Bot username Bot username Bot token Bot token Request access to send messages from your bot Request access to send messages from your bot Telegram Attribute mapping Telegram Attribute mapping Federation and Social login Federation and Social login Sources of identities, which can either be synced into authentik's database, or can be used by users to authenticate and enroll themselves. Sources of identities, which can either be synced into authentik's database, or can be used by users to authenticate and enroll themselves. Source(s) Source(s) Disabled مُعطَّل Built-in Built-in Kerberos Source is in preview. Kerberos Source is in preview. Update Kerberos Source Update Kerberos Source Connectivity Connectivity Global status Global status Vendor Vendor OAuth Source OAuth Source Group mappings can only be checked if a user is already logged in when trying to access this source. Group mappings can only be checked if a user is already logged in when trying to access this source. User mappings can only be checked if a user is already logged in when trying to access this source. User mappings can only be checked if a user is already logged in when trying to access this source. Generic OpenID Connect Generic OpenID Connect Unknown provider type Unknown provider type Callback URL Callback URL Access Key Access Key Diagram Diagram Policy Bindings Policy Bindings These bindings control which users can access this source. You can only use policies here as access is checked before the user is authenticated. These bindings control which users can access this source. You can only use policies here as access is checked before the user is authenticated. Update Plex Source Update Plex Source Update SAML Source Update SAML Source Update SCIM Source Update SCIM Source SCIM Base URL SCIM Base URL Telegram bot Telegram bot Update Telegram Source Update Telegram Source Successfully updated mapping. Successfully updated mapping. Successfully created mapping. Successfully created mapping. Unconfigured Unconfigured This option will not be changed by this mapping. This option will not be changed by this mapping. General settings General settings Password كلمة المرور RDP settings RDP settings Ignore server certificate Ignore server certificate Enable wallpaper Enable wallpaper Enable font-smoothing Enable font-smoothing Enable full window dragging Enable full window dragging SAML Attribute Name SAML Attribute Name Attribute name used for SAML Assertions. Can be a URN OID, a schema reference, or a any other string. If this property mapping is used for NameID Property, this field is discarded. Attribute name used for SAML Assertions. Can be a URN OID, a schema reference, or a any other string. If this property mapping is used for NameID Property, this field is discarded. Friendly Name Friendly Name Optionally set the 'FriendlyName' value of the Assertion attribute. Optionally set the 'FriendlyName' value of the Assertion attribute. Scope name Scope name Scope which the client can specify to access these properties. Scope which the client can specify to access these properties. Description shown to the user when consenting. If left empty, the user won't be informed. Description shown to the user when consenting. If left empty, the user won't be informed. Active Directory User Active Directory User Active Directory Group Active Directory Group Property Mappings تعيينات الخصائص Control how authentik exposes and interprets information. Control how authentik exposes and interprets information. Property Mapping(s) Property Mapping(s) Identifier Identifier Unique identifier the token is referenced by. Unique identifier the token is referenced by. Intent Intent API Token API Token Used to access the API programmatically Used to access the API programmatically App password. App password. Used to login using a flow executor Used to login using a flow executor Tokens الرموز Tokens are used throughout authentik for Email validation stages, Recovery keys and API access. Tokens are used throughout authentik for Email validation stages, Recovery keys and API access. Token(s) Token(s) Create Token Create Token Token is managed by authentik. Token is managed by authentik. Update Token Update Token Editing is disabled for managed tokens Editing is disabled for managed tokens Successfully updated brand. Successfully updated brand. Successfully created brand. Successfully created brand. Domain Domain Matching is done based on domain suffix, so if you enter domain.tld, foo.domain.tld will still match. Matching is done based on domain suffix, so if you enter domain.tld, foo.domain.tld will still match. Use this brand for each domain that doesn't have a dedicated brand. Use this brand for each domain that doesn't have a dedicated brand. Branding settings Branding settings Title Title Branding shown in page title and several other places. Branding shown in page title and several other places. Logo Logo Logo shown in sidebar/header and flow executor. Logo shown in sidebar/header and flow executor. Favicon Favicon Icon shown in the browser tab. Icon shown in the browser tab. Default flow background Default flow background Default background used during flow execution. Can be overridden per flow. Default background used during flow execution. Can be overridden per flow. Custom CSS Custom CSS Custom CSS to apply to pages when this brand is active. Custom CSS to apply to pages when this brand is active. External user settings External user settings Default application Default application Select an application... Select an application... When configured, external users will automatically be redirected to this application when not attempting to access a different application When configured, external users will automatically be redirected to this application when not attempting to access a different application Default flows Default flows Flow used to authenticate users. If left empty, the first applicable flow sorted by the slug is used. Flow used to authenticate users. If left empty, the first applicable flow sorted by the slug is used. Flow used to logout. If left empty, the first applicable flow sorted by the slug is used. Flow used to logout. If left empty, the first applicable flow sorted by the slug is used. Recovery flow Recovery flow Select a recovery flow... Select a recovery flow... Unenrollment flow Unenrollment flow Select an unenrollment flow... Select an unenrollment flow... If set, users are able to unenroll themselves using this flow. If no flow is set, option is not shown. If set, users are able to unenroll themselves using this flow. If no flow is set, option is not shown. User settings flow User settings flow Select a user settings flow... Select a user settings flow... If set, users are able to configure details of their profile. If set, users are able to configure details of their profile. Device code flow Device code flow Select a device code flow... Select a device code flow... If set, the OAuth Device Code profile can be used, and the selected flow will be used to enter the code. If set, the OAuth Device Code profile can be used, and the selected flow will be used to enter the code. Other global settings Other global settings Web Certificate Web Certificate Client Certificates Client Certificates Available Certificates Available Certificates Selected Certificates Selected Certificates Set custom attributes using YAML or JSON. Any attributes set here will be inherited by users, if the request is handled by this brand. Set custom attributes using YAML or JSON. Any attributes set here will be inherited by users, if the request is handled by this brand. Search by domain or brand name... Search by domain or brand name... Brands العلامات التجارية Configure visual settings and defaults for different domains. Configure visual settings and defaults for different domains. Brand name Brand name Default? Default? Brand(s) Brand(s) Policies السياسات Allow users to use Applications based on properties, enforce Password Criteria and selectively apply Stages. Allow users to use Applications based on properties, enforce Password Criteria and selectively apply Stages. Assigned to object(s). Assigned to object(s). Warning: Policy is not assigned. Warning: Policy is not assigned. Policy / Policies Policy / Policies Successfully cleared policy cache Successfully cleared policy cache Failed to delete policy cache Failed to delete policy cache Clear Policy cache Clear Policy cache Are you sure you want to clear the policy cache? This will cause all policies to be re-evaluated on their next usage. Are you sure you want to clear the policy cache? This will cause all policies to be re-evaluated on their next usage. Reputation scores Reputation scores Reputation for IP and user identifiers. Scores are decreased for each failed login and increased for each successful login. Reputation for IP and user identifiers. Scores are decreased for each failed login and increased for each successful login. IP IP Score Score Updated تم التحديث Reputation Reputation Search for a group by name… Search for a group by name… Group Search Group Search Groups المجموعات Group users together and give them permissions based on the membership. Group users together and give them permissions based on the membership. Superuser privileges? Superuser privileges? Group(s) Group(s) View details of group "" View details of group "" Create group Create group Create and assign a group with the same name as the user. Create and assign a group with the same name as the user. Whether the token will expire. Upon expiration, the token will be rotated. Whether the token will expire. Upon expiration, the token will be rotated. Use the username and password below to authenticate. The password can be retrieved later on the Tokens page. Use the username and password below to authenticate. The password can be retrieved later on the Tokens page. Valid for 360 days, after which the password will automatically rotate. You can copy the password from the Token List. Valid for 360 days, after which the password will automatically rotate. You can copy the password from the Token List. Impersonating user... Impersonating user... This may take a few seconds. This may take a few seconds. Reason Reason Reason for impersonating the user Reason for impersonating the user A brief explanation of why you are impersonating the user. This will be included in audit logs. A brief explanation of why you are impersonating the user. This will be included in audit logs. New Password New Password Successfully updated password. Successfully updated password. Email stage Email stage Successfully added user(s). Successfully added user(s). Users Users Open user selection dialog Open user selection dialog Add users Add users User(s) User(s) removed removed Impersonate انتحال الهوية Temporarily assume the identity of this user Temporarily assume the identity of this user User status User status Inactive غير نشط Regular user Regular user Change status Change status Deactivate تعطيل Activate تفعيل Update 's password Update 's password Set password Set password Send link Send link Send recovery link to user Send recovery link to user Email recovery link Email recovery link Assign Additional Users Assign Additional Users Warning: This group is configured with superuser access. Added users will have superuser access. Warning: This group is configured with superuser access. Added users will have superuser access. New User New User This user will be added to the group "". This user will be added to the group "". Hide service-accounts Hide service-accounts Group Info Group Info Notes Notes Edit the notes attribute of this group to add notes here. Edit the notes attribute of this group to add notes here. Unnamed Unnamed Collapse "" Collapse "" Expand "" Expand "" Select "" Select "" Items of "" Items of "" Root Root Search by username, email, etc... Search by username, email, etc... User Search User Search No name set لم يتم تعيين اسم Create recovery link Create recovery link User folders User folders User paths User paths Successfully added user to group(s). Successfully added user to group(s). Groups to add Groups to add Add group Add group Remove from Group(s) Remove from Group(s) Are you sure you want to remove user from the following groups? Are you sure you want to remove user from the following groups? Add to existing group Add to existing group Add new group Add new group Application authorizations Application authorizations Revoked? Revoked? Expires تنتهي في ID Token ID Token Access Tokens(s) Access Tokens(s) Refresh Tokens(s) Refresh Tokens(s) Last IP Last IP Last used Last used Session(s) Session(s) Expiry Expiry (Current session) (Current session) Consent(s) Consent(s) Reputation score(s) Reputation score(s) Disconnect قطع الاتصال Successfully disconnected source Successfully disconnected source Failed to disconnected source: Failed to disconnected source: Connect اتصال Error: unsupported source settings: Error: unsupported source settings: "" source "" source No services available. No services available. Source Settings Source Settings Confirmed Confirmed Created at Created at Last updated at Last updated at Last used at Last used at Device type cannot be deleted Device type cannot be deleted Device(s) Device(s) Email البريد الإلكتروني Last password change Last password change User Info User Info Lock the user out of this system Lock the user out of this system Allow the user to log in and use this system Allow the user to log in and use this system Sessions الجلسات Explicit Consent Explicit Consent OAuth Access Tokens OAuth Access Tokens OAuth Refresh Tokens OAuth Refresh Tokens MFA Authenticators MFA Authenticators Connected services Connected services RAC Connections RAC Connections Actions over the last week (per 8 hours) Actions over the last week (per 8 hours) User events User events Credentials / Tokens Credentials / Tokens Successfully updated role. Successfully updated role. Successfully created role. Successfully created role. Manage roles which grant permissions to objects within authentik. Manage roles which grant permissions to objects within authentik. Role(s) Role(s) Successfully updated initial permissions. Successfully updated initial permissions. Successfully created initial permissions. Successfully created initial permissions. When a user with the selected Role creates an object, the Initial Permissions will be applied to that object. When a user with the selected Role creates an object, the Initial Permissions will be applied to that object. Available Permissions Available Permissions Selected Permissions Selected Permissions Permissions to grant when a new object is created. Permissions to grant when a new object is created. Initial Permissions Initial Permissions Set initial permissions for newly created objects. Set initial permissions for newly created objects. Role Info Role Info Role Role Successfully updated invitation. Successfully updated invitation. Successfully created invitation. Successfully created invitation. The name of an invitation must be a slug: only lower case letters, numbers, and the hyphen are permitted here. The name of an invitation must be a slug: only lower case letters, numbers, and the hyphen are permitted here. Flow تدفق Custom attributes Custom attributes Optional data which is loaded into the flow's 'prompt_data' context variable. YAML or JSON. Optional data which is loaded into the flow's 'prompt_data' context variable. YAML or JSON. Single use Single use When enabled, the invitation will be deleted after usage. When enabled, the invitation will be deleted after usage. Select an enrollment flow Select an enrollment flow Link to use the invitation. Link to use the invitation. Invitations الدعوات Create Invitation Links to enroll Users, and optionally force specific attributes of their account. Create Invitation Links to enroll Users, and optionally force specific attributes of their account. Created by Created by Invitation(s) Invitation(s) Invitation not limited to any flow, and can be used with any enrollment flow. Invitation not limited to any flow, and can be used with any enrollment flow. Warning: No invitation stage is bound to any flow. Invitations will not work as expected. Warning: No invitation stage is bound to any flow. Invitations will not work as expected. Not you? Not you? Required. Required. Continue متابعة Successfully updated prompt. Successfully updated prompt. Successfully created prompt. Successfully created prompt. Text: Simple Text input Text: Simple Text input Text Area: Multiline text input Text Area: Multiline text input Text (read-only): Simple Text input, but cannot be edited. Text (read-only): Simple Text input, but cannot be edited. Text Area (read-only): Multiline text input, but cannot be edited. Text Area (read-only): Multiline text input, but cannot be edited. Username: Same as Text input, but checks for and prevents duplicate usernames. Username: Same as Text input, but checks for and prevents duplicate usernames. Email: Text field with Email type. Email: Text field with Email type. Password: Masked input, multiple inputs of this type on the same prompt need to be identical. Password: Masked input, multiple inputs of this type on the same prompt need to be identical. Number Number Checkbox Checkbox Radio Button Group (fixed choice) Radio Button Group (fixed choice) Dropdown (fixed choice) Dropdown (fixed choice) Date التاريخ Date Time Date Time File File Separator: Static Separator Line Separator: Static Separator Line Hidden: Hidden field, can be used to insert data into form. Hidden: Hidden field, can be used to insert data into form. Static: Static value, displayed as-is. Static: Static value, displayed