GitLab · App integration
Single sign-on for self-managed GitLab
Self-managed GitLab signs users in through OmniAuth providers, including any OpenID Connect provider. With Casdoor as the provider, developers use one account for GitLab and the rest of your tools.
https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.Set up GitLab with Casdoor
- 1
Register GitLab in Casdoor
In the Casdoor console, open Applications, add an application for GitLab, and on its OIDC/OAuth tab copy the Client ID and Client secret. Add this redirect URL to Redirect URLs:
https://gitlab.example.com/users/auth/openid_connect/callback
- 2
Add Casdoor to gitlab.rb
GitLab only talks to OpenID providers over HTTPS, so serve Casdoor over HTTPS. Add this to
/etc/gitlab/gitlab.rband runsudo gitlab-ctl reconfigure.gitlab_rails['omniauth_allow_single_sign_on'] = ['openid_connect'] gitlab_rails['omniauth_block_auto_created_users'] = false gitlab_rails['omniauth_providers'] = [ { name: "openid_connect", label: "Casdoor", args: { name: "openid_connect", scope: ["openid", "profile", "email"], response_type: "code", issuer: "https://auth.example.com", discovery: true, client_auth_method: "query", uid_field: "sub", pkce: true, client_options: { identifier: "<client ID>", secret: "<client secret>", redirect_uri: "https://gitlab.example.com/users/auth/openid_connect/callback" } } } ] - 3
Map Casdoor groups (GitLab Premium and Ultimate)
To make members of a Casdoor group GitLab administrators, or to mark contractors as external users, add a
gitlabblock insideclient_options. Set the Casdoor application's Token group format to Name so the values match.gitlab: { groups_attribute: "groups", admin_groups: ["gitlab-admins"], external_groups: ["contractors"] } - 4
Sign in
The sign-in page now has a Casdoor button. People who already have a GitLab account can connect Casdoor under User settings → Account → Service sign-in.
Good to know
omniauth_allow_single_sign_onlets GitLab create an account on first sign-in, andomniauth_block_auto_created_users = falselets new users in without waiting for an administrator to approve them.uid_field: "sub"ties each GitLab identity to the Casdoor user ID, which doesn't change when a user is renamed.
GitLab settings are from its documentation as of October 2026 (GitLab OpenID Connect); see also the Casdoor documentation. GitLab is a trademark of its owner.
Frequently asked questions
Do I need GitLab Premium?
Not for single sign-on: any self-managed GitLab can use Casdoor as its OpenID Connect provider. Rules based on OIDC group membership (required, external and admin groups) need GitLab Premium or Ultimate.
I compiled GitLab from source. Where do the settings go?
Put the same provider settings under omniauth in config/gitlab.yml; GitLab's OpenID Connect documentation shows that format next to the gitlab.rb one.
More app integrations
View allArgo CD
App integrationConnect Argo CD to Casdoor over OpenID Connect: oidc.config in argocd-cm, the client secret, PKCE, CLI login and RBAC from Casdoor groups.
Gitea
App integrationAdd Casdoor to Gitea as an OpenID Connect authentication source: the add-oauth command, callback URL, and admins from a Casdoor group.
Grafana
App integrationSet up Grafana single sign-on with Casdoor over OpenID Connect: Generic OAuth settings, PKCE, and Grafana roles mapped from Casdoor groups.
