Authelia · Identity provider
Sign in to Casdoor with Authelia
Authelia's OpenID Connect provider lets other apps sign people in with their Authelia accounts and second factor. Add it to Casdoor, and your Casdoor applications get the same sign-in.
https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.Set up Authelia with Casdoor
- 1
Generate a client secret
Authelia stores client secrets hashed. This prints a random secret and its digest: Casdoor gets the secret, Authelia's configuration the digest.
authelia crypto hash generate pbkdf2 --variant sha512 --random --random.length 72 --random.charset rfc3986 - 2
Register Casdoor as a client
Add a client to Authelia's configuration, choosing any client ID, and restart Authelia.
identity_providers: oidc: clients: - client_id: '<client ID>' client_name: 'Casdoor' client_secret: '<digest from the previous step>' public: false authorization_policy: 'two_factor' redirect_uris: - 'https://auth.example.com/callback' scopes: ['openid', 'profile', 'email'] response_types: ['code'] grant_types: ['authorization_code'] token_endpoint_auth_method: 'client_secret_basic' - 3
Add Authelia as a provider in Casdoor
In the Casdoor console, open Providers, click Add, and fill in:
Category OAuth Type OIDC Display name Authelia Client ID <client ID> Client secret <client secret> Issuer URL https://authelia.example.com Auth URL https://authelia.example.com/api/oidc/authorization Token URL https://authelia.example.com/api/oidc/token Scope openid profile email UserInfo URL https://authelia.example.com/api/oidc/userinfo Enable PKCE On Request next to Issuer URL fills in the other URLs from Authelia's discovery document. Casdoor links users of every OIDC-type provider in an organization through the same field, so if the organization already has one, set Type to Custom Flexible instead, which links accounts per provider.
- 4
Add the provider to an application
Open Applications, edit the application people sign in to, and add the provider on its Providers tab. Its sign-in page now has a Authelia button.
Good to know
- Authelia doesn't support RP-initiated logout, so signing out of Casdoor leaves the Authelia session alone.
- Authelia keeps the ID token minimal and returns the profile and email claims from its userinfo endpoint, which Casdoor reads, so no
claims_policyis needed. - If the discovery document shows wrong URLs, check the
X-Forwarded-ProtoandHostheaders your reverse proxy sends to Authelia.
Authelia settings are from its documentation as of October 2026 (Authelia OpenID Connect, Authelia OIDC clients, Authelia OIDC claims). Authelia is a trademark of its owner.
Frequently asked questions
Which authorization policy should I use?
two_factor makes people complete Authelia's second factor before they reach Casdoor. Use one_factor if a password is enough, for example because Casdoor applications ask for MFA themselves.
Why client_secret_basic?
It is Authelia's default and the method Casdoor tries first.
More identity providers
View allauthentik
Identity providerLet people sign in to Casdoor with their authentik accounts over OpenID Connect: the provider settings, and the application and OAuth2 provider to create in authentik.
GitLab Self-Managed
Identity providerLet people sign in to Casdoor with accounts on your own GitLab over OpenID Connect: the provider settings, and the OAuth application to create in GitLab.
Keycloak
Identity providerLet people sign in to Casdoor with their Keycloak accounts over OpenID Connect: the provider settings for a Keycloak realm, and the client to create on the Keycloak side.
