Nextcloud · App integration
Single sign-on for Nextcloud
Nextcloud's OpenID Connect user backend app (user_oidc) creates Nextcloud accounts from an OpenID Connect provider. With Casdoor as the provider, people sign in to Nextcloud with their Casdoor account, and their Casdoor groups become Nextcloud groups.
https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.Set up Nextcloud with Casdoor
- 1
Register Nextcloud in Casdoor
In the Casdoor console, open Applications, add an application for Nextcloud, and on its OIDC/OAuth tab copy the Client ID and Client secret. Add this redirect URL to Redirect URLs:
https://cloud.example.com/apps/user_oidc/code
If your Nextcloud URLs include
/index.php, usehttps://cloud.example.com/index.php/apps/user_oidc/codeinstead. To use groups, create them in the application's organization (for examplefamilyorfinance) and add users. Then set Token group format to Name on the same tab, so tokens carryfamilyrather than<organization>/family. - 2
Install the OpenID Connect app
Install OpenID Connect user backend from the Nextcloud app store, or with occ:
sudo -u www-data php occ app:install user_oidc - 3
Add Casdoor as a provider
Run this from the Nextcloud directory. It names the provider Casdoor, maps Nextcloud user IDs to Casdoor usernames instead of hashes, and creates Nextcloud groups from the
groupsclaim.sudo -u www-data php occ user_oidc:provider Casdoor \ --clientid="<client ID>" \ --clientsecret="<client secret>" \ --discoveryuri="https://auth.example.com/.well-known/openid-configuration" \ --scope="openid email profile" \ --unique-uid=0 \ --mapping-uid=name \ --mapping-display-name=displayName \ --mapping-email=email \ --mapping-groups=groups \ --group-provisioning=1 - 4
Sign in
The Nextcloud login page now has a Log in with Casdoor button. To send everyone straight to Casdoor, turn off the other login methods; administrators can still reach the normal login form by adding
?direct=1to the login URL.sudo -u www-data php occ config:app:set --type=string --value=0 user_oidc allow_multiple_user_backends
Good to know
- The mappings above read Casdoor's default ID token, where
nameis the username anddisplayNamethe display name. If you switch the application's Token format to JWT-Standard, map the user ID topreferred_usernameand the display name tonameinstead; that format doesn't include groups. - Without
--unique-uid=0, Nextcloud stores each user under a hash of the provider and user ID, which is safe with several providers but hard to read.
Nextcloud settings are from its documentation as of October 2026 (Nextcloud user_oidc); see also the Casdoor documentation. Nextcloud is a trademark of its owner.
Frequently asked questions
Does it work with the Nextcloud desktop and mobile apps?
Yes. The apps sign in through the browser using Nextcloud's login flow, which shows the same Log in with Casdoor button.
Can I use LDAP instead?
Casdoor also runs an LDAP server that Nextcloud's LDAP app can use. OpenID Connect is simpler to set up, and it keeps Casdoor's MFA, passkeys and social logins in the sign-in.
More app integrations
View allArgo CD
App integrationConnect Argo CD to Casdoor over OpenID Connect: oidc.config in argocd-cm, the client secret, PKCE, CLI login and RBAC from Casdoor groups.
Gitea
App integrationAdd Casdoor to Gitea as an OpenID Connect authentication source: the add-oauth command, callback URL, and admins from a Casdoor group.
GitLab
App integrationConfigure self-managed GitLab to sign users in with Casdoor over OpenID Connect: gitlab.rb provider settings, account creation and group-based admins.
