Argo CD · App integration
Single sign-on for Argo CD
Argo CD can use an existing OpenID Connect provider directly, without its bundled Dex. With Casdoor, people sign in to the Argo CD UI and CLI with their Casdoor account, and Casdoor groups decide what they can do.
https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.Set up Argo CD with Casdoor
- 1
Register Argo CD in Casdoor
In the Casdoor console, open Applications, add an application for Argo CD, and on its OIDC/OAuth tab copy the Client ID and Client secret. Add these redirect URLs to Redirect URLs:
https://argocd.example.com/auth/callbackhttp://localhost:8085/auth/callback
The second URL is for
argocd login --ssofrom the CLI. To use groups, create them in the application's organization (for exampleargocd-admins) and add users. Then set Token group format to Name on the same tab, so tokens carryargocd-adminsrather than<organization>/argocd-admins. - 2
Store the client secret
Put the client secret in the
argocd-secretSecret, whereoidc.configcan reference it.kubectl -n argocd patch secret argocd-secret \ --patch='{"stringData": {"oidc.casdoor.clientSecret": "<client secret>"}}' - 3
Configure OIDC in argocd-cm
Add Casdoor to the
argocd-cmConfigMap. Casdoor puts the user's groups in the ID token, which is where Argo CD reads them.apiVersion: v1 kind: ConfigMap metadata: name: argocd-cm namespace: argocd data: url: https://argocd.example.com oidc.config: | name: Casdoor issuer: https://auth.example.com clientID: <client ID> clientSecret: $oidc.casdoor.clientSecret requestedScopes: ["openid", "profile", "email"] enablePKCEAuthentication: true - 4
Grant permissions by group
Map Casdoor groups to Argo CD roles in
argocd-rbac-cm. Here members ofargocd-adminsget full access and everyone else can only look.apiVersion: v1 kind: ConfigMap metadata: name: argocd-rbac-cm namespace: argocd data: policy.default: role:readonly policy.csv: | g, argocd-admins, role:admin scopes: "[groups]" - 5
Sign in
The Argo CD login page now has a Log in via Casdoor button, and
argocd login argocd.example.com --ssoopens Casdoor in the browser.
Good to know
- Argo CD reads
oidc.configchanges without a restart, but users have to sign in again to pick up new group memberships.
Argo CD settings are from its documentation as of October 2026 (Argo CD user management); see also the Casdoor documentation. Argo CD is a trademark of its owner.
Frequently asked questions
Do I still need Dex?
No. With oidc.config, Argo CD talks to Casdoor directly, and you can leave Dex unconfigured.
Can the argocd CLI sign in through Casdoor?
Yes. argocd login <server> --sso opens the browser and receives the result on http://localhost:8085/auth/callback, which is why that URL is in the Casdoor application.
More app integrations
View allGitea
App integrationAdd Casdoor to Gitea as an OpenID Connect authentication source: the add-oauth command, callback URL, and admins from a Casdoor group.
GitLab
App integrationConfigure self-managed GitLab to sign users in with Casdoor over OpenID Connect: gitlab.rb provider settings, account creation and group-based admins.
Grafana
App integrationSet up Grafana single sign-on with Casdoor over OpenID Connect: Generic OAuth settings, PKCE, and Grafana roles mapped from Casdoor groups.