as-is. authentik: Locale: Displays a list of locales authentik supports. authentik: Locale: Displays a list of locales authentik supports. Preview errors Preview errors Data preview Data preview Unique name of this field, used for selecting fields in prompt stages. Unique name of this field, used for selecting fields in prompt stages. Field Key Field Key Name of the form field, also used to store the value. Name of the form field, also used to store the value. When used in conjunction with a User Write stage, use attributes.foo to write attributes. When used in conjunction with a User Write stage, use attributes.foo to write attributes. Label Label Label shown next to/above the prompt. Label shown next to/above the prompt. Interpret placeholder as expression Interpret placeholder as expression When checked, the placeholder will be evaluated in the same way a property mapping is. If the evaluation fails, the placeholder itself is returned. When checked, the placeholder will be evaluated in the same way a property mapping is. If the evaluation fails, the placeholder itself is returned. Placeholder Placeholder Optionally provide a short hint that describes the expected input value. When creating a fixed choice field, enable interpreting as expression and return a list to return multiple choices. Optionally provide a short hint that describes the expected input value. When creating a fixed choice field, enable interpreting as expression and return a list to return multiple choices. Interpret initial value as expression Interpret initial value as expression When checked, the initial value will be evaluated in the same way a property mapping is. If the evaluation fails, the initial value itself is returned. When checked, the initial value will be evaluated in the same way a property mapping is. If the evaluation fails, the initial value itself is returned. Initial value القيمة الأولية Optionally pre-fill the input with an initial value. When creating a fixed choice field, enable interpreting as expression and return a list to return multiple default choices. Optionally pre-fill the input with an initial value. When creating a fixed choice field, enable interpreting as expression and return a list to return multiple default choices. Help text نص المساعدة Any HTML can be used. Any HTML can be used. Prompts Prompts Single Prompts that can be used for Prompt Stages. Single Prompts that can be used for Prompt Stages. Field Field Stages المراحل Prompt(s) Prompt(s) Create Prompt Create Prompt Successfully updated stage. Successfully updated stage. Successfully created stage. Successfully created stage. Stage used to configure a duo-based authenticator. This stage should be used for configuration flows. Stage used to configure a duo-based authenticator. This stage should be used for configuration flows. Authenticator type name Authenticator type name Display name of this authenticator, used by users when they enroll an authenticator. Display name of this authenticator, used by users when they enroll an authenticator. API Hostname API Hostname Duo Auth API Duo Auth API Integration key Integration key Secret key Secret key Duo Admin API (optional) Duo Admin API (optional) When using a Duo MFA, Access or Beyond plan, an Admin API application can be created. This will allow authentik to import devices automatically. When using a Duo MFA, Access or Beyond plan, an Admin API application can be created. This will allow authentik to import devices automatically. Stage-specific settings Stage-specific settings Configuration flow Configuration flow Flow used by an authenticated user to configure this Stage. If empty, user will not be able to configure this stage. Flow used by an authenticated user to configure this Stage. If empty, user will not be able to configure this stage. SMTP Host SMTP Host SMTP Port SMTP Port SMTP Username SMTP Username SMTP Password SMTP Password Use TLS Use TLS Use SSL Use SSL From address From address Email address the verification email will be sent from. Email address the verification email will be sent from. Stage used to configure an email-based authenticator. Stage used to configure an email-based authenticator. Use global connection settings Use global connection settings When enabled, global email connection settings will be used and connection settings below will be ignored. When enabled, global email connection settings will be used and connection settings below will be ignored. Subject of the verification email. Subject of the verification email. Token expiration Token expiration Time the token sent is valid (Format: hours=3,minutes=17,seconds=300). Time the token sent is valid (Format: hours=3,minutes=17,seconds=300). Template Template Loading templates... Loading templates... Template used for the verification email. Template used for the verification email. Twilio Account SID Twilio Account SID Get this value from https://console.twilio.com Get this value from https://console.twilio.com Twilio Auth Token Twilio Auth Token Authentication Type Authentication Type Basic Auth Basic Auth Bearer Token Bearer Token External API URL External API URL This is the full endpoint to send POST requests to. This is the full endpoint to send POST requests to. API Auth Username API Auth Username This is the username to be used with basic auth or the token when used with bearer token This is the username to be used with basic auth or the token when used with bearer token API Auth password API Auth password This is the password to be used with basic auth This is the password to be used with basic auth Stage used to configure an SMS-based TOTP authenticator. Stage used to configure an SMS-based TOTP authenticator. Twilio Twilio Generic Generic From number From number Number the SMS will be sent from. Number the SMS will be sent from. Mapping Mapping Modify the payload sent to the provider. Modify the payload sent to the provider. Hash phone number Hash phone number If enabled, only a hash of the phone number will be saved. This can be done for data-protection reasons. Devices created from a stage with this enabled cannot be used with the authenticator validation stage. If enabled, only a hash of the phone number will be saved. This can be done for data-protection reasons. Devices created from a stage with this enabled cannot be used with the authenticator validation stage. Stage used to configure a static authenticator (i.e. static tokens). This stage should be used for configuration flows. Stage used to configure a static authenticator (i.e. static tokens). This stage should be used for configuration flows. Token count Token count The number of tokens generated whenever this stage is used. Every token generated per stage execution will be attached to a single static device. The number of tokens generated whenever this stage is used. Every token generated per stage execution will be attached to a single static device. Token length Token length Stage used to configure a TOTP authenticator (i.e. Authy/Google Authenticator). Stage used to configure a TOTP authenticator (i.e. Authy/Google Authenticator). Digits Digits 6 digits, widely compatible 6 digits, widely compatible 8 digits, not compatible with apps like Google Authenticator 8 digits, not compatible with apps like Google Authenticator Static Tokens Static Tokens TOTP Authenticators TOTP Authenticators WebAuthn Authenticators WebAuthn Authenticators Duo Authenticators Duo Authenticators SMS-based Authenticators SMS-based Authenticators Email-based Authenticators Email-based Authenticators Stage used to validate any authenticator. This stage should be used during authentication or authorization flows. Stage used to validate any authenticator. This stage should be used during authentication or authorization flows. Device classes which can be used to authenticate. Device classes which can be used to authenticate. Last validation threshold Last validation threshold If the user has successfully authenticated with a device in the classes listed above within this configured duration, this stage will be skipped. If the user has successfully authenticated with a device in the classes listed above within this configured duration, this stage will be skipped. Not configured action Not configured action Force the user to configure an authenticator Force the user to configure an authenticator Deny the user access Deny the user access Configuration stages Configuration stages Available Stages Available Stages Selected Stages Selected Stages Stages used to configure Authenticator when user doesn't have any compatible devices. After this configuration Stage passes, the user is not prompted again. Stages used to configure Authenticator when user doesn't have any compatible devices. After this configuration Stage passes, the user is not prompted again. When multiple stages are selected, the user can choose which one they want to enroll. When multiple stages are selected, the user can choose which one they want to enroll. WebAuthn-specific settings WebAuthn-specific settings WebAuthn User verification WebAuthn User verification User verification must occur. User verification must occur. User verification is preferred if available, but not required. User verification is preferred if available, but not required. User verification should not occur. User verification should not occur. WebAuthn Device type restrictions WebAuthn Device type restrictions Available Device types Available Device types Selected Device types Selected Device types Optionally restrict which WebAuthn device types may be used. When no device types are selected, all devices are allowed. Optionally restrict which WebAuthn device types may be used. When no device types are selected, all devices are allowed. Stage used to configure a WebAuthn authenticator (i.e. Yubikey, FaceID/Windows Hello). Stage used to configure a WebAuthn authenticator (i.e. Yubikey, FaceID/Windows Hello). User verification User verification Required: User verification must occur. Required: User verification must occur. Preferred: User verification is preferred if available, but not required. Preferred: User verification is preferred if available, but not required. Discouraged: User verification should not occur. Discouraged: User verification should not occur. Resident key requirement Resident key requirement Required: The authenticator MUST create a dedicated credential. If it cannot, the RP is prepared for an error to occur Required: The authenticator MUST create a dedicated credential. If it cannot, the RP is prepared for an error to occur Preferred: The authenticator can create and store a dedicated credential, but if it doesn't that's alright too Preferred: The authenticator can create and store a dedicated credential, but if it doesn't that's alright too Discouraged: The authenticator should not create a dedicated credential Discouraged: The authenticator should not create a dedicated credential Authenticator Attachment Authenticator Attachment Maximum registration attempts Maximum registration attempts Maximum allowed registration attempts. When set to 0 attempts, attempts are not limited. Maximum allowed registration attempts. When set to 0 attempts, attempts are not limited. Device type restrictions Device type restrictions Public Key Public Key Private Key Private Key Interactive Interactive Prompt for the user's consent. The consent can either be permanent or expire in a defined amount of time. Prompt for the user's consent. The consent can either be permanent or expire in a defined amount of time. Always require consent Always require consent Consent given lasts indefinitely Consent given lasts indefinitely Consent expires Consent expires Consent expires in Consent expires in Offset after which consent expires. Offset after which consent expires. Statically deny the flow. To use this stage effectively, disable *Evaluate when flow is planned* on the respective binding. Statically deny the flow. To use this stage effectively, disable *Evaluate when flow is planned* on the respective binding. Deny message Deny message Message shown when this stage is run. Message shown when this stage is run. Dummy stage used for testing. Shows a simple continue button and always passes. Dummy stage used for testing. Shows a simple continue button and always passes. Throw error? Throw error? Verify the user's email address by sending them a one-time-link. Can also be used for recovery to verify the user's authenticity. Verify the user's email address by sending them a one-time-link. Can also be used for recovery to verify the user's authenticity. Activate pending user on success Activate pending user on success When a user returns from the email successfully, their account will be activated. When a user returns from the email successfully, their account will be activated. Time the token sent is valid. Time the token sent is valid. Account Recovery Max Attempts Account Recovery Max Attempts Account Recovery Cache Timeout Account Recovery Cache Timeout The time window used to count recent account recovery attempts. The time window used to count recent account recovery attempts. A selection is required A selection is required UPN UPN Let the user identify themselves with their username or Email address. Let the user identify themselves with their username or Email address. Fields a user can identify themselves with. If no fields are selected, the user will only be able to use sources. Fields a user can identify themselves with. If no fields are selected, the user will only be able to use sources. Password stage Password stage When selected, a password field is shown on the same page instead of a separate page. This prevents username enumeration attacks. When selected, a password field is shown on the same page instead of a separate page. This prevents username enumeration attacks. Captcha stage Captcha stage When set, adds functionality exactly like a Captcha stage, but baked into the Identification stage. When set, adds functionality exactly like a Captcha stage, but baked into the Identification stage. Case insensitive matching Case insensitive matching When enabled, user fields are matched regardless of their casing. When enabled, user fields are matched regardless of their casing. Pretend user exists Pretend user exists When enabled, the stage will always accept the given user identifier and continue. When enabled, the stage will always accept the given user identifier and continue. Show matched user Show matched user When a valid username/email has been entered, and this option is enabled, the user's username and avatar will be shown. Otherwise, the text that the user entered will be shown. When a valid username/email has been entered, and this option is enabled, the user's username and avatar will be shown. Otherwise, the text that the user entered will be shown. Enable "Remember me on this device" Enable "Remember me on this device" When enabled, the user can save their username in a cookie, allowing them to skip directly to entering their password. When enabled, the user can save their username in a cookie, allowing them to skip directly to entering their password. Source settings Source settings Sources المصادر Select sources should be shown for users to authenticate with. This only affects web-based sources, not LDAP. Select sources should be shown for users to authenticate with. This only affects web-based sources, not LDAP. Show sources' labels Show sources' labels By default, only icons are shown for sources. Enable this to show their full names. By default, only icons are shown for sources. Enable this to show their full names. Passwordless flow Passwordless flow Optional passwordless flow, which is linked at the bottom of the page. When configured, users can use this flow to authenticate with a WebAuthn authenticator, without entering any details. Optional passwordless flow, which is linked at the bottom of the page. When configured, users can use this flow to authenticate with a WebAuthn authenticator, without entering any details. Optional enrollment flow, which is linked at the bottom of the page. Optional enrollment flow, which is linked at the bottom of the page. Optional recovery flow, which is linked at the bottom of the page. Optional recovery flow, which is linked at the bottom of the page. This stage can be included in enrollment flows to accept invitations. This stage can be included in enrollment flows to accept invitations. Continue flow without invitation Continue flow without invitation If this flag is set, this Stage will jump to the next Stage when no Invitation is given. By default this Stage will cancel the Flow when no invitation is given. If this flag is set, this Stage will jump to the next Stage when no Invitation is given. By default this Stage will cancel the Flow when no invitation is given. Client-certificate/mTLS authentication/enrollment. Client-certificate/mTLS authentication/enrollment. Certificate optional Certificate optional If no certificate was provided, this stage will succeed and continue to the next stage. If no certificate was provided, this stage will succeed and continue to the next stage. Certificate required Certificate required If no certificate was provided, this stage will stop flow execution. If no certificate was provided, this stage will stop flow execution. Certificate authorities Certificate authorities Configure the certificate authority client certificates are validated against. The certificate authority can also be configured on a brand, which allows for different certificate authorities for different domains. Configure the certificate authority client certificates are validated against. The certificate authority can also be