Lock down your deployments without blocking your team

Dokploy gives you layered security at every level, from how your team authenticates to exactly what each user can access. Get SSO, custom roles, a complete audit trail, and host in your own secure environment.

Connect any identity provider

Enterprise users can authenticate through any OIDC or SAML 2.0-compatible identity provider. If your organization already runs Okta, Azure AD, or Keycloak, Dokploy connects to it.

Integrate with OIDC and SAML

Dokploy's SSO supports both OpenID Connect and SAML 2.0, so it works with virtually any enterprise IdP—no custom engineering work required.

Connect the providers you use

Pre-configured integrations with Okta, Microsoft Entra ID, Auth0, Keycloak, and Zitadel. Any other compatible provider can be configured.

Centralize user provisioning

When you add or remove a user in your IdP, it's reflected in Dokploy. No parallel user management, no accounts lingering after someone leaves.

Enforce your auth policies

MFA requirements, session timeouts, and conditional access rules configured in your IdP apply to Dokploy automatically so your security posture stays consistent.

Control exactly what each user can access

Role-based access control ships with every paid plan. Enterprise extends it with fully custom roles built from individual permissions across every resource type in the platform.

All plans

Assign built-in roles

Every paid plan includes built-in Owner, Admin, and Member roles, giving you immediate control over who can manage the platform and who simply uses it, with no configuration needed.

Enterprise

Build custom roles from scratch

Go beyond the defaults by creating roles with the permissions each function needs: a “deployer” who can trigger releases but can't touch infrastructure, or a “viewer” who can just read logs.

Enterprise

Set permissions at the resource level

Permissions span users, projects, services, servers, certificates, environment variables, domains, backups, and more—each with granular read, write, create, and delete controls.

Enterprise

Control deployment access independently

Deployment permissions are separate from service configuration permissions. A team member might be able to trigger a deploy without access to edit environment variables or infrastructure settings.

Enterprise

Restrict environment variable visibility

Sensitive configuration values stay hidden from users whose roles don't include environment variable read access, even if they can deploy and manage the service itself.

Enterprise

Scope access to logs and monitoring

Read access to application logs, audit entries, and server metrics—each one has separate permissions, so teams get the visibility they need without exposure to production configuration.

Know exactly who did what and when

Audit Logs give Enterprise organizations a complete, filterable record of every action taken across the platform—essential for SOC 2, GDPR, and internal change management processes.

Authentication events

every login, logout, and session change, with timestamps and the user responsible

User management

role assignments, invitations, and member removals

Deployments

every deploy triggered, cancelled, or queued, with the user and resource named

Infrastructure changes

servers, certificates, SSH keys, registries, and S3 destinations

Configuration changes

environment variables, domains, backups, and scheduled jobs

Powerful filtering

filter by user, action type, resource type, or resource name to zero in on exactly what you need

Security features by plan

Core access controls come with every paid plan. Enterprise adds the layers that compliance-conscious teams and larger organizations need.

Startup and above

A great starting point:

  • Built-in roles, including Admin and Developer
  • Two-factor authentication (2FA)
  • SSH key management
  • SSL/TLS certificate management
  • API key authentication
  • Server security audit checks
  • UFW firewall guidance
  • Email and chat support

Enterprise

Everything in Startup, plus:

  • SSO/SAML (Okta, Azure AD, Auth0, Keycloak, Zitadel, and more)
  • Fine-grained RBAC with custom roles
  • Audit logs
  • MSA/SLA
  • Complete hosting flexibility (on-prem or your own cloud)
  • Priority support

Security from the infrastructure up

Access control is only one part of the picture. Dokploy is built with server-level security in mind, including built-in guidance to keep your infrastructure hardened alongside your access policies.

Enable two-factor authentication

Startup plans and above include 2FA for all users: an extra layer of protection on top of passwords, without needing SSO.

Automate SSL/TLS certificate management

Dokploy handles certificate provisioning and renewal automatically via Traefik, so your services stay encrypted without manual intervention or renewal tracking.

Authenticate with SSH keys, not passwords

Dokploy's built-in security checks recommend disabling password authentication on your servers and switching to key-based SSH. You can manage your keys directly within the platform.

Keep your data on your own infrastructure

Self-hosted Dokploy means your deployments, credentials, and configurations stay on servers you control. No vendor accesses your environment.

Security and governance FAQs

What SSO providers does Dokploy support?

Dokploy supports any OIDC or SAML 2.0 provider. Pre-configured integrations are available for Okta, Azure AD (now Microsoft Entra ID), Auth0, Keycloak, and Zitadel. If your provider isn't listed, you can configure it manually using standard endpoints.

Is RBAC available on every plan?

Basic role-based access control—Owner, Admin, and Member roles—is available from the Startup plan. There are Admin and Developer roles on the Startup plan. Custom roles with granular, resource-level permissions are an Enterprise feature.

What does the audit log record?

Every meaningful action: logins and logouts, user and role changes, deployments, domain and certificate changes, environment variable edits, backup events, and infrastructure modifications.

Does Dokploy support SOC 2 or GDPR compliance?

Dokploy's Enterprise features—SSO, custom RBAC, and audit logs—are designed to support compliance with SOC 2, GDPR, and internal governance requirements. For MSA/SLA and compliance documentation, contact the Dokploy team.

Can I use SSO on Dokploy Cloud and self-hosted?

SSO is available on both Dokploy Cloud and self-hosted Enterprise instances. Contact sales for configuration support.

Deploy securely with Dokploy

Start shipping applications today with Dokploy, safe in the knowledge that your environment is secure. For additional governance, choose our Enterprise plan.