CasdoorMarketplace
Submit

Authelia · Identity provider

Sign in to Casdoor with Authelia

Authelia's OpenID Connect provider lets other apps sign people in with their Authelia accounts and second factor. Add it to Casdoor, and your Casdoor applications get the same sign-in.

Verified by CasdoorOIDCPKCESelf-hosted
You need a running Casdoor, self-hosted or on Casdoor Cloud. In the examples, replace https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.

Set up Authelia with Casdoor

  1. 1

    Generate a client secret

    Authelia stores client secrets hashed. This prints a random secret and its digest: Casdoor gets the secret, Authelia's configuration the digest.

    authelia crypto hash generate pbkdf2 --variant sha512 --random --random.length 72 --random.charset rfc3986
  2. 2

    Register Casdoor as a client

    Add a client to Authelia's configuration, choosing any client ID, and restart Authelia.

    identity_providers:
      oidc:
        clients:
          - client_id: '<client ID>'
            client_name: 'Casdoor'
            client_secret: '<digest from the previous step>'
            public: false
            authorization_policy: 'two_factor'
            redirect_uris:
              - 'https://auth.example.com/callback'
            scopes: ['openid', 'profile', 'email']
            response_types: ['code']
            grant_types: ['authorization_code']
            token_endpoint_auth_method: 'client_secret_basic'
  3. 3

    Add Authelia as a provider in Casdoor

    In the Casdoor console, open Providers, click Add, and fill in:

    CategoryOAuth
    TypeOIDC
    Display nameAuthelia
    Client ID<client ID>
    Client secret<client secret>
    Issuer URLhttps://authelia.example.com
    Auth URLhttps://authelia.example.com/api/oidc/authorization
    Token URLhttps://authelia.example.com/api/oidc/token
    Scopeopenid profile email
    UserInfo URLhttps://authelia.example.com/api/oidc/userinfo
    Enable PKCEOn

    Request next to Issuer URL fills in the other URLs from Authelia's discovery document. Casdoor links users of every OIDC-type provider in an organization through the same field, so if the organization already has one, set Type to Custom Flexible instead, which links accounts per provider.

  4. 4

    Add the provider to an application

    Open Applications, edit the application people sign in to, and add the provider on its Providers tab. Its sign-in page now has a Authelia button.

Good to know

  • Authelia doesn't support RP-initiated logout, so signing out of Casdoor leaves the Authelia session alone.
  • Authelia keeps the ID token minimal and returns the profile and email claims from its userinfo endpoint, which Casdoor reads, so no claims_policy is needed.
  • If the discovery document shows wrong URLs, check the X-Forwarded-Proto and Host headers your reverse proxy sends to Authelia.

Authelia settings are from its documentation as of October 2026 (Authelia OpenID Connect, Authelia OIDC clients, Authelia OIDC claims). Authelia is a trademark of its owner.

Frequently asked questions

Which authorization policy should I use?

two_factor makes people complete Authelia's second factor before they reach Casdoor. Use one_factor if a password is enough, for example because Casdoor applications ask for MFA themselves.

Why client_secret_basic?

It is Authelia's default and the method Casdoor tries first.