configured on a brand, which allows for different certificate authorities for different domains. Certificate attribute Certificate attribute Common Name الاسم الشائع Configure the attribute of the certificate used to look for a user. Configure the attribute of the certificate used to look for a user. User attribute User attribute Configure the attribute of the user used to look for a user. Configure the attribute of the user used to look for a user. User database + standard password User database + standard password User database + app passwords User database + app passwords User database + LDAP password User database + LDAP password User database + Kerberos password User database + Kerberos password Validate the user's password against the selected backend(s). Validate the user's password against the selected backend(s). Backends Backends Selection of backends to test the password against. Selection of backends to test the password against. Flow used by an authenticated user to configure their password. If empty, user will not be able to change their password. Flow used by an authenticated user to configure their password. If empty, user will not be able to change their password. Failed attempts before cancel Failed attempts before cancel How many attempts a user has before the flow is canceled. To lock the user out, use a reputation policy and a user_write stage. How many attempts a user has before the flow is canceled. To lock the user out, use a reputation policy and a user_write stage. Provide users with a 'show password' button. Provide users with a 'show password' button. ("", of type ) ("", of type ) Fields Fields Available Fields Available Fields Selected Fields Selected Fields Validation Policies Validation Policies Available Policies Available Policies Selected Policies Selected Policies Selected policies are executed when the stage is submitted to validate the data. Selected policies are executed when the stage is submitted to validate the data. Static Static Target URL Target URL Redirect the user to a static URL. Redirect the user to a static URL. Target Flow Target Flow Redirect the user to a Flow. Redirect the user to a Flow. Keep flow context Keep flow context Inject an OAuth or SAML Source into the flow execution. This allows for additional user verification, or to dynamically access different sources for different user identifiers (username, email address, etc). Inject an OAuth or SAML Source into the flow execution. This allows for additional user verification, or to dynamically access different sources for different user identifiers (username, email address, etc). Source مصدر Resume timeout Resume timeout Amount of time a user can take to return from the source to continue the flow. Amount of time a user can take to return from the source to continue the flow. Delete the currently pending user. CAUTION, this stage does not ask for confirmation. Use a consent stage to ensure the user is aware of their actions. Delete the currently pending user. CAUTION, this stage does not ask for confirmation. Use a consent stage to ensure the user is aware of their actions. Log the currently pending user in. Log the currently pending user in. Determines how long a session lasts. Default of 0 seconds means that the sessions lasts until the browser is closed. Determines how long a session lasts. Default of 0 seconds means that the sessions lasts until the browser is closed. Different browsers handle session cookies differently, and might not remove them even when the browser is closed. Different browsers handle session cookies differently, and might not remove them even when the browser is closed. See here. See here. Stay signed in offset Stay signed in offset If set to a duration above 0, the user will have the option to choose to "stay signed in", which will extend their session by the time specified here. If set to a duration above 0, the user will have the option to choose to "stay signed in", which will extend their session by the time specified here. Remember device Remember device If set to a duration above 0, a cookie will be stored for the duration specified which will allow authentik to know if the user is signing in from a new device. If set to a duration above 0, a cookie will be stored for the duration specified which will allow authentik to know if the user is signing in from a new device. Network binding Network binding No binding No binding Bind ASN Bind ASN Bind ASN and Network Bind ASN and Network Bind ASN, Network and IP Bind ASN, Network and IP Configure if sessions created by this stage should be bound to the Networks they were created in. Configure if sessions created by this stage should be bound to the Networks they were created in. GeoIP binding GeoIP binding Bind Continent Bind Continent Bind Continent and Country Bind Continent and Country Bind Continent, Country and City Bind Continent, Country and City Configure if sessions created by this stage should be bound to their GeoIP-based location Configure if sessions created by this stage should be bound to their GeoIP-based location Terminate other sessions Terminate other sessions When enabled, all previous sessions of the user will be terminated. When enabled, all previous sessions of the user will be terminated. Remove the user from the current session. Remove the user from the current session. Write any data from the flow's context's 'prompt_data' to the currently pending user. If no user is pending, a new user is created, and data is written to them. Write any data from the flow's context's 'prompt_data' to the currently pending user. If no user is pending, a new user is created, and data is written to them. Never create users Never create users When no user is present in the flow context, the stage will fail. When no user is present in the flow context, the stage will fail. Create users when required Create users when required When no user is present in the the flow context, a new user is created. When no user is present in the the flow context, a new user is created. Always create new users Always create new users Create a new user even if a user is in the flow context. Create a new user even if a user is in the flow context. Create users as inactive Create users as inactive Mark newly created users as inactive. Mark newly created users as inactive. Internal users might be users such as company employees, which will get access to the full Enterprise feature set. Internal users might be users such as company employees, which will get access to the full Enterprise feature set. External users might be external consultants or B2C customers. These users don't get access to enterprise features. External users might be external consultants or B2C customers. These users don't get access to enterprise features. Service accounts should be used for machine-to-machine authentication or other automations. Service accounts should be used for machine-to-machine authentication or other automations. User type used for newly created users. User type used for newly created users. User path template User path template Path new users will be created under. If left blank, the default path will be used. Path new users will be created under. If left blank, the default path will be used. Newly created users are added to this group, if a group is selected. Newly created users are added to this group, if a group is selected. Target Target Stage مرحلة Evaluate when flow is planned Evaluate when flow is planned Evaluate policies during the Flow planning process. Evaluate policies during the Flow planning process. Evaluate when stage is run Evaluate when stage is run Evaluate policies before the Stage is presented to the user. Evaluate policies before the Stage is presented to the user. Invalid response behavior Invalid response behavior Returns the error message and a similar challenge to the executor Returns the error message and a similar challenge to the executor Restarts the flow from the beginning Restarts the flow from the beginning Restarts the flow from the beginning, while keeping the flow context Restarts the flow from the beginning, while keeping the flow context Configure how the flow executor should handle an invalid response to a challenge given by this bound stage. Configure how the flow executor should handle an invalid response to a challenge given by this bound stage. Successfully imported device. Successfully imported device. The user in authentik this device will be assigned to. The user in authentik this device will be assigned to. Duo User ID Duo User ID The user ID in Duo, can be found in the URL after clicking on a user. The user ID in Duo, can be found in the URL after clicking on a user. Automatic import Automatic import Successfully imported devices. Successfully imported devices. Start automatic import Start automatic import Or manually import Or manually import Endpoint Google Chrome Device Trust is in preview. Endpoint Google Chrome Device Trust is in preview. Stage used to verify users' browsers using Google Chrome Device Trust. This stage can be used in authentication/authorization flows. Stage used to verify users' browsers using Google Chrome Device Trust. This stage can be used in authentication/authorization flows. Google Verified Access API Google Verified Access API Stages are single steps of a Flow that a user is guided through. A stage can only be executed from within a flow. Stages are single steps of a Flow that a user is guided through. A stage can only be executed from within a flow. Flows التدفقات Stage(s) Stage(s) Import استيراد Import devices Import devices Shown as the Title in Flow pages. Shown as the Title in Flow pages. Visible in the URL. Visible in the URL. Designation Designation Decides what this Flow is used for. For example, the Authentication flow is redirect to when an un-authenticated user visits authentik. Decides what this Flow is used for. For example, the Authentication flow is redirect to when an un-authenticated user visits authentik. No requirement No requirement Require authentication Require authentication Require no authentication Require no authentication Require superuser Require superuser Require being redirected from another flow Require being redirected from another flow Require Outpost (flow can only be executed from an outpost) Require Outpost (flow can only be executed from an outpost) Required authentication level for this flow. Required authentication level for this flow. Behavior settings Behavior settings Compatibility mode Compatibility mode Increases compatibility with password managers and mobile devices. Increases compatibility with password managers and mobile devices. Denied action Denied action Will follow the ?next parameter if set, otherwise show a message Will follow the ?next parameter if set, otherwise show a message Will either follow the ?next parameter or redirect to the default interface Will either follow the ?next parameter or redirect to the default interface Will notify the user the flow isn't applicable Will notify the user the flow isn't applicable Decides the response when a policy denies access to this flow for a user. Decides the response when a policy denies access to this flow for a user. Appearance settings Appearance settings Layout Layout Background Background Background shown during execution. Background shown during execution. .yaml files, which can be found in the Example Flows documentation .yaml files, which can be found in the Example Flows documentation Flows describe a chain of Stages to authenticate, enroll or recover a user. Stages are chosen based on policies applied to them. Flows describe a chain of Stages to authenticate, enroll or recover a user. Stages are chosen based on policies applied to them. Flow(s) Flow(s) Execute "" Execute "" Execute تنفيذ Export "" Export "" Export تصدير Successfully cleared flow cache Successfully cleared flow cache Failed to delete flow cache Failed to delete flow cache Clear Flow cache Clear Flow cache Are you sure you want to clear the flow cache? This will cause all flows to be re-evaluated on their next usage. Are you sure you want to clear the flow cache? This will cause all flows to be re-evaluated on their next usage. Stage binding(s) Stage binding(s) Stage type Stage type Edit Stage Edit Stage These bindings control if this stage will be applied to the flow. These bindings control if this stage will be applied to the flow. No Stages bound No Stages bound No stages are currently bound to this flow. No stages are currently bound to this flow. Flow Overview Flow Overview Flow Info Flow Info Related actions Related actions Execute flow Execute flow Execute "" normally Execute "" normally Normal Normal Execute "" as current user Execute "" as current user Current user Current user Execute "" with inspector Execute "" with inspector Use inspector Use inspector Stage Bindings Stage Bindings These bindings control which users can access this flow. These bindings control which users can access this flow. Event Log Event Log Brand علامة تجارية Show details Show details Event info Event info Created تم الإنشاء Raw event info Raw event info Event Event Successfully updated transport. Successfully updated transport. Successfully created transport. Successfully created transport. Send once Send once Only send notification once, for example when sending a webhook into a chat channel. Only send notification once, for example when sending a webhook into a chat channel. Local (notifications will be created within authentik) Local (notifications will be created within authentik) Webhook (generic) Webhook (generic) Webhook (Slack/Discord) Webhook (Slack/Discord) Webhook URL Webhook URL Webhook Body Mapping Webhook Body Mapping Webhook Header Mapping Webhook Header Mapping Email Subject Prefix Email Subject Prefix Email Template Email Template Notification Transports Notification Transports Define how notifications are sent to users, like Email or Webhook. Define how notifications are sent to users, like Email or Webhook. Notification transport(s) Notification transport(s) Successfully updated rule. Successfully updated rule. Successfully created rule. Successfully created rule. Select the group of users which the alerts are sent to. Select the group of users which the alerts are sent to. Send notification to event user Send notification to event user Transports وسائل النقل Available Transports Available Transports Selected Transports Selected Transports Select which transports should be used to notify the user. If none are selected, the notification will only be shown in the authentik UI. Select which transports should be used to notify the user. If none are selected, the notification will only be shown in the authentik UI. Severity الخطورة Notification Rules Notification Rules Send notifications whenever a specific Event is created and matched by policies. Send notifications whenever a specific Event is created and matched by policies. Sent to group Sent to group Notification rule(s) Notification rule(s) These bindings control upon which events this rule triggers. Bindings to groups/users are checked against the user of the event. These bindings control upon which events this rule triggers. Bindings to groups/users are checked against the user of the event. Outpost Deployment Info Outpost Deployment Info View deployment documentation View deployment documentation If your authentik Instance is using a self-signed certificate, set this value. If your authentik Instance is using a self-signed certificate, set this value. If your authentik_host setting does not match the URL you want to login with, add this setting. If your authentik_host setting does not match the URL you want to login with, add this setting. Successfully updated outpost. Successfully updated outpost. Successfully created outpost. Successfully created outpost. LDAP LDAP Radius Radius RAC RAC Integration التكامل Selecting an integration enables the management of the outpost by authentik. Selecting an integration enables the management of the outpost by authentik. Available Applications Available Applications Selected Applications Selected Applications Configuration Configuration (build ) (build ) (FIPS) (FIPS) Last seen آخر ظهور , should be , should be Not available Not available Last seen: () Last seen: () Outposts النقاط الخارجية Outposts are deployments of authentik components to support different environments and protocols, like reverse proxies. Outposts are deployments of authentik components to support different environments and protocols, like reverse proxies. Health and Version Health and Version Warning: authentik Domain is not configured, authentication will not work. Warning: authentik Domain is not configured, authentication will not work. Logging in via . Logging in via . No integration active No integration active Outpost(s) Outpost(s) Successfully updated integration. Successfully updated integration. Successfully created integration. Successfully created integration. Local Local Docker URL Docker URL Can be in the format of unix:// when connecting to a local docker daemon, using ssh:// to connect via SSH, or https://:2376 when connecting to a remote system. Can be in the format of unix:// when connecting to a local docker daemon, using ssh:// to connect via SSH, or https://:2376 when connecting to a remote system. CA which the endpoint's Certificate is verified against. Can be left empty for no validation. CA which the endpoint's Certificate is verified against. Can be left empty for no validation. TLS Authentication Certificate/SSH Keypair TLS Authentication Certificate/SSH Keypair Certificate/Key used for authentication. Can be left empty for no authentication. Certificate/Key used