GitLab Self-Managed · Identity provider
Sign in to Casdoor with your own GitLab
GitLab is also an OpenID Connect provider. Casdoor's built-in GitLab provider only talks to gitlab.com; this template points Casdoor at your own GitLab, so developers sign in with the account they already use every day.
https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.Set up GitLab Self-Managed with Casdoor
- 1
Create an OAuth application in GitLab
As an administrator, open Admin → Applications and click Add new application. (A group's Settings → Applications or your own Edit profile → Applications work too, without the Trusted option.) Fill in:
Name Casdoor Redirect URI https://auth.example.com/callback Trusted On, to skip the consent screen Confidential On Scopes openid, profile, email - 2
Copy the credentials
Save the application and copy the Application ID (the client ID) and the Secret. GitLab stores the secret hashed, so this is the only time you can see it.
- 3
Add GitLab Self-Managed as a provider in Casdoor
In the Casdoor console, open Providers, click Add, and fill in:
Category OAuth Type OIDC Display name GitLab Client ID <client ID> Client secret <client secret> Issuer URL https://gitlab.example.com Auth URL https://gitlab.example.com/oauth/authorize Token URL https://gitlab.example.com/oauth/token Scope openid profile email UserInfo URL https://gitlab.example.com/oauth/userinfo Enable PKCE On Request next to Issuer URL fills in the other URLs from GitLab Self-Managed's discovery document. Casdoor links users of every OIDC-type provider in an organization through the same field, so if the organization already has one, set Type to Custom Flexible instead, which links accounts per provider.
- 4
Add the provider to an application
Open Applications, edit the application people sign in to, and add the provider on its Providers tab. Its sign-in page now has a GitLab button.
Good to know
- GitLab only sends
emailfor users who have a public email address. Others arrive in Casdoor without an email. - Renewing the secret in GitLab breaks sign-in until you put the new one in Casdoor.
GitLab Self-Managed settings are from its documentation as of October 2026 (GitLab as an OpenID Connect provider, GitLab as an OAuth 2.0 provider, GitLab OAuth 2.0 API). GitLab Self-Managed is a trademark of its owner.
Frequently asked questions
Does this work with gitlab.com?
Yes, with https://gitlab.com as the GitLab URL, but Casdoor's built-in GitLab provider already covers gitlab.com.
Do GitLab groups come over?
No. GitLab returns the user's groups from its userinfo endpoint, but Casdoor only fills in the standard profile from it, not Casdoor groups.
More identity providers
View allAuthelia
Identity providerLet people sign in to Casdoor through Authelia over OpenID Connect: the provider settings, and the client to add to Authelia's configuration.
authentik
Identity providerLet people sign in to Casdoor with their authentik accounts over OpenID Connect: the provider settings, and the application and OAuth2 provider to create in authentik.
Keycloak
Identity providerLet people sign in to Casdoor with their Keycloak accounts over OpenID Connect: the provider settings for a Keycloak realm, and the client to create on the Keycloak side.
