authentik · Identity provider
Sign in to Casdoor with authentik
Add authentik to Casdoor as an OpenID Connect provider, and people sign in to your Casdoor applications with the accounts, MFA and policies they already have in authentik.
https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.Set up authentik with Casdoor
- 1
Create the application
In the authentik admin interface, open Applications → Applications and click New Application. Name it, set the slug to
casdoor, and choose OAuth2/OpenID Connect as the provider type. - 2
Configure the provider
In the provider step, keep the client type confidential, add a strict redirect URI, and pick a signing key:
Client type Confidential Redirect URIs Strict: https://auth.example.com/callback Signing Key authentik Self-signed Certificate (or your own) - 3
Copy the credentials
Finish the wizard, open the provider and copy its Client ID and Client Secret.
- 4
Add authentik as a provider in Casdoor
In the Casdoor console, open Providers, click Add, and fill in:
Category OAuth Type OIDC Display name authentik Client ID <client ID> Client secret <client secret> Issuer URL https://authentik.example.com/application/o/casdoor/ Auth URL https://authentik.example.com/application/o/authorize/ Token URL https://authentik.example.com/application/o/token/ Scope openid profile email UserInfo URL https://authentik.example.com/application/o/userinfo/ Logout URL https://authentik.example.com/application/o/casdoor/end-session/ Enable PKCE On Request next to Issuer URL fills in the other URLs from authentik's discovery document. Casdoor links users of every OIDC-type provider in an organization through the same field, so if the organization already has one, set Type to Custom Flexible instead, which links accounts per provider.
- 5
Add the provider to an application
Open Applications, edit the application people sign in to, and add the provider on its Providers tab. Its sign-in page now has a authentik button.
Good to know
- The issuer of an authentik provider contains the application slug and ends with a slash, for example
https://authentik.example.com/application/o/casdoor/. Casdoor compares it with the token's issuer, so the slug must match. - Always pick a signing key. Without one, authentik signs tokens with the client secret and publishes no keys.
- Since authentik 2025.10,
email_verifiedis false unless you change the email scope mapping, so Casdoor receives the email as unverified.
authentik settings are from its documentation as of October 2026 (authentik OAuth2 provider). authentik is a trademark of its owner.
Frequently asked questions
Casdoor says the issuer doesn't match. Why?
Check the slug and the trailing slash. If you set the provider's issuer mode to global, the issuer is https://authentik.example.com/ instead; put that in the provider's Issuer URL in Casdoor.
Do I need Include claims in id_token?
No. Casdoor also calls authentik's userinfo endpoint, which returns the profile and email claims.
More identity providers
View allAuthelia
Identity providerLet people sign in to Casdoor through Authelia over OpenID Connect: the provider settings, and the client to add to Authelia's configuration.
GitLab Self-Managed
Identity providerLet people sign in to Casdoor with accounts on your own GitLab over OpenID Connect: the provider settings, and the OAuth application to create in GitLab.
Keycloak
Identity providerLet people sign in to Casdoor with their Keycloak accounts over OpenID Connect: the provider settings for a Keycloak realm, and the client to create on the Keycloak side.