for authentication. Can be left empty for no authentication. When connecting via SSH, this keypair is used for authentication. When connecting via SSH, this keypair is used for authentication. Kubeconfig Kubeconfig Verify Kubernetes API SSL Certificate Verify Kubernetes API SSL Certificate Outpost integrations Outpost integrations Outpost integrations define how authentik connects to external platforms to manage and deploy Outposts. Outpost integrations define how authentik connects to external platforms to manage and deploy Outposts. State الحالة Unhealthy غير سليم Outpost integration(s) Outpost integration(s) Successfully generated certificate-key pair. Successfully generated certificate-key pair. Subject-alt name Subject-alt name Optional, comma-separated SubjectAlt Names. Optional, comma-separated SubjectAlt Names. Validity days Validity days Private key Algorithm Private key Algorithm RSA RSA ECDSA ECDSA Algorithm used to generate the private key. Algorithm used to generate the private key. Successfully updated certificate-key pair. Successfully updated certificate-key pair. Successfully created certificate-key pair. Successfully created certificate-key pair. PEM-encoded Certificate data. PEM-encoded Certificate data. Optional Private Key. If this is set, you can use this keypair for encryption. Optional Private Key. If this is set, you can use this keypair for encryption. Certificate-Key Pairs Certificate-Key Pairs Import certificates of external providers or create certificates to sign requests with. Import certificates of external providers or create certificates to sign requests with. Private key available? Private key available? Managed by authentik Managed by authentik Managed by authentik (Discovered) Managed by authentik (Discovered) Yes () Yes () Update Certificate-Key Pair Update Certificate-Key Pair Certificate Fingerprint (SHA1) Certificate Fingerprint (SHA1) Certificate Fingerprint (SHA256) Certificate Fingerprint (SHA256) Certificate Subject Certificate Subject Download Certificate Download Certificate Download Private key Download Private key Generate Generate Link Title Link Title Successfully updated settings. Successfully updated settings. Avatars Avatars Configure how authentik should show avatars for users. The following values can be set: Configure how authentik should show avatars for users. The following values can be set: Disables per-user avatars and just shows a 1x1 pixel transparent picture Disables per-user avatars and just shows a 1x1 pixel transparent picture Uses gravatar with the user's email address Uses gravatar with the user's email address Generated avatars based on the user's name Generated avatars based on the user's name Any URL: If you want to use images hosted on another server, you can set any URL. Additionally, these placeholders can be used: Any URL: If you want to use images hosted on another server, you can set any URL. Additionally, these placeholders can be used: The user's username The user's username The email address, md5 hashed The email address, md5 hashed The user's UPN, if set (otherwise an empty string) The user's UPN, if set (otherwise an empty string) An attribute path like attributes.something.avatar, which can be used in combination with the file field to allow users to upload custom avatars for themselves. An attribute path like attributes.something.avatar, which can be used in combination with the file field to allow users to upload custom avatars for themselves. Multiple values can be set, comma-separated, and authentik will fallback to the next mode when no avatar could be found. Multiple values can be set, comma-separated, and authentik will fallback to the next mode when no avatar could be found. For example, setting this to gravatar,initials will attempt to get an avatar from Gravatar, and if the user has not configured on there, it will fallback to a generated avatar. For example, setting this to gravatar,initials will attempt to get an avatar from Gravatar, and if the user has not configured on there, it will fallback to a generated avatar. Allow users to change name Allow users to change name Enable the ability for users to change their name. Enable the ability for users to change their name. Allow users to change email Allow users to change email Enable the ability for users to change their email. Enable the ability for users to change their email. Allow users to change username Allow users to change username Enable the ability for users to change their username. Enable the ability for users to change their username. Event retention Event retention Duration after which events will be deleted from the database. Duration after which events will be deleted from the database. When using an external logging solution for archiving, this can be set to minutes=5. When using an external logging solution for archiving, this can be set to minutes=5. This setting only affects new Events, as the expiration is saved per-event. This setting only affects new Events, as the expiration is saved per-event. Reputation: lower limit Reputation: lower limit Reputation cannot decrease lower than this value. Zero or negative. Reputation cannot decrease lower than this value. Zero or negative. Reputation: upper limit Reputation: upper limit Reputation cannot increase higher than this value. Zero or positive. Reputation cannot increase higher than this value. Zero or positive. Footer links Footer links This option configures the footer links on the flow executor pages. The URL is limited to web and mail addresses. If the name is left blank, the URL will be shown. This option configures the footer links on the flow executor pages. The URL is limited to web and mail addresses. If the name is left blank, the URL will be shown. GDPR compliance GDPR compliance When enabled, all the events caused by a user will be deleted upon the user's deletion. When enabled, all the events caused by a user will be deleted upon the user's deletion. Impersonation انتحال الهوية Globally enable/disable impersonation. Globally enable/disable impersonation. Require reason for impersonation Require reason for impersonation Require administrators to provide a reason for impersonating a user. Require administrators to provide a reason for impersonating a user. Default token duration Default token duration Default duration for generated tokens Default duration for generated tokens Default token length Default token length Default length of generated tokens Default length of generated tokens Flags Flags Save حفظ System settings System settings Successfully updated instance. Successfully updated instance. Successfully created instance. Successfully created instance. Disabled blueprints are never applied. Disabled blueprints are never applied. Local path Local path OCI Registry OCI Registry OCI URL OCI URL A valid OCI manifest URL, prefixed with the protocol e.g. oci://registry.domain.tld/path/to/manifest A valid OCI manifest URL, prefixed with the protocol e.g. oci://registry.domain.tld/path/to/manifest Read more about Read more about OCI Support OCI Support Blueprint مخطط Configure the blueprint context, used for templating. Configure the blueprint context, used for templating. Orphaned Orphaned Blueprints المخططات Automate and template configuration within authentik. Automate and template configuration within authentik. Last applied آخر تطبيق Blueprint(s) Blueprint(s) Apply "" blueprint Apply "" blueprint Apply تطبيق Successfully updated license. Successfully updated license. Successfully created license. Successfully created license. Install ID Install ID License key License key Expired Expired Expiring soon Expiring soon Unlicensed Unlicensed Read Only Read Only Valid صالح Current license status Current license status Overall license status Overall license status Licenses Licenses Manage enterprise licenses Manage enterprise licenses No licenses found. No licenses found. License(s) License(s) Forecast internal users Forecast internal users Estimated user count one year from now based on current internal users and forecasted internal users. Estimated user count one year from now based on current internal users and forecasted internal users. Approximately Approximately Forecast external users Forecast external users Estimated user count one year from now based on current external users and forecasted external users. Estimated user count one year from now based on current external users and forecasted external users. Cumulative license expiry Cumulative license expiry No expiry No expiry Internal: Internal: External: External: Your Install ID Your Install ID Go to Customer Portal Go to Customer Portal Learn more Learn more Install تثبيت Release Release Development Development UI Version UI Version Build Build Python version Python version Platform Platform Kernel Kernel OpenSSL OpenSSL Enterprise Enterprise Collapse Collapse Expand Expand navigation navigation Dashboards Dashboards Endpoint Devices Endpoint Devices Logs Logs Customization التخصيص Flows and Stages Flows and Stages Directory الدليل Tokens and App passwords Tokens and App passwords System النظام Certificates الشهادات Outpost Integrations Outpost Integrations Warning: The current user count has exceeded the configured licenses. Warning: The current user count has exceeded the configured licenses. Warning: One or more license(s) have expired. Warning: One or more license(s) have expired. Warning: One or more license(s) will expire within the next 2 weeks. Warning: One or more license(s) will expire within the next 2 weeks. Caution: This authentik instance has entered read-only mode due to expired/exceeded licenses. Caution: This authentik instance has entered read-only mode due to expired/exceeded licenses. Click here for more info. Click here for more info. This authentik instance uses a Trial license. This authentik instance uses a Trial license. This authentik instance uses a Non-production license. This authentik instance uses a Non-production license. A newer version () of the UI is available. A newer version () of the UI is available. API drawer API drawer API Requests API Requests Open API Browser Open API Browser Close API drawer Close API drawer View details for View details for Mark as read وضع علامة مقروء Successfully cleared notifications Successfully cleared notifications No notifications found. No notifications found. You don't have any notifications currently. You don't have any notifications currently. Notifications الإشعارات Open about dialog Open about dialog Product name Product name Product version Product version Version Version Global navigation Global navigation WebAuthn requires this page to be accessed via HTTPS. WebAuthn requires this page to be accessed via HTTPS. WebAuthn not supported by browser. WebAuthn not supported by browser. API request failed API request failed Site links Site links Powered by authentik Powered by authentik Authenticating with Apple... Authenticating with Apple... Retry إعادة المحاولة Authenticating with Plex... Authenticating with Plex... Waiting for authentication... Waiting for authentication... If no Plex popup opens, click the button below. If no Plex popup opens, click the button below. Open login Open login Authenticating with Telegram... Authenticating with Telegram... Click the button below to start. Click the button below to start. User information User information Something went wrong! Please try again later. Something went wrong! Please try again later. Request ID Request ID You may close this page now. You may close this page now. Follow redirect Follow redirect Flow inspector Flow inspector Close flow inspector Close flow inspector Next stage Next stage Stage name Stage name Stage kind Stage kind Stage object Stage object This flow is completed. This flow is completed. Plan history Plan history Current plan context Current plan context Session ID Session ID Flow inspector loading Flow inspector loading Request has been denied. Request has been denied. Show password Show password Hide password Hide password Please enter your password Please enter your password Caps Lock is enabled. Caps Lock is enabled. CAPTCHA challenge CAPTCHA challenge Verifying... Verifying... Remember me on this device Remember me on this device Continue with Continue with Need an account? Need an account? Sign up. Sign up. Forgot username or password? Forgot username or password? Additional actions Additional actions Select one of the options below to continue. Select one of the options below to continue. Or Or Use a security key Use a security key Login sources Login sources Forgot password? هل نسيت كلمة المرور؟ Application requires following permissions: Application requires following permissions: Application already has access to the following permissions: Application already has access to the following permissions: Application requires following new permissions: Application requires following new permissions: Stage name: Stage name: Check your Inbox for a verification email. Check your Inbox for a verification email. QR-Code to setup a time-based one-time password QR-Code to setup a time-based one-time password Copy time-based one-time password configuration Copy time-based one-time password configuration Copy TOTP Config Copy TOTP Config Please scan the QR code above using the Microsoft Authenticator, Google Authenticator, or other authenticator apps on your device, and enter the code the device displays below to finish setting up the MFA device. Please scan the QR code above using the Microsoft Authenticator, Google Authenticator, or other authenticator apps on your device, and enter the code the device displays below to finish setting up the MFA device. Time-based one-time password Time-based one-time password TOTP Code TOTP Code Type your TOTP code... Type your TOTP code... Type your time-based one-time password code. Type your time-based one-time password code. Duo activation QR code Duo activation QR code Alternatively, if your current device has Duo installed, click on this link: Alternatively, if your current device has Duo installed, click on this link: Duo activation Duo activation Check status Check status Make sure to keep these tokens in a safe place. Make sure to keep these tokens in a safe place. Configure your email Configure your email Please enter your email address. Please enter your email address. Code Code Please enter the code you received via email Please enter the code you received via email Phone number رقم الهاتف Please enter your Phone number. Please enter your Phone number. Please enter the code you received via SMS Please enter the code you received via SMS Select another authentication method Select another authentication method Authentication code Authentication code Static token Static token Type an authentication code... Type an authentication code... Sending Duo push notification... Sending Duo push notification... Failed to authenticate Failed to authenticate Authenticating... Authenticating... Retry authentication Retry authentication Duo push-notifications Duo push-notifications Receive a push notification on your device. Receive a push notification on your device. Traditional authenticator Traditional authenticator Use a code-based authenticator. Use a code-based authenticator. Recovery keys Recovery keys In case you lose access to your primary authenticators. In case you lose access to your primary authenticators. SMS SMS Tokens sent via SMS. Tokens sent via SMS. Tokens sent via email. Tokens sent via email. Unknown device Unknown device An unknown device class was provided. An unknown device class was provided. Select an authentication method Select an authentication method Select a configuration stage Select a configuration stage Stay signed in? Stay signed in? Select Yes to reduce the number of times you're asked to sign in. Select Yes to reduce the number of times you're asked to sign in. Device Code Device Code Please enter your code Please enter your code You've successfully authenticated your device. You've successfully authenticated your device. You've logged out of . You can go back to the overview to launch another application, or log out of your authentik account. You've logged out of . You can go back to the overview to launch another application, or log out of your authentik account. Go back to overview Go back to overview Log out of Log out of Log back into Log back into SAML Provider SAML Provider SAML logout complete SAML logout complete Redirecting to SAML provider: Redirecting to SAML provider: Posting logout request to SAML provider: Posting logout request to SAML provider: Unknown Provider Unknown Provider Logging out of providers... Logging out of providers... Single Logout Single Logout Open flow inspector Open flow inspector Authentication form Authentication form Failed to register. Please try again. Failed to register. Please try again. Registering... Registering... Failed to register Failed to register Retry registration Retry registration Idle Idle Connecting Connecting Waiting Waiting Connected Connected Disconnecting Disconnecting Disconnected Disconnected Connection failed after attempts. Connection failed after attempts. Re-connecting in second(s). Re-connecting in second(s). Connecting... Connecting... Please wait while the content is loading Please wait while the content is loading application application Actions for "" Actions for "" Edit application... Edit application... Refer to documentation Refer to documentation No Applications available. No Applications available. Either no applications are defined, or you don’t have access to any. Either no applications are defined, or you don’t have access to any. Ungrouped Ungrouped Search for an application by name... Search