IdPVault Documentation
Self-hosted backup, drift detection, and restore for Authentik, Okta, and Auth0.
IdPVault takes encrypted, versioned snapshots of your identity provider configuration - every app, flow, policy, group, user, and assignment in Authentik, Okta, and Auth0 - shows exactly what changed, and restores selectively with a dry-run preview. These docs are the same ones built into the app.
Getting startedDeploy IdPVault and connect your first tenant.
Backups & snapshotsEncrypted config snapshots, retention, Full-DR capture and restore.
Live StateThe provider's current config vs your latest backup.
Drift & eventsUnbacked-changes detection and the change events feed.
Config restoreSelective restore with dry-run previews and per-object reports.
Clone & promoteApply a snapshot into another tenant: staging to prod, standby, DR.
Users & Access backupBack up and restore users, memberships, and app assignments.
Alerts & notificationsEmail and webhook alerts: drift, failures, restores, clones.
Users & securityApp users, roles, MFA, sessions, and the audit log.
Licensing & tiersCommunity, Business, and MSP tiers; offline license keys.
MSP & client orgsClient orgs, scoped roles, renewal tracking, CSV onboarding.
Deployment & proxyCompose, reverse proxies, public URL, and upgrades.