Portainer · App integration
Single sign-on for Portainer
Portainer's custom OAuth provider works with Casdoor's OAuth 2.0 endpoints, so people manage containers with their Casdoor account instead of a separate Portainer password.
https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.Set up Portainer with Casdoor
- 1
Register Portainer in Casdoor
In the Casdoor console, open Applications, add an application for Portainer, and on its OIDC/OAuth tab copy the Client ID and Client secret. Add this redirect URL to Redirect URLs:
https://portainer.example.com
- 2
Configure OAuth in Portainer
In Portainer, open Settings → Authentication, choose OAuth, turn on Use SSO and Automatic user provisioning, pick the Custom provider and fill in:
Client ID <client ID> Client secret <client secret> Authorization URL https://auth.example.com/login/oauth/authorize Access token URL https://auth.example.com/api/login/oauth/access_token Resource URL https://auth.example.com/api/userinfo Redirect URL https://portainer.example.com User identifier preferred_username Scopes openid profile email - 3
Sign in
Save and log out. The Portainer login page now has a Login with OAuth button that sends users to Casdoor.
Good to know
- New users created by automatic provisioning have no access until you add them to a team or give them access to an environment.
- The Redirect URL in Portainer and in Casdoor must be the address people open Portainer at, exactly.
Portainer settings are from its documentation as of October 2026 (Portainer OAuth); see also the Casdoor documentation. Portainer is a trademark of its owner.
Frequently asked questions
Can Casdoor groups become Portainer teams?
Mapping OAuth groups to Portainer teams is a Portainer Business Edition feature. In the Community Edition, assign users to teams in Portainer.
Why preferred_username as the user identifier?
It is the Casdoor username in the userinfo response, so Portainer usernames match Casdoor's. You can use email instead if you prefer.
More app integrations
View allArgo CD
App integrationConnect Argo CD to Casdoor over OpenID Connect: oidc.config in argocd-cm, the client