for an application by name... Search returned no results. Search returned no results. Application list Application list Failed to fetch applications. Failed to fetch applications. Change your password Change your password Change password تغيير كلمة المرور Delete account Delete account Successfully updated details Successfully updated details Open settings Open settings No settings flow configured. No settings flow configured. Update details Update details Device type cannot be edited Device type cannot be edited Enroll Enroll Edit device Edit device User settings User settings User details User details Consent موافقة MFA Devices MFA Devices Connect your user account to the services listed below, to allow you to login using the service instead of traditional credentials. Connect your user account to the services listed below, to allow you to login using the service instead of traditional credentials. Admin interface Admin interface ... ... Truncation ellipsis Via Via Select from uploaded files, or type a Font Awesome icon (fa://fa-icon-name) or URL. Select from uploaded files, or type a Font Awesome icon (fa://fa-icon-name) or URL. This type is deprecated. This type is deprecated. No connectors configured. Navigate to Connectors in the sidebar and first create a connector. No connectors configured. Navigate to Connectors in the sidebar and first create a connector. Home directory Home directory Successfully updated agent connector. Successfully updated agent connector. Successfully created agent connector. Successfully created agent connector. Device compliance settings Device compliance settings Challenge certificate Challenge certificate Challenge idle timeout Challenge idle timeout Duration the flow executor will wait before continuing without a response. Duration the flow executor will wait before continuing without a response. Trigger check-in on device Trigger check-in on device Configure how devices connect with authentik and ingest external device data. Configure how devices connect with authentik and ingest external device data. Stage which associates the currently used device with the current session. Stage which associates the currently used device with the current session. Connector Connector Device optional Device optional If no device was provided, this stage will succeed and continue to the next stage. If no device was provided, this stage will succeed and continue to the next stage. Device required Device required If no device was provided, this stage will stop flow execution. If no device was provided, this stage will stop flow execution. Files Files Manage uploaded files. Manage uploaded files. file file files files Upload رفع Failed to validate device. Failed to validate device. Verifying your device... Verifying your device... Service Provider Config cache timeout Service Provider Config cache timeout Cache duration for ServiceProviderConfig responses. Set minutes=0 to disable caching. Cache duration for ServiceProviderConfig responses. Set minutes=0 to disable caching. JWTs signed by the selected providers can be used to authenticate to devices. JWTs signed by the selected providers can be used to authenticate to devices. Score Configuration Score Configuration This CAPTCHA provider does not support scoring. Score thresholds will be ignored. This CAPTCHA provider does not support scoring. Score thresholds will be ignored. Score Minimum Threshold Score Minimum Threshold Minimum required score to allow continuing. Lower scores indicate more suspicious behavior. Minimum required score to allow continuing. Lower scores indicate more suspicious behavior. Score Maximum Threshold Score Maximum Threshold Maximum allowed score to allow continuing. Set to -1 to disable upper bound checking. Maximum allowed score to allow continuing. Set to -1 to disable upper bound checking. Error on Invalid Score Error on Invalid Score When enabled and the score is outside the threshold, the user will not be able to continue. When disabled, the user can continue and the score can be used in policies. When enabled and the score is outside the threshold, the user will not be able to continue. When disabled, the user can continue and the score can be used in policies. Advanced Settings Advanced Settings JavaScript URL JavaScript URL URL to fetch the CAPTCHA JavaScript library from. Automatically set based on provider selection but can be customized. URL to fetch the CAPTCHA JavaScript library from. Automatically set based on provider selection but can be customized. API Verification URL API Verification URL URL used to validate CAPTCHA response on the backend. Automatically set based on provider selection but can be customized. URL used to validate CAPTCHA response on the backend. Automatically set based on provider selection but can be customized. This stage checks the user's current session against a CAPTCHA service to prevent automated abuse. This stage checks the user's current session against a CAPTCHA service to prevent automated abuse. CAPTCHA Provider CAPTCHA Provider Enable this if the CAPTCHA requires user interaction (clicking checkbox, solving puzzles, etc.). Required for reCAPTCHA v2, hCaptcha interactive mode, and Cloudflare Turnstile. Enable this if the CAPTCHA requires user interaction (clicking checkbox, solving puzzles, etc.). Required for reCAPTCHA v2, hCaptcha interactive mode, and Cloudflare Turnstile. Flow Examples Flow Examples Type an outpost name... Type an outpost name... Outpost Name Outpost Name Outpost configuration Outpost configuration Delete Object Permission Delete Object Permission Global and object permission Global and object permission Global permission Global permission Object permission Object permission Permissions on this object Permissions on this object Permissions assigned to this role affecting specific object instances. Permissions assigned to this role affecting specific object instances. Parents Parents Available Groups Available Groups Selected Groups Selected Groups A group recursively inherits every role from its ancestors. A group recursively inherits every role from its ancestors. User updated. User updated. User created and added to group User created and added to group User created and added to role User created and added to role User created. User created. Successfully downloaded ! Successfully downloaded ! Show MDM configuration Show MDM configuration Hide MDM configuration Hide MDM configuration Is Primary user Is Primary user Primary Primary Remove User(s) Remove User(s) Are you sure you want to remove the selected users from ? هل أنت متأكد من رغبتك في إزالة المستخدمين المحددين من ؟ Are you sure you want to remove the selected users? Are you sure you want to remove the selected users? This user will be added to the role "". This user will be added to the role "". Successfully added user to role(s). Successfully added user to role(s). Roles to add Roles to add Add role Add role Remove from Role(s) Remove from Role(s) Are you sure you want to remove user from the following roles? Are you sure you want to remove user from the following roles? Add to existing role Add to existing role Add new role Add new role Data export ready Data export ready Data Exports Data Exports Manage past data exports. Manage past data exports. Data type Data type Requested by Requested by Creation date Creation date Completed مكتمل Row actions Row actions Data export(s) Data export(s) Query parameters Query parameters SAML metadata XML file to import provider settings from. SAML metadata XML file to import provider settings from. Configure SAML Provider from Metadata Configure SAML Provider from Metadata Outgoing syncs will not be triggered. Outgoing syncs will not be triggered. Immediate Immediate Outgoing syncs will be triggered immediately for each object that is updated. This can create many background tasks and is therefore not recommended Outgoing syncs will be triggered immediately for each object that is updated. This can create many background tasks and is therefore not recommended Deferred until end Deferred until end Outgoing syncs will be triggered at the end of the source synchronization. Outgoing syncs will be triggered at the end of the source synchronization. Outgoing sync trigger mode Outgoing sync trigger mode Successfully connected source Successfully connected source Failed to connect source: Failed to connect source: Passkey settings Passkey settings WebAuthn Authenticator Validation Stage WebAuthn Authenticator Validation Stage When set, allows users to authenticate using passkeys directly from the browser's autofill dropdown without entering a username first. When set, allows users to authenticate using passkeys directly from the browser's autofill dropdown without entering a username first. Pagination: default page size Pagination: default page size Default page size for API requests not specifying a page size. Default page size for API requests not specifying a page size. Pagination: maximum page size Pagination: maximum page size Maximum page size for API requests. Maximum page size for API requests. Local connection Local connection Requires Docker socket/Kubernetes Integration. Requires Docker socket/Kubernetes Integration. Next, download the configuration to deploy the authentik Agent via MDM Next, download the configuration to deploy the authentik Agent via MDM Device Access Group Device Access Group Select a device access group to be added to upon enrollment. Select a device access group to be added to upon enrollment. To create a data export, navigate to Directory > Users or to Events > Logs. To create a data export, navigate to Directory > Users or to Events > Logs. Choose the object permissions that you want the selected role to have on this object. These object permissions are in addition to any global permissions already within the role. Choose the object permissions that you want the selected role to have on this object. These object permissions are in addition to any global permissions already within the role. Device access group Device access group Primary disk size Primary disk size Primary disk usage Primary disk usage The start for user ID numbers, this number is added to the user ID to make sure that the numbers aren't too low for POSIX users. Default is 2000 to prevent collisions with local users. The start for user ID numbers, this number is added to the user ID to make sure that the numbers aren't too low for POSIX users. Default is 2000 to prevent collisions with local users. The start for group ID numbers, this number is added to a number generated from the groups' ID to make sure that the numbers aren't too low for POSIX groups. Default is 4000 to prevent collisions with local groups. The start for group ID numbers, this number is added to a number generated from the groups' ID to make sure that the numbers aren't too low for POSIX groups. Default is 4000 to prevent collisions with local groups. Data exports are not available as storage for reports is not configured. Data exports are not available as storage for reports is not configured. will collect all objects with the specified parameters: will collect all objects with the specified parameters: Successfully requested data export Successfully requested data export Failed to export data Failed to export data Export data Export data English (Pseudo-Accents) English (Pseudo-Accents) Finished Finished Queued Queued Configured file backend does not support file management. Configured file backend does not support file management. Please ensure the data folder is mounted or S3 storage is configured. Please ensure the data folder is mounted or S3 storage is configured. View details... View details... Type a connector name... Type a connector name... Type a name for the token... Type a name for the token... Type a unique identifier... Type a unique identifier... Type a token description... Type a token description... Integrations synced in the last 12 hours. Integrations synced in the last 12 hours. Loading data Loading data Label for progress bar shown when table data is loading Assigned Roles Assigned Roles All Roles All Roles Inherited from parent group Inherited from parent group Inherited from group Inherited from group Inherited Inherited Toggle API requests drawer Toggle API requests drawer API Drawer API Drawer Toggle notifications drawer Toggle notifications drawer Notification Drawer Notification Drawer Failed to fetch notifications. Failed to fetch notifications. Clear all notifications Clear all notifications Close notification drawer Close notification drawer No MFA devices enrolled. No MFA devices enrolled. User Tokens User Tokens No User Tokens enrolled. No User Tokens enrolled. unread unread Indicates the number of unread notifications in the notification drawer Agent version: Agent version: Warning: Flow imports are blueprint files, which may contain objects other than flows (such as users, policies, etc). Warning: Flow imports are blueprint files, which may contain objects other than flows (such as users, policies, etc). You should only import files from trusted sources and review blueprints before importing them. You should only import files from trusted sources and review blueprints before importing them. The length of the individual generated tokens. Can be set to a maximum of 100 characters. The length of the individual generated tokens. Can be set to a maximum of 100 characters. Close sidebar Close sidebar Open sidebar Open sidebar Certificate-Key Pair Certificate-Key Pair Avatar for Avatar for User avatar User avatar Go back Go back A verification token has been sent to your configured email address: A verification token has been sent to your configured email address: Displayed when a verification token has been sent to the user's configured email address. A verification token has been sent to your email address. A verification token has been sent to your email address. Displayed when a verification token has been sent to the user's email address. application found for "" application found for "" applications found for "" applications found for "" application available application available applications available applications available Type to filter applications Type to filter applications Screen reader hint to inform the user they can filter the application list by typing Press Enter to open Press Enter to open Screen reader hint to inform the user they can open the selected application by pressing Enter Press Enter to open Press Enter to open Screen reader hint to inform the user they can open the selected application by pressing Enter Open "" Open "" Screen reader label for the application card Active Sessions Active Sessions Successfully revoked session(s) for user(s) Successfully revoked session(s) for user(s) Failed to revoke sessions: Failed to revoke sessions: Revoke Sessions Revoke Sessions Are you sure you want to revoke all sessions for user(s)? Are you sure you want to revoke all sessions for user(s)? This will force the selected users to re-authenticate on all their devices. This will force the selected users to re-authenticate on all their devices. Security key مفتاح الأمان Use a Passkey or security key to prove your identity. Use a Passkey or security key to prove your identity. Include additional data in Audit logs Include additional data in Audit logs When enabled, additional data about objects added/removed is saved in the audit log. May reduce performance in certain requests. When enabled, additional data about objects added/removed is saved in the audit log. May reduce performance in certain requests. Successfully updated Fleet connector. Successfully updated Fleet connector. Successfully created Fleet connector. Successfully created Fleet connector. Fleet settings Fleet settings Fleet Server URL Fleet Server URL Fleet API Token Fleet API Token Map users Map users When enabled, users detected by Fleet will be mapped in authentik, granting them access to the device. When enabled, users detected by Fleet will be mapped in authentik, granting them access to the device. Map teams to device access group Map teams to device access group When enabled, Fleet teams will be mapped to Device access groups. Missing device access groups are automatically created. Devices assigned to a different group are not re-assigned When enabled, Fleet teams will be mapped to Device access groups. Missing device access groups are automatically created. Devices assigned to a different group are not re-assigned Software Software Paste your license key... Paste your license key... You can select from popular providers with preset configurations or choose a custom setup to specify your own endpoints and keys. You can select from popular providers with preset configurations or choose a custom setup to specify your own endpoints and keys. Paste your CAPTCHA public key... Paste your CAPTCHA public key... Secret Key Secret Key Paste your CAPTCHA secret key... Paste your CAPTCHA secret key... Type a stage name... Type a stage name... The unique name used internally to identify the stage. The unique name used internally to identify the stage. Google reCAPTCHA v2 Google reCAPTCHA v2 reCAPTCHA admin console reCAPTCHA admin console Google reCAPTCHA v3 Google reCAPTCHA v3 reCAPTCHA admin console reCAPTCHA admin console Google reCAPTCHA Enterprise Google reCAPTCHA Enterprise Google Cloud Console Google Cloud Console hCaptcha hCaptcha hCaptcha dashboard hCaptcha dashboard Cloudflare Turnstile Cloudflare Turnstile Cloudflare dashboard Cloudflare dashboard Custom مخصص Type an email address... Type an email address... The public key is used by authentik to render the CAPTCHA widget. The public key is used by authentik to render the