Dokploy gives you layered security at every level, from how your team authenticates to exactly what each user can access. Get SSO, custom roles, a complete audit trail, and host in your own secure environment.
Enterprise users can authenticate through any OIDC or SAML 2.0-compatible identity provider. If your organization already runs Okta, Azure AD, or Keycloak, Dokploy connects to it.
Dokploy's SSO supports both OpenID Connect and SAML 2.0, so it works with virtually any enterprise IdP—no custom engineering work required.
Pre-configured integrations with Okta, Microsoft Entra ID, Auth0, Keycloak, and Zitadel. Any other compatible provider can be configured.
When you add or remove a user in your IdP, it's reflected in Dokploy. No parallel user management, no accounts lingering after someone leaves.
MFA requirements, session timeouts, and conditional access rules configured in your IdP apply to Dokploy automatically so your security posture stays consistent.
Role-based access control ships with every paid plan. Enterprise extends it with fully custom roles built from individual permissions across every resource type in the platform.
Every paid plan includes built-in Owner, Admin, and Member roles, giving you immediate control over who can manage the platform and who simply uses it, with no configuration needed.
Go beyond the defaults by creating roles with the permissions each function needs: a “deployer” who can trigger releases but can't touch infrastructure, or a “viewer” who can just read logs.
Permissions span users, projects, services, servers, certificates, environment variables, domains, backups, and more—each with granular read, write, create, and delete controls.
Deployment permissions are separate from service configuration permissions. A team member might be able to trigger a deploy without access to edit environment variables or infrastructure settings.
Sensitive configuration values stay hidden from users whose roles don't include environment variable read access, even if they can deploy and manage the service itself.
Read access to application logs, audit entries, and server metrics—each one has separate permissions, so teams get the visibility they need without exposure to production configuration.
Audit Logs give Enterprise organizations a complete, filterable record of every action taken across the platform—essential for SOC 2, GDPR, and internal change management processes.
every login, logout, and session change, with timestamps and the user responsible
role assignments, invitations, and member removals
every deploy triggered, cancelled, or queued, with the user and resource named
servers, certificates, SSH keys, registries, and S3 destinations
environment variables, domains, backups, and scheduled jobs
filter by user, action type, resource type, or resource name to zero in on exactly what you need
Core access controls come with every paid plan. Enterprise adds the layers that compliance-conscious teams and larger organizations need.
A great starting point:
Everything in Startup, plus:
Access control is only one part of the picture. Dokploy is built with server-level security in mind, including built-in guidance to keep your infrastructure hardened alongside your access policies.
Startup plans and above include 2FA for all users: an extra layer of protection on top of passwords, without needing SSO.
Dokploy handles certificate provisioning and renewal automatically via Traefik, so your services stay encrypted without manual intervention or renewal tracking.
Dokploy's built-in security checks recommend disabling password authentication on your servers and switching to key-based SSH. You can manage your keys directly within the platform.
Self-hosted Dokploy means your deployments, credentials, and configurations stay on servers you control. No vendor accesses your environment.
Dokploy supports any OIDC or SAML 2.0 provider. Pre-configured integrations are available for Okta, Azure AD (now Microsoft Entra ID), Auth0, Keycloak, and Zitadel. If your provider isn't listed, you can configure it manually using standard endpoints.
Basic role-based access control—Owner, Admin, and Member roles—is available from the Startup plan. There are Admin and Developer roles on the Startup plan. Custom roles with granular, resource-level permissions are an Enterprise feature.
Every meaningful action: logins and logouts, user and role changes, deployments, domain and certificate changes, environment variable edits, backup events, and infrastructure modifications.
Dokploy's Enterprise features—SSO, custom RBAC, and audit logs—are designed to support compliance with SOC 2, GDPR, and internal governance requirements. For MSA/SLA and compliance documentation, contact the Dokploy team.
SSO is available on both Dokploy Cloud and self-hosted Enterprise instances. Contact sales for configuration support.
Dive deeper into the access control and governance features that keep your organization secure.
Centralize authentication with your existing identity provider for secure, seamless access across your organization.
Define exactly what each user can do once they're in Dokploy, with granular role and permission controls across projects, services, and features.
Keep a full record of every login, logout, and action taken across your Dokploy environment for compliance and accountability.
Start shipping applications today with Dokploy, safe in the knowledge that your environment is secure. For additional governance, choose our Enterprise plan.