Grafana · App integration
Single sign-on for Grafana
Grafana's Generic OAuth works with any OpenID Connect provider. Point it at Casdoor and people sign in to Grafana with their Casdoor accounts, MFA and social logins included, with their Grafana role set from Casdoor groups.
https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.Set up Grafana with Casdoor
- 1
Register Grafana in Casdoor
In the Casdoor console, open Applications, add an application for Grafana, and on its OIDC/OAuth tab copy the Client ID and Client secret. Add this redirect URL to Redirect URLs:
https://grafana.example.com/login/generic_oauth
To use groups, create them in the application's organization (for example
grafana-adminsandgrafana-editors) and add users. Then set Token group format to Name on the same tab, so tokens carrygrafana-adminsrather than<organization>/grafana-admins. - 2
Configure Grafana
Add this section to
grafana.ini, or set the same keys asGF_AUTH_GENERIC_OAUTH_*environment variables.root_urlmust be the address people open in the browser, because Grafana builds the callback URL from it.[server] root_url = https://grafana.example.com/ [auth.generic_oauth] enabled = true name = Casdoor client_id = <client ID> client_secret = <client secret> scopes = openid profile email auth_url = https://auth.example.com/login/oauth/authorize token_url = https://auth.example.com/api/login/oauth/access_token api_url = https://auth.example.com/api/userinfo use_pkce = true allow_sign_up = true login_attribute_path = preferred_username email_attribute_path = email groups_attribute_path = groups role_attribute_path = contains(groups[*], 'grafana-admins') && 'Admin' || contains(groups[*], 'grafana-editors') && 'Editor' || 'Viewer' - 3
Sign in
Restart Grafana. The login page now has a Sign in with Casdoor button. Members of
grafana-adminsbecome Admins, members ofgrafana-editorsEditors, and everyone else a Viewer.
Good to know
- Grafana evaluates
role_attribute_pathagainst the ID token first, then the userinfo response. Casdoor's ID token also lists the user's roles as objects, socontains(roles[*].name, 'admin')works too if you prefer Casdoor roles to groups. - Grafana needs an email address for every user, so make sure your Casdoor users have one.
Grafana settings are from its documentation as of October 2026 (Grafana Generic OAuth); see also the Casdoor documentation. Grafana is a trademark of its owner.
Frequently asked questions
Can I use SAML instead?
Grafana's SAML sign-in is part of Grafana Enterprise and Grafana Cloud. On open-source Grafana, OpenID Connect through Generic OAuth, as shown here, is the way to connect Casdoor.
Do Casdoor groups become Grafana teams?
groups_attribute_path feeds Grafana's Team Sync, which is a Grafana Enterprise and Grafana Cloud feature. On open-source Grafana, use the groups to set roles as shown above.
More app integrations
View allArgo CD
App integrationConnect Argo CD to Casdoor over OpenID Connect: oidc.config in argocd-cm, the client secret, PKCE, CLI login and RBAC from Casdoor groups.
Gitea
App integrationAdd Casdoor to Gitea as an OpenID Connect authentication source: the add-oauth command, callback URL, and admins from a Casdoor group.
GitLab
App integrationConfigure self-managed GitLab to sign users in with Casdoor over OpenID Connect: gitlab.rb provider settings, account creation and group-based admins.