CAPTCHA widget. Description for CAPTCHA public key field. The secret key allows communication between authentik and the CAPTCHA provider to validate user responses. The secret key allows communication between authentik and the CAPTCHA provider to validate user responses. Description for CAPTCHA secret key field. Modify تعديل Help text for secret input field to indicate that clicking will allow changing the value. API keys can be obtained from the API keys can be obtained from the Supplementary help text with link to provider dashboard. item marked to add. item marked to add. items marked to add. items marked to add. item selected. item selected. items selected. items selected. item marked to remove. item marked to remove. items marked to remove. items marked to remove. Reply URL Reply URL Update WS-Federation Provider Update WS-Federation Provider WS-Federation Configuration WS-Federation Configuration WS-Federation URL WS-Federation URL Realm (wtrealm) Realm (wtrealm) WS-Federation Metadata WS-Federation Metadata Example WS-Federation attributes Example WS-Federation attributes Group Filter Group Filter Groups to be synced. If empty, all groups will be synced. Groups to be synced. If empty, all groups will be synced. Custom Attributes Custom Attributes No custom attributes defined. No custom attributes defined. The CAPTCHA challenge failed to load. The CAPTCHA challenge failed to load. Could not find a suitable CAPTCHA provider. Could not find a suitable CAPTCHA provider. Copy time-based one-time password secret Copy time-based one-time password secret Copy Secret Copy Secret ED25519 ED25519 ED448 ED448 Enrollment Token Enrollment Token New Token New Token Create link Create link Recovery link Recovery link Successfully queued email. Successfully queued email. Token duration Token duration If a recovery token already exists, its duration is updated. If a recovery token already exists, its duration is updated. copied to clipboard. copied to clipboard. Copied to clipboard. Copied to clipboard. Clipboard not available. Please copy the value manually. Clipboard not available. Please copy the value manually. An unknown error occurred while retrieving the token. An unknown error occurred while retrieving the token. TOTP Config TOTP Config Paste this URL into your authenticator app to set up a time-based one-time password. Paste this URL into your authenticator app to set up a time-based one-time password. TOTP Secret TOTP Secret Paste this secret into your authenticator app to set up a time-based one-time password. Paste this secret into your authenticator app to set up a time-based one-time password. Type a unique identifier for this token... Type a unique identifier for this token... Type a description for this token... Type a description for this token... Create App Password Create App Password New App Password New App Password Sidebar left (frame background) Sidebar left (frame background) Sidebar right (frame background) Sidebar right (frame background) Configuration warning Configuration warning Lifecycle Rules Lifecycle Rules Lifecycle Lifecycle Object Lifecycle Management is in preview. Object Lifecycle Management is in preview. Select a group... Select a group... Select a role... Select a role... Select an object... Select an object... Rule Name Rule Name Type a name for this lifecycle rule... Type a name for this lifecycle rule... Interval Interval The interval between opening new reviews for matching objects. The interval between opening new reviews for matching objects. Grace period Grace period The duration of time before an open review is considered overdue. The duration of time before an open review is considered overdue. Reviewer groups Reviewer groups Number of users from the selected reviewer groups that must approve the review. Number of users from the selected reviewer groups that must approve the review. Reviewers Reviewers Object type Object type When set, the rule will apply to the selected individual object. Otherwise, the rule applies to all objects of the selected type. When set, the rule will apply to the selected individual object. Otherwise, the rule applies to all objects of the selected type. Available Users Available Users Selected Users Selected Users A review will require approval from each of the users selected here in addition to group members as per above settings. A review will require approval from each of the users selected here in addition to group members as per above settings. Notification transports Notification transports Select which transports should be used to notify the user. Select which transports should be used to notify the user. Object Lifecycle Rules Object Lifecycle Rules Schedule periodic reviews for objects in authentik. Schedule periodic reviews for objects in authentik. Lifecycle rule(s) Lifecycle rule(s) No reviews yet. No reviews yet. Reviewed on Reviewed on Reviewer Reviewer Note Note No review iteration found for this object. No review iteration found for this object. At least user from this group: . At least user from this group: . At least user from these groups: . At least user from these groups: . At least users from this group: . At least users from this group: . At least users from these groups: . At least users from these groups: . Review opened on Review opened on Grace period till Grace period till Next review date Next review date Latest review for this object Latest review for this object Review state Review state Required reviewers Required reviewers Reviews Reviews Review Notes Review Notes Type optional notes to include in this review... Type optional notes to include in this review... Open Reviews Open Reviews See all currently open reviews. See all currently open reviews. Only show reviews where I am a reviewer Only show reviews where I am a reviewer Opened Opened Grace period ends Grace period ends Pending review Pending review Reviewed Reviewed Overdue Overdue Canceled Canceled An unknown error occurred while submitting the form. An unknown error occurred while submitting the form. Sign logout response Sign logout response When enabled, SAML logout responses will be signed. When enabled, SAML logout responses will be signed. Posting logout response to SAML provider: Posting logout response to SAML provider: If checked, approving a review will require at least that many users from each of the selected groups. When disabled, the value is a total across all groups. If checked, approving a review will require at least that many users from each of the selected groups. When disabled, the value is a total across all groups. Review initiated Review initiated Review overdue Review overdue Review attested Review attested Review completed Review completed Copy Link Copy Link Send إرسال Send Invitation via Email Send Invitation via Email Send via Email Send via Email Please enter at least one email address Please enter at least one email address Invitation emails queued for sending to recipient(s). Check the System Tasks for more information. Invitation emails queued for sending to recipient(s). Check the System Tasks for more information. Failed to queue invitation emails: Failed to queue invitation emails: Never أبداً No flow set No flow set One email address per line, or comma/semicolon separated. Each recipient will receive a separate email with an invitation link. One email address per line, or comma/semicolon separated. Each recipient will receive a separate email with an invitation link. CC CC A comma-separated list of addresses to receive copies of the invitation. Recipients will receive the full list of other addresses in this list. A comma-separated list of addresses to receive copies of the invitation. Recipients will receive the full list of other addresses in this list. BCC BCC A comma-separated list of addresses to receive copies of the invitation. Recipients will not receive the addresses of other recipients. A comma-separated list of addresses to receive copies of the invitation. Recipients will not receive the addresses of other recipients. Select the email template to use for sending invitations. Select the email template to use for sending invitations. Site footer Site footer Enter the email address or username associated with your account. Enter the email address or username associated with your account. You're about to be redirected to the following URL. You're about to be redirected to the following URL. Log in to continue to . Log in to continue to . Continuous Login Continuous Login Successfully updated Google Chrome connector. Successfully updated Google Chrome connector. Successfully created Google Chrome connector. Successfully created Google Chrome connector. Google settings Google settings Webhook Certificate Authority Webhook Certificate Authority Keypair used to validate the certificate of the webhook endpoint. When not configured, the standard CA bundle is used. Keypair used to validate the certificate of the webhook endpoint. When not configured, the standard CA bundle is used. Security key (e.g. YubiKey) Security key (e.g. YubiKey) Client device (e.g. Touch ID, Windows Hello) Client device (e.g. Touch ID, Windows Hello) Hybrid (e.g. QR code, phone) Hybrid (e.g. QR code, phone) WebAuthn Hints WebAuthn Hints Available Hints Available Hints Selected Hints Selected Hints Optional hints to guide the browser in prioritizing the preferred authenticator type. Order matters - the first hint has highest priority. These are advisory and may be ignored by browsers. Optional hints to guide the browser in prioritizing the preferred authenticator type. Order matters - the first hint has highest priority. These are advisory and may be ignored by browsers. Hints Hints Optional hints to guide the browser in prioritizing the preferred authenticator type during registration. Order matters - the first hint has highest priority. These are advisory and may be ignored by browsers. Optional hints to guide the browser in prioritizing the preferred authenticator type during registration. Order matters - the first hint has highest priority. These are advisory and may be ignored by browsers. Filtering Filtering See documentation for path rules and theme-aware names. See documentation for path rules and theme-aware names. No assertion was returned by the authenticator No assertion was returned by the authenticator Authentication was cancelled or timed out Authentication was cancelled or timed out Registration was cancelled or timed out. Please try again. Registration was cancelled or timed out. Please try again. An error occurred while creating the credential. Please try again. An error occurred while creating the credential. Please try again. Server validation of credential failed Server validation of credential failed Upon successful authentication, re-start authentication in other open tabs. Upon successful authentication, re-start authentication in other open tabs. About authentik About authentik Create a new application... Create a new application... Username or email address... Username or email address... Type an optional publisher name... Type an optional publisher name... Type an optional description... Type an optional description... New Application New Application Opens the new application wizard, which will guide you through creating a new application with an existing provider. Opens the new application wizard, which will guide you through creating a new application with an existing provider. Opens the new application form, which will guide you through creating a new application with an existing provider. Opens the new application form, which will guide you through creating a new application with an existing provider. Clear Cache Clear Cache Search for a provider... Search for a provider... e.g. my-application e.g. my-application Select Groups Select Groups New Group User New Group User New Role User New Role User Add Existing User Add Existing User Add New User Add New User New Group User... New Group User... New Role User... New Role User... New Service Account... New Service Account... Start Export Start Export Assign Additional Roles Assign Additional Roles Role Name Role Name Type a name for this role... Type a name for this role... This name will be used to identify the role within authentik. This name will be used to identify the role within authentik. Service Account Service Account Service Accounts Service Accounts Impersonate User Impersonate User Impersonate Impersonate Set Password Set Password User "" User "" search search find find Search the docs for "" Search the docs for "" New Tab New Tab Command palette Command palette No commands No commands No matching commands. No matching commands. No commands are currently available. No commands are currently available. Fetching users... Fetching users... No matching users No matching users No matching users. No matching users. Jump to Jump to Search for Search for Open فتح View عرض New Tab New Tab Peek Peek Integrations Integrations Documentation التوثيق Release notes Release notes New in New in authentik authentik About authentik About authentik Session جلسة Navigate to Navigate to Interface Interface API requests drawer API requests drawer Toggle Toggle Notifications drawer Notifications drawer Reloads page Reloads page authentik information authentik information Landmark: Landmark: Switch to tab Switch to tab Save Changes حفظ التغييرات Resend Email Resend Email Open Command Palette Open Command Palette Label for the button that opens the command palette Type a command... Type a command... Label for the command palette input What are you looking for? What are you looking for? Placeholder for the command palette input Type a username or email address... Type a username or email address... Placeholder for the user search command in the admin interface The headline for a form that creates or updates a model instance. Open Command Palette Open Command Palette Tooltip for the button that opens the command palette Configure WS-Federation Provider Configure WS-Federation Provider Outpost نقطة خارجية No instances running. No instances running. New Outpost New Outpost No providers configured. No providers configured. Outpost Info Outpost Info Health Health Configured providers Configured providers Detailed health (data is cached so may be out of date) Detailed health (data is cached so may be out of date) Webex Webex Altered behavior for usage with Cisco Webex. Altered behavior for usage with Cisco Webex. Statistics Statistics Authorizations (24 hours) Authorizations (24 hours) Authorizations (7 days) Authorizations (7 days) Authorizations (1 month) Authorizations (1 month) Successfully imported blueprint. Successfully imported blueprint. File upload File upload Warning: Blueprint files may contain objects such as users, policies and expression. Warning: Blueprint files may contain objects such as users, policies and expression. Force authentication Force authentication When enabled, the IdP is requested to force re-authentication of the user, even if the user has an existing session. When enabled, the IdP is requested to force re-authentication of the user, even if the user has an existing session. / instances are healthy. / instances are healthy. Federated OAuth2/OpenID Providers Federated OAuth2/OpenID Providers Info Info Verify Push stream endpoints' certificate Verify Push stream endpoints' certificate Stream(s) Stream(s) Delivery method Delivery method Delivery Method Delivery Method Pull Pull Push Push post logout post logout authorization authorization Valid redirect URIs after a successful authorization or invalidation flow. Also specify any origins here for Implicit flows. Use the type dropdown to designate URIs for authorization or post-logout redirection. Valid redirect URIs after a successful authorization or invalidation flow. Also specify any origins here for Implicit flows. Use the type dropdown to designate URIs for authorization or post-logout redirection. If no explicit authorization redirect URIs are specified, the first successfully used authorization redirect URI will be saved. If no explicit authorization redirect URIs are specified, the first successfully used authorization redirect URI will be saved. Post Logout Post Logout No connectivity status available. No connectivity status available. LDAP Group(s) LDAP Group(s) Connect Group Connect Group Successfully connected user. Successfully connected user. The unique identifier of this object in LDAP, the value of the '' attribute. The unique identifier of this object in LDAP, the value of the '' attribute. LDAP User(s) LDAP User(s) Connect User Connect User Object Identifier () Object Identifier () Synced Users Synced Users Synced Groups Synced Groups Avatar الصورة الرمزية Save changes Save changes Edit Settings Edit Settings Server Version Server Version Applications search Applications search Search for application by name, group or provider... Search for application by name, group or provider... New Application options New Application options Select a ... Select a ... Application Details Application Details Provider Details Provider Details Flow Blueprint Flow Blueprint Flow Blueprints Flow Blueprints Select a blueprint... Select a blueprint... Search for a blueprint by name or path... Search for a blueprint by name or path... Type a name for this certificate... Type a name for this certificate... e.g. mydomain.com, *.mydomain.com, mydomain.local e.g. mydomain.com, *.mydomain.com, mydomain.local Import Existing Import Existing Certificate Name Certificate Name Type a name for this certificate-key pair... Type a name for this certificate-key pair... Search for a certificate or key name... Search for a certificate or key name... Select a device access