Skip to content

Authentik (Single Sign-On)

Website: https://auth.deepinthesand.com

What it does

Authentik is an open-source Identity Provider. It lets you use one username and password (plus 2FA) to log in to almost every service on Deep in the Sand. When a service shows a "Sign in with Authentik" button, click it — if you're already signed in, you'll be let straight through.

Replaces

Okta, Auth0, Microsoft Entra ID (Azure AD), Google Workspace SSO.

First login

  1. Go to https://auth.deepinthesand.com.
  2. Enter the username and password Ammo gave you.
  3. Consider changing your password. See below for steps.
  4. Setup 2 Factor Authentication - this is really important for security and making sure only you can login. See below for steps.

Changing your password

  1. Sign in at https://auth.deepinthesand.com.
  2. Click on the gear icon (top-right) → Settings.
  3. Click User details, Change password, enter your new password twice and save.

Setting up 2FA (TOTP) — do this immediately

TOTP = time-based one-time passwords, the 6-digit codes that refresh every 30 seconds.

Recommended authenticator apps (FOSS-friendly):

Save your recovery / backup codes

When you enable TOTP, you'll be shown one-time recovery codes. Save them somewhere safe — a printed copy in a drawer, or a Secure Note in your Vaultwarden vault. If you lose your phone and don't have these, you will be locked out and Ammo will need to manually reset your 2FA.

Steps:

  1. In Authentik, click your name → User settingsMFA Authenticators.
  2. Click Enroll → TOTP Device.
  3. Open Aegis/Raivo, tap +, choose Scan QR code, scan the QR shown by Authentik.
  4. Enter the 6-digit code to confirm.
  5. Save your recovery codes in Vaultwarden under a Secure Note.

Problem with this service? Message Ammo or email admin(Q)deepinthesand(P)com.