Open WebUI · App integration
Single sign-on for Open WebUI
Open WebUI, the self-hosted chat interface for local and hosted models, can sign users in through any OpenID Connect provider. With Casdoor, your team signs in with their company account, and Casdoor groups decide which models and tools they see.
https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.Set up Open WebUI with Casdoor
- 1
Register Open WebUI in Casdoor
In the Casdoor console, open Applications, add an application for Open WebUI, and on its OIDC/OAuth tab copy the Client ID and Client secret. Add this redirect URL to Redirect URLs:
https://chat.example.com/oauth/oidc/callback
To use groups, create them in the application's organization (for example
engineeringorsupport) and add users. Then set Token group format to Name on the same tab, so tokens carryengineeringrather than<organization>/engineering. - 2
Set the OAuth environment variables
Add these to the Open WebUI container and restart it.
OPENID_PROVIDER_URLis Casdoor's discovery document.WEBUI_URL=https://chat.example.com ENABLE_OAUTH_SIGNUP=true DEFAULT_USER_ROLE=user OAUTH_PROVIDER_NAME=Casdoor OAUTH_CLIENT_ID=<client ID> OAUTH_CLIENT_SECRET=<client secret> OPENID_PROVIDER_URL=https://auth.example.com/.well-known/openid-configuration OAUTH_SCOPES=openid email profile ENABLE_OAUTH_GROUP_MANAGEMENT=true OAUTH_GROUP_CLAIM=groups - 3
Sign in
The login page now has a Continue with Casdoor button. With group management on, each sign-in syncs the user's Open WebUI groups with their Casdoor groups.
Good to know
- Open WebUI only adds users to groups that already exist in Open WebUI. Create them first, or set
ENABLE_OAUTH_GROUP_CREATION=trueto create them on sign-in. - By default, these environment variables are the source of truth and the OAuth section of the admin panel is read-only.
- Set
OAUTH_MERGE_ACCOUNTS_BY_EMAIL=trueif existing local users should keep their chats when they switch to Casdoor.
Open WebUI settings are from its documentation as of October 2026 (Open WebUI SSO, Open WebUI SSO troubleshooting); see also the Casdoor documentation. Open WebUI is a trademark of its owner.
Frequently asked questions
Who becomes an admin?
Users signing up through Casdoor get the role in DEFAULT_USER_ROLE. Left at its default, pending, an admin has to approve each new user; user lets them in straight away. Promote admins in the Open WebUI admin panel.
Can I restrict models by Casdoor group?
Yes. Once groups sync from Casdoor, give each Open WebUI group access to the models, knowledge bases and tools it should see.
More app integrations
View allArgo CD
App integrationConnect Argo CD to Casdoor over OpenID Connect: oidc.config in argocd-cm, the client secret, PKCE, CLI login and RBAC from Casdoor groups.
Gitea
App integrationAdd Casdoor to Gitea as an OpenID Connect authentication source: the add-oauth command, callback URL, and admins from a Casdoor group.
GitLab
App integrationConfigure self-managed GitLab to sign users in with Casdoor over OpenID Connect: gitlab.rb provider settings, account creation and group-based admins.