group... Select a device access group... No enrollment tokens found for this connector. No enrollment tokens found for this connector. Search for an enrollment token... Search for an enrollment token... Search connectors by name or type... Search connectors by name or type... Endpoint Connector Endpoint Connector Endpoint Connectors Endpoint Connectors Provide your Fleet API token... Provide your Fleet API token... Device Access Groups Device Access Groups Search device groups by name... Search device groups by name... Search devices by name, OS, or group... Search devices by name, OS, or group... Enterprise License Enterprise License Enterprise Licenses Enterprise Licenses Search for a license by name... Search for a license by name... Notification Rule Notification Rule Type a name for this rule... Type a name for this rule... Search for a notification rule by name, severity or group... Search for a notification rule by name, severity or group... Notification Transport Notification Transport Transport Name Transport Name Type a name for this transport... Type a name for this transport... Search for a notification transport by name or mode... Search for a notification transport by name or mode... Search for a file by name... Search for a file by name... Flow Name Flow Name Type a name for this flow... Type a name for this flow... Type a title for this flow... Type a title for this flow... e.g. my-flow e.g. my-flow Select a designation... Select a designation... Search for a flow by name or identifier... Search for a flow by name or identifier... Stage Binding Stage Binding Select a stage... Select a stage... Select one or more users to assign... Select one or more users to assign... Lifecycle Rule Lifecycle Rule Search for a lifecycle rule by name or target... Search for a lifecycle rule by name or target... Review Review Outpost Integration Outpost Integration Search outposts by name, type or assigned integration... Search outposts by name, type or assigned integration... Search for an outpost integration by name, type or assigned integration... Search for an outpost integration by name, type or assigned integration... Open the wizard to create a new service connection. Open the wizard to create a new service connection. New Outpost Integration New Outpost Integration Open the wizard to create a new policy. Open the wizard to create a new policy. Policy Name Policy Name Type a policy name... Type a policy name... Policy Binding Policy Binding Search for a policy by name or type... Search for a policy by name or type... New Policy New Policy Search for a reputation by identifier or IP... Search for a reputation by identifier or IP... Property Mapping تعيين الخصائص Mapping Name Mapping Name Type a name for this mapping... Type a name for this mapping... Search for a property mapping by name or type... Search for a property mapping by name or type... New Property Mapping New Property Mapping Run Test Run Test Example Context Data Example Context Data Select a user... Select a user... Bind Mode Bind Mode Search Mode Search Mode Bind Flow Bind Flow Unbind Flow Unbind Flow TLS Server Name TLS Server Name UID Start Number UID Start Number GID Start Number GID Start Number Authorization Flow Authorization Flow Client Type Client Type Authentication Flow Authentication Flow Invalidation Flow Invalidation Flow Access Code Validity Access Code Validity Access Token Validity Access Token Validity Refresh Token Validity Refresh Token Validity Refresh Token Threshold Refresh Token Threshold Subject Mode Subject Mode Search for provider by name, type or assigned application... Search for provider by name, type or assigned application... RAC Endpoint RAC Endpoint RAC Endpoints RAC Endpoints Endpoint Name Endpoint Name Type a name for this endpoint... Type a name for this endpoint... e.g. myserver.example.com, 10.0.0.1:22 e.g. myserver.example.com, 10.0.0.1:22 Create an endpoint to get started. Create an endpoint to get started. Search for an endpoint by name or host... Search for an endpoint by name or host... Initial Permission Name Initial Permission Name Type a name for these initial permissions... Type a name for these initial permissions... Search for initial permissions by name... Search for initial permissions by name... Create an initial permission to get started. Create an initial permission to get started. Role Object Permission Role Object Permission Role Object Permissions Role Object Permissions Object Permission Object Permission Object Permissions Object Permissions Update تحديث Search for a role... Search for a role... Source Name Source Name Type a name for this source... Type a name for this source... e.g. my-kerberos-source e.g. my-kerberos-source e.g. my-oauth-source e.g. my-oauth-source e.g. my-plex-source e.g. my-plex-source e.g. my-saml-source e.g. my-saml-source e.g. my-scim-source مثال: my-scim-source Search for a source... البحث عن مصدر... e.g. my-telegram-source مثال: my-telegram-source Duo Device جهاز Duo Duo Devices أجهزة Duo Importing جارٍ الاستيراد Type the Duo user ID for this device... Type the Duo user ID for this device... Invitation دعوة Invitation Name اسم الدعوة Search for an invitation by name... البحث عن دعوة بالاسم... Prompt طلب Search for a prompt by name, field or type... البحث عن طلب بالاسم أو الحقل أو النوع... Search for a stage name, type, or flow... البحث عن اسم مرحلة أو نوع أو تدفق... User creation mode وضع إنشاء المستخدم Search for a token identifier, user, or intent... البحث عن معرّف رمز أو مستخدم أو غرض... Review Credentials مراجعة بيانات الاعتماد Type a username for the service account... اكتب اسم مستخدم لحساب الخدمة... Internal User مستخدم داخلي Internal Users المستخدمون الداخليون External User مستخدم خارجي External Users المستخدمون الخارجيون Type a username for the internal user... اكتب اسم مستخدم للمستخدم الداخلي... Type a username for the external user... اكتب اسم مستخدم للمستخدم الخارجي... Open the new user wizard فتح معالج المستخدم الجديد Select email stage... اختر مرحلة البريد الإلكتروني... Copying ... Copying ... Copying to clipboard... جارٍ النسخ إلى الحافظة... e.g. my-slug مثال: my-slug Create Create Create إنشاء Copy to clipboard نسخ إلى الحافظة Entity كيان Edit "" Edit "" Edit Edit Open "" permissions Open "" permissions Open permissions فتح الصلاحيات New جديد New جديد Create إنشاء Creating جارٍ الإنشاء Edit تعديل Save Changes حفظ التغييرات Saving Changes... جارٍ حفظ التغييرات... An error occurred while loading . حدث خطأ أثناء تحميل . Select an option... اختر خياراً... Cancel wizard إلغاء المعالج Search for an endpoint by name... البحث عن نقطة نهاية بالاسم... No endpoints found for this application. لم يتم العثور على نقاط نهاية لهذا التطبيق. Launch Endpoint تشغيل نقطة النهاية Wizard المعالج ARIA label for the creation wizard when no entity singular is provided. Create New Entity إنشاء كيان جديد Header for the creation wizard when no entity singular is provided. ... ... The message shown while a form is being submitted. Query استعلام Event query using the AKQL syntax. استعلام الأحداث باستخدام صيغة AKQL. See documentation for examples. راجع التوثيق للأمثلة. Access وصول Checking جارٍ التحقق with New Provider... مع موفّر جديد... with Existing Provider... مع موفّر موجود... Select one or more backchannel providers... اختر موفّراً واحداً أو أكثر للقناة الخلفية... Device جهاز Select one or more groups... اختر مجموعة واحدة أو أكثر... Select one or more roles... اختر دوراً واحداً أو أكثر... Select one or more permissions... اختر صلاحية واحدة أو أكثر... Avatar for Avatar for Username: Username: Display name: Display name: Dialog content محتوى الحوار Require Flow token (flow can only be executed from a generated recovery link) يتطلب رمز التدفق (لا يمكن تنفيذ التدفق إلا من رابط استرداد مُنشأ) Select the type of policy you want to create. اختر نوع السياسة التي تريد إنشاءها. Bind Existing... ربط موجود... Select a type to bind an existing object instead of creating a new one. اختر نوعاً لربط كائن موجود بدلاً من إنشاء كائن جديد. Bind a user ربط مستخدم Statically bind an existing user. ربط مستخدم موجود بشكل ثابت. Bind a group ربط مجموعة Statically bind an existing group. ربط مجموعة موجودة بشكل ثابت. Bind an existing policy ربط سياسة موجودة Bind an existing policy. ربط سياسة موجودة. Create or bind... إنشاء أو ربط... Select the type of stage you want to create. اختر نوع المرحلة التي تريد إنشاءها. Existing Stage مرحلة موجودة Bind an existing stage to this flow. ربط مرحلة موجودة بهذا التدفق. Deactivating... جارٍ التعطيل... Activating... جارٍ التفعيل... Unknown user مستخدم غير معروف Review Deactivation مراجعة إلغاء تنشيط Review Activation مراجعة تنشيط Objects الكائنات Related object الكائن ذو الصلة Connection will be deleted سيتم حذف الاتصال Reference will be reset to default value سيتم إعادة تعيين المرجع إلى القيمة الافتراضية Reference will be set to an empty value سيتم تعيين المرجع إلى قيمة فارغة will be left dangling (may cause errors) will be left dangling (may cause errors) has an unknown relationship (check logs) has an unknown relationship (check logs) has an unrecognized relationship (check logs) لـ علاقة غير معروفة (تحقق من السجلات) Failed to delete فشل حذف Modify تعديل Modifying جارٍ التعديل Unnamed object كائن بدون اسم List of objects that are associated with this . قائمة بالكائنات المرتبطة بـ هذا. Object Name اسم الكائن Consequence النتيجة Details التفاصيل will be deleted سيتم حذف Consequence of deletion, when the related object will also be deleted. The name of the related object will be included, in the format 'Related object will be deleted'. Unknown user مستخدم غير معروف Placeholder for an unknown user, in the format 'Unknown user'. is associated with objects. مرتبط بـ كائنات. Plural: N objects use this entity. is associated with one object. مرتبط بكائن واحد. Singular: exactly one object uses this entity. No found. لم يتم العثور على . The message to show when a table has no content. The placeholder {0} is replaced with the pluralized name of the type of entity being shown in the table. () () The user's name in parentheses, used when the name is different from the username () () Used in list item, showing the name of the object and the consequence of deletion. is not associated with any objects. غير مرتبط بأي كائنات. Zero: no objects use this entity. Authorization Code رمز التفويض Implicit ضمني Hybrid هجين Refresh token رمز التحديث Client credentials بيانات اعتماد العميل Device-code رمز الجهاز Grant Types أنواع المنح Grant types this provider may use. أنواع المنح التي يمكن لهذا الموفّر استخدامها. vCenter vCenter Altered behavior for usage with VMware vCenter. سلوك معدَّل للاستخدام مع VMware vCenter. EntityID/Issuer override تجاوز EntityID/المُصدِر Sets a custom EntityID/Issuer to override the authentik generated default. يضبط EntityID/مُصدِراً مخصصاً لتجاوز الإعداد الافتراضي الذي يُنشئه authentik. Passwords كلمات المرور Setting الإعداد Type a new password... اكتب كلمة مرور جديدة... When enabled, your username will be remembered on this device for future logins. عند التفعيل، سيتم تذكر اسم المستخدم الخاص بك على هذا الجهاز لعمليات تسجيل الدخول المستقبلية. ... ... The message shown while a form is being submitted, when no entity name is provided. Account lockdown flow تدفق قفل الحساب Select an account lockdown flow... اختر تدفق قفل الحساب... Flow used when a user triggers account lockdown (e.g. in case of compromise). Should contain an Account Lockdown stage. التدفق المستخدم عندما يُشغِّل مستخدم قفل الحساب (مثلاً في حالة الاختراق). يجب أن يحتوي على مرحلة قفل الحساب. Account lockdown flows should require authentication so they can only be started from a signed-in session. يجب أن تتطلب تدفقات قفل الحساب المصادقة حتى لا تُبدأ إلا من جلسة مسجّل الدخول فيها. If no group is selected and 'Send notification to event user' is disabled, the rule is disabled. إذا لم يتم اختيار أي مجموعة وكان خيار 'إرسال الإشعار إلى مستخدم الحدث' معطّلاً، فستكون القاعدة معطّلة. When enabled, notification will be sent to the user that triggered the event in addition to any users in the group above. The event user will always be the first user, to send a notification only to the event user enabled 'Send once' in the notification transport. عند التفعيل، سيتم إرسال الإشعار إلى المستخدم الذي أطلق الحدث بالإضافة إلى أي مستخدمين في المجموعة أعلاه. سيكون مستخدم الحدث دائماً المستخدم الأول، ولإرسال إشعار إلى مستخدم الحدث فقط فعّل 'إرسال مرة واحدة' في ناقل الإشعارات. Minimum reviewers الحد الأدنى من المراجعين Minimum reviewers is per-group الحد الأدنى من المراجعين هو لكل مجموعة The following reviews apply to this object: تنطبق المراجعات التالية على هذا الكائن: This object has no reviews yet. لا توجد مراجعات لهذا الكائن حتى الآن. Rule قاعدة This stage executes account lockdown actions on a target user. Configure which actions to perform when this stage runs. تُنفِّذ هذه المرحلة إجراءات قفل الحساب على مستخدم مستهدف. قم بتكوين الإجراءات التي تريد تنفيذها عند تشغيل هذه المرحلة. Deactivate user تعطيل المستخدم Deactivate the user account (set is_active to False). تعطيل حساب المستخدم (تعيين is_active إلى False). Set unusable password تعيين كلمة مرور غير قابلة للاستخدام Set an unusable password for the user. تعيين كلمة مرور غير قابلة للاستخدام للمستخدم. Delete sessions حذف الجلسات Delete all active sessions for the user. حذف جميع الجلسات النشطة للمستخدم. Revoke tokens إلغاء الرموز Revoke all tokens for the user (API, app password, recovery, verification). إلغاء جميع الرموز للمستخدم (API وكلمة مرور التطبيق والاسترداد والتحقق). Self-service completion اكتمال الخدمة الذاتية Configure what happens after a user locks their own account. Since all sessions are deleted, the user cannot continue in the current flow and will be redirected to a separate completion flow. تكوين ما يحدث بعد أن يقوم المستخدم بقفل حسابه. بما أن جميع الجلسات تُحذف، لا يمكن للمستخدم المتابعة في التدفق الحالي وسيتم إعادة توجيهه إلى تدفق اكتمال منفصل. Completion flow تدفق الاكتمال Select a completion flow... اختر تدفق الاكتمال... Flow to redirect users to after self-service lockdown. This flow must not require authentication since the user's session is deleted. التدفق الذي يُعاد توجيه المستخدمين إليه بعد الإغلاق الذاتي للخدمة. يجب ألا يتطلب هذا التدفق مصادقة لأن جلسة المستخدم تُحذف. Alert (Info): Static alert box with info styling تنبيه (معلومات): مربع تنبيه ثابت بأسلوب معلومات Alert (Warning): Static alert box with warning styling تنبيه (تحذير): مربع تنبيه ثابت بأسلوب تحذير Alert (Danger): Static alert box with danger styling تنبيه (خطر): مربع تنبيه ثابت بأسلوب خطر Warning: You are about to delete user , but you are currently logged in as this user. Proceed at your own risk. تحذير: أنت على وشك حذف المستخدم ، لكنك مسجّل الدخول حالياً بهذا المستخدم. تابع على مسؤوليتك الخاصة. Account Lockdown قفل الحساب Security الأمان If you suspect your account has been compromised, you can immediately lock it to prevent unauthorized access. إذا كنت تشك في تعرض حسابك للاختراق، يمكنك قفله فوراً لمنع الوصول غير المصرح به. Lock my account قفل حسابي Bind existing group/user ربط مجموعة/مستخدم موجود Leave empty to skip certificate validation, or select a certificate/keypair containing the LDAP server CA chain to validate the remote certificate. اتركه فارغاً لتخطي التحقق من الشهادة، أو اختر شهادة/زوج مفاتيح يحتوي على سلسلة CA لخادم LDAP للتحقق من الشهادة البعيدة. Choose Policy Type اختر نوع السياسة Negate Result عكس النتيجة Failure Result نتيجة الفشل Device Classes فئات الجهاز User Fields حقول المستخدم No preference: the browser may offer any available authenticator بلا تفضيل: قد يتيح المتصفح أي مصادق متاح Platform: a non-removable authenticator built into the device, such as Touch ID, Face ID, or Windows Hello المنصة: مصادق غير قابل للإزالة مدمج في الجهاز، مثل Touch ID أو Face ID أو Windows Hello Cross-platform: a roaming authenticator, such as a YubiKey or Google Titan عبر المنصات: مصادق متنقل، مثل YubiKey أو Google Titan Controls the authenticatorAttachment parameter sent to the browser during WebAuthn registration. If Hints are configured and this is left as 'No preference', a value is inferred from the selected hints for backward compatibility with older browsers. يتحكم في معامل authenticatorAttachment المُرسل إلى المتصفح أثناء تسجيل WebAuthn. إذا تم ضبط التلميحات Hints وتُرك هذا الخيار على 'لا تفضيل'، فسيُستنتج قيمة من التلميحات المختارة للتوافق مع المتصفحات القديمة. New Invitation دعوة جديدة Enrollment Flow تدفق التسجيل Invitation Details تفاصيل الدعوة Blueprint validation failed فشل التحقق من المخطط Flow with slug "" not found after import Flow with slug "" not found after import Enrolled users are created as external (e.g. customers, guests). New users will be placed under users/external. يتم إنشاء المستخدمين المسجلين كخارجيين (مثل العملاء والضيوف). ستتم إضافة المستخدمين الجدد تحت users/external. Enrolled users are created as internal (e.g. employees). New users will be placed under users/internal. يتم إنشاء المستخدمين المسجلين كداخليين (مثل الموظفين). ستتم إضافة المستخدمين الجدد تحت users/internal. If enabled, the stage will jump to the next stage when no invitation is given. If disabled, the flow will be cancelled without a valid invitation. إذا كان مُفعَّلاً، ستنتقل المرحلة إلى المرحلة التالية عندما لا تُقدَّم دعوة. إذا كان مُعطَّلاً، سيتم إلغاء التدفق بدون دعوة صالحة. Redirect the user to a static URL or another flow, optionally with all gathered context. إعادة توجيه المستخدم إلى عنوان URL ثابت أو تدفق آخر، مع جميع السياق المجمَّع اختيارياً. The element could not be loaded. This may be due to a missing import or a version mismatch. تعذّر تحميل العنصر. قد يكون ذلك بسبب استيراد مفقود أو عدم تطابق الإصدار. An element could not be loaded. Please try refreshing the page or clearing your cache. تعذّر تحميل عنصر. يرجى محاولة تحديث الصفحة أو مسح ذاكرة التخزين المؤقت. Failed to load element فشل تحميل العنصر SAML Endpoint نقطة