CasdoorMarketplace
Submit

authentik · Identity provider

Sign in to Casdoor with authentik

Add authentik to Casdoor as an OpenID Connect provider, and people sign in to your Casdoor applications with the accounts, MFA and policies they already have in authentik.

Verified by CasdoorOIDCPKCESelf-hosted
You need a running Casdoor, self-hosted or on Casdoor Cloud. In the examples, replace https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.

Set up authentik with Casdoor

  1. 1

    Create the application

    In the authentik admin interface, open Applications → Applications and click New Application. Name it, set the slug to casdoor, and choose OAuth2/OpenID Connect as the provider type.

  2. 2

    Configure the provider

    In the provider step, keep the client type confidential, add a strict redirect URI, and pick a signing key:

    Client typeConfidential
    Redirect URIsStrict: https://auth.example.com/callback
    Signing Keyauthentik Self-signed Certificate (or your own)
  3. 3

    Copy the credentials

    Finish the wizard, open the provider and copy its Client ID and Client Secret.

  4. 4

    Add authentik as a provider in Casdoor

    In the Casdoor console, open Providers, click Add, and fill in:

    CategoryOAuth
    TypeOIDC
    Display nameauthentik
    Client ID<client ID>
    Client secret<client secret>
    Issuer URLhttps://authentik.example.com/application/o/casdoor/
    Auth URLhttps://authentik.example.com/application/o/authorize/
    Token URLhttps://authentik.example.com/application/o/token/
    Scopeopenid profile email
    UserInfo URLhttps://authentik.example.com/application/o/userinfo/
    Logout URLhttps://authentik.example.com/application/o/casdoor/end-session/
    Enable PKCEOn

    Request next to Issuer URL fills in the other URLs from authentik's discovery document. Casdoor links users of every OIDC-type provider in an organization through the same field, so if the organization already has one, set Type to Custom Flexible instead, which links accounts per provider.

  5. 5

    Add the provider to an application

    Open Applications, edit the application people sign in to, and add the provider on its Providers tab. Its sign-in page now has a authentik button.

Good to know

  • The issuer of an authentik provider contains the application slug and ends with a slash, for example https://authentik.example.com/application/o/casdoor/. Casdoor compares it with the token's issuer, so the slug must match.
  • Always pick a signing key. Without one, authentik signs tokens with the client secret and publishes no keys.
  • Since authentik 2025.10, email_verified is false unless you change the email scope mapping, so Casdoor receives the email as unverified.

authentik settings are from its documentation as of October 2026 (authentik OAuth2 provider). authentik is a trademark of its owner.

Frequently asked questions

Casdoor says the issuer doesn't match. Why?

Check the slug and the trailing slash. If you set the provider's issuer mode to global, the issuer is https://authentik.example.com/ instead; put that in the provider's Issuer URL in Casdoor.

Do I need Include claims in id_token?

No. Casdoor also calls authentik's userinfo endpoint, which returns the profile and email claims.