نهاية SAML SAML provider endpoint. Use this URL for SP configuration. نقطة نهاية موفّر SAML. استخدم هذا العنوان لتكوين SP. Throttling settings إعدادات التحديد Email OTP throttling factor معامل تحديد OTP بالبريد الإلكتروني SMS OTP throttling factor معامل تحديد OTP بالرسائل القصيرة TOTP throttling factor معامل تحديد TOTP Static OTP throttling factor معامل تحديد OTP الثابت View Credentials عرض بيانات الاعتماد OAuth (Silent) OAuth (صامت) OAuth (Interactive) OAuth (تفاعلي) Authenticate SCIM requests using OAuth, interactively authorized. مصادقة طلبات SCIM باستخدام OAuth، مع تفويض تفاعلي. OAuth Token last updated آخر تحديث لرمز OAuth OAuth Token expires انتهاء صلاحية رمز OAuth OAuth Status حالة OAuth Authenticated مُصادَق عليه No token saved لا يوجد رمز محفوظ (Re-)authenticate (إعادة) المصادقة OAuth Callback URL عنوان URL لاستدعاء OAuth The name displayed in the Application Dashboard. الاسم المعروض في لوحة تحكم التطبيقات. If checked, the launch URL will open in a new browser tab or window from the user's Application Dashboard. إذا تم تحديده، سيتم فتح رابط التشغيل في علامة تبويب أو نافذة متصفح جديدة من لوحة تطبيقات المستخدم. Hide from Application Dashboard إخفاء من لوحة تحكم التطبيقات If checked, this application will not be shown on the user's Application Dashboard. إذا تم تحديده، فلن يظهر هذا التطبيق في لوحة تطبيقات المستخدم. The publisher is shown in the Application Dashboard. يظهر الناشر في لوحة تحكم التطبيقات. The description is shown in the Application Dashboard and may provide additional information about the application to end users. يظهر الوصف في لوحة تحكم التطبيقات وقد يوفر معلومات إضافية عن التطبيق للمستخدمين النهائيين. You've logged out of . You can log out of your authentik account. You've logged out of . You can log out of your authentik account. You've logged out of . You've logged out of . Application Dashboard لوحة تحكم التطبيقات View details of role "" View details of role "" New Stage مرحلة جديدة Choose type اختر النوع Generic label for the initial step in the creation wizard where the type of the entity being created is selected, used when no singular entity name is provided. Choose Type اختر نوع Label for the initial step in the creation wizard where the type of the entity being created is selected. The placeholder {entity} is replaced with the singular name of the entity, for example 'Choose User Type' or 'Choose Group Type'. Details تفاصيل Label for the step in the creation wizard where the details of the entity being created are filled in. The placeholder {entity} is replaced with the name of the entity type, for example 'User Details' or 'Group Details'. Flags allow you to enable new functionality and behavior in authentik early. تتيح لك الأعلام تفعيل وظائف وسلوكيات جديدة في authentik مبكراً. Cap Endpoint نقطة نهاية Cap https://cap.example.com/site-key/ https://cap.example.com/site-key/ For Cap, prefer the self-hosted widget asset, for example https://cap.example.com/assets/widget.js. If using a CDN, pin a reviewed release. بالنسبة لـ Cap، يُفضَّل استخدام أصل الأداة المستضافة ذاتياً، مثال https://cap.example.com/assets/widget.js. إذا كنت تستخدم CDN، فحدّد إصداراً مراجَعاً. Cap's server-side verification endpoint, for example https://cap.example.com/site-key/siteverify. Cap's server-side verification endpoint, for example https://cap.example.com/site-key/siteverify. Request Content Type نوع محتوى الطلب Content-Type used for server-side verification. Cap requires JSON; most other providers use form-encoded requests. نوع المحتوى المستخدم للتحقق من جانب الخادم. Cap يتطلب JSON؛ معظم الموفّرين الآخرين يستخدمون طلبات مُشفَّرة بالنموذج. Form encoded مُشفَّر بالنموذج JSON JSON Cap Cap Cap is a self-hostable CAPTCHA server that uses proof-of-work challenges. Cap هو خادم CAPTCHA يمكن استضافته ذاتياً ويستخدم تحديات إثبات العمل. Cap documentation توثيق Cap The public site-key endpoint of your Cap server. نقطة نهاية مفتاح الموقع العام لخادم Cap الخاص بك. Description for Cap endpoint field. Use the to self-host Cap and configure the endpoint. Use the to self-host Cap and configure the endpoint. Supplementary help text with link to Cap documentation. Connection Token رمز الاتصال Connection Tokens رموز الاتصال Access Token رمز الوصول Access Tokens رموز الوصول Refresh Token رمز التحديث Refresh Tokens رموز التحديث Unknown action إجراء غير معروف Custom action إجراء مخصص Unknown user type نوع مستخدم غير معروف object كائن objects كائنات Consents الموافقات Reputation score درجة السمعة New Wizard New Wizard ARIA label for the creation wizard, where the entity singular is interpolated. token for token for Description for a clipboard copy action for tokens, with the token intent and username as variables. No found. No found. Empty state message when no objects are found, where the entity plural is interpolated. No matches "" No matches "" Empty state message when no objects match the search query, where the entity singular is interpolated, followed by the search query truncated to 50 characters. Create New Create New Header for the creation wizard, where the entity singular is interpolated. Copy token نسخ الرمز Label for a button that copies a token to the clipboard. Token رمز Label for a token entity, used in clipboard copy success messages. Search for ... Search for ... Placeholder text for the search input, where the entity plural is interpolated. Waiting for dependencies بانتظار التبعيات 0: Too guessable: risky password. (guesses < 10^3) 0: سهل التخمين جدًا: كلمة مرور خطيرة. (التخمينات &lt; 10^3) 1: Very guessable: protection from throttled online attacks. (guesses < 10^6) 1: سهل التخمين: حماية من الهجمات المقيّدة عبر الإنترنت. (التخمينات &lt; 10^6) 2: Somewhat guessable: protection from unthrottled online attacks. (guesses < 10^8) 2: قابل للتخمين إلى حد ما: حماية من الهجمات غير المقيّدة عبر الإنترنت. (التخمينات &lt; 10^8) 3: Safely unguessable: moderate protection from offline slow-hash scenario. (guesses < 10^10) 3: يصعب تخمينه بأمان: حماية معتدلة من سيناريو التجزئة البطيئة دون اتصال. (التخمينات &lt; 10^10) 4: Very unguessable: strong protection from offline slow-hash scenario. (guesses >= 10^10) 4: يصعب تخمينه جدًا: حماية قوية من سيناريو التجزئة البطيئة دون اتصال. (التخمينات &gt;= 10^10) Unset غير محدد Token exchange Issuer override Also known as Entity ID. Defaults to the Metadata URL. Enrollment Flows Successfully created enrollment flow with invitation stage. Type a name for the new enrollment flow... Flow Slug Internal flow name used in URLs. e.g. my-enrollment-flow Invitation Stage Name Type a name for the stage... Select an enrollment flow. e.g. my-invite Create a new enrollment flow with invitation stage... The enrollment flow the invitation link will use. The flow should have an invitation stage bound to it for the invitation to be accepted. Invitation Stage Invitation Stages e.g. invitation-stage This user does not have an email address, so authentik cannot email a recovery link. Add an email address to enable email recovery. This brand does not have a recovery flow, so recovery links cannot be created. Configure a recovery flow in the brand settings to enable recovery. No notes. Created Changes Saved Successfully created Successfully updated Unknown Field Unknown Field Open "" Screen reader label for the application list row The message shown after a form is successfully submitted. Switch to list view Tooltip on the library view toggle when grid view is active Switch to grid view Tooltip on the library view toggle when list view is active Object Attribute Object Attributes Successfully updated attribute. Successfully created attribute. Type a human-readable name... Human-readable name of this attribute. Unique identifier per object type, which is used as a key in the attributes field. Type an optional group identifier... Optional grouping for this attribute in forms. When checked, attribute will be shown in forms for the selected object type. Text Boolean Validation Attribute is required Value of the attribute cannot be empty. Attribute is unique Value of the attribute must be unique across all instances of the selected object type. RegEx Enter an optional Regular Expression for validation... Optional RegEx to validate any value against. Uses the Python RegEx engine. Object attributes Object Attribute(s) New Attribute User Count Exceeded Internal user usage External user usage Allow application access with no policies Applications with no policies bound can be accessed by any user.. Expiring today Expiring in SAML 1.1 (required by Microsoft Entra ID / ADFS) SAML 2.0 SAML assertion version Microsoft Entra ID and classic ADFS-style relying parties typically require SAML 1.1. Base URL Configure the base URL under which this authentik instance is reachable, e.g. https://authentik.company. Do not include any path component (for example, /authentik). Sync Group Hierarchy Sync group hierarchy from LDAP directories. Additional Parent Group Dismiss banner Configure it in the system settings The base URL has not been configured. All Search for an offboarding by username... User Offboardings Scheduled deactivation or deletion of users, and their outcomes. Only show pending offboardings Scheduled for Scheduled by Offboarding(s) canceled Cancel Offboardings Cancel Offboarding Pending Offboardings Hide managed Managed Yes No Successfully cancelled offboarding. Failed to cancel offboarding Cancel offboarding Cancel scheduled offboarding The following scheduled offboarding will be cancelled: Offboarding scheduled for Cancel Offboarding Schedule Schedule Offboarding Schedule Offboarding User Offboarding User Offboardings Successfully scheduled offboarding. Action Deactivate Lock the user out of authentik without removing their account. Delete Permanently delete the user's account. Scheduled for The offboarding runs on the next scheduled check after this time (within a few minutes). Revoke sessions Revoke all of the user's sessions when offboarding. Revoke tokens Revoke all of the user's tokens when offboarding. User was offboarded Request rules Configure rules which grant users the ability to request access to this app. Request flow Select a request flow... Default flow used by users requesting access. Fulfill request Submit Requester Fulfiller Approved Denied Data Revoked Access Requests Apps Requester Data Targets Fulfill Successfully revoked grant Failed to revoke grant Revoke Revoke grant Are you sure you want to revoke this grant? Access will be removed immediately. Entitlement(s) Request rule binding(s) Bind existing rule These bindings control which users/groups can request access to this object. No request rules bound. No request rules are currently bound to this object. Request rule actions Request Rule Binding Request Rule Bindings Pending expiry How long a request against this binding stays pending before it automatically lapses if not approved or denied. Maximum granted expiry The maximum duration a grant approved against this binding can last. Requesters may ask for less, but never more. Additional entitlements Available entitlements Granted entitlements Application entitlements granted alongside access to this object when a request is approved. Everyone who can approve Only individually-selected reviewers A random subset (of size “minimum reviewers”) of everyone who can approve Request Rule Request Rules Type a name for this request rule... Number of reviewers that must approve the request before it is granted. Notify Who to notify when a request is created against this rule. Optional flow to use when a user requests access to a target bound to this rule. Select which transports should be used to notify reviewers. If none are selected, the notification will only be shown in the authentik UI. Search for a request rule by name... Define who can approve access requests for the objects these rules are bound to. Bound to Request rule(s) object(s) These bindings control which users/groups can approve requests. Access request created Access request approved Access request denied Access request revoked Show all schedules Show all tasks Standalone Include successful tasks Discover Requests to review: Access requests Browse My Requests For My Review Nothing available to request. There's currently nothing you're eligible to request access to. Requestable applications Requested Successfully cancelled request Failed to cancel request Cancel request Are you sure you want to cancel this pending request? No requests yet. Requests you've made for access will show up here. Nothing to review. Requests waiting on your approval will show up here. Search for an entitlement... No entitlements found for this application. Select entitlement Entitlement Requestor notes When enabled, fulfilling the request requires at least that many reviewers from each of the reviewer groups bound to this rule. When disabled, the value is a total across all reviewer groups. Unknown Grant type Dynamic Client Registration Successfully updated Dynamic Client Registration. Successfully enabled Dynamic Client Registration. Default application group Group assigned to automatically created applications. Override authorization flow Authorization flow applied to dynamically registered clients. When not selected, authorization flow of the parent provider is used. Override invalidation flow Invalidation flow applied to dynamically registered clients. When not selected, authorization flow of the parent provider is used. Override property mappings Access token validity Maximum access token validity for registered clients. Refresh token validity Maximum refresh token validity for registered clients. Allowed grant types If none are selected, all grant types are allowed. Dynamic Client Registration is not enabled. Allow OAuth2/OIDC clients to register themselves against this provider (RFC 7591). Enable Dynamic Client Registration Dynamic application policies Bindings configured here will be copied to dynamically registered applications. If no bindings are created, bindings of this providers' application are copied. User switch flow Select a user switch flow... Authentication flow used when switching between users signed in on the same browser. If left empty, user switching is disabled. Switch user Add another user Sign out current user Map tiles Vector tile source for the events map. Accepts a pmtiles:// archive URL or an XYZ template such as /tiles/{z}/{x}/{y}.mvt. Leave empty to use the bundled basemap, which needs no tile server. This URL is served to unauthenticated clients along with the rest of the brand, so avoid tile providers that carry an API key in the URL. Login Failed login Logout Authorize Application Other Adding Enable automatic discovery of remote resources. Scope mappings applied to dynamically registered clients. When not selected, scope mappings of the parent provider are used. Dynamic Client Registration URL Successfully deleted Dynamic Client Registration configuration Failed to delete Dynamic Client Registration configuration Delete Dynamic Client Registration configuration Are you sure you want to delete the Dynamic Client Registration configuration for this provider? No new clients will be able to register themselves, existing clients will not be removed. Define who can approve access requests for the objects this rule is bound to. New Request Rule Create a new request rule to bind to this object. Existing Request Rule Bind an existing request rule to this object. Mirror The agent has exactly the parent user's access, evaluated live. Copy Copy the parent's policy bindings onto the agent. None The agent uses only its own policy bindings. Agent Agents Close Successfully created agent. Parent user The user this agent acts on behalf of. Optional display name. Defaults to the parent user's name. Policy behavior How the agent's access relates to its parent user. Whether this agent should be automatically removed once it expires. Use the token below to authenticate as this agent. It is shown only once — store it now. Token Search for a agent... Admin-provisioned delegate identities that access can be requested and granted for, separately from their parent user. Parent Agent(s) Are you sure you want to deactivate ? Are you sure you want to activate ? Name Expires Actions Agent(s) Delete - Agent Delete Copy value Agent Agents Create Create Successfully created agent. Label Optional display name for this agent. This agent mirrors your access: it can act on exactly the applications you can, and never more. No agents. Create Agent Create Agent Create expiring agent identities and hand their token to a harness so it can act on your behalf via the API. Select File Type an optional file name without an extension... Custom Name Leave empty to keep the original filename. List of CIDRs (comma-separated) that clients can connect from. A more specific CIDR will match before a looser one. Clients connecting from a non-specified CIDR will be dropped. Upload file Select a file or enter a value... Choose an existing file, or enter a URL or Font Awesome icon. Supported values Valid file names can contain letters, numbers, dots, hyphens, underscores, slashes, and placeholders such as . Validation message for file name input. The placeholders are displayed as code elements. Valid file names can contain letters, numbers, dots, hyphens, underscores, slashes, and placeholders such as . Validation message for file name input. The placeholders are displayed as plain text. Object Attributes are in preview. Resume on matching failures Resume this flow for the selected source matching failures. No source connection is created. Missing property Stage Name Type a name for this stage... Show arbitrary input fields to the user, for example during enrollment. Data is saved in the flow context under the prompt_data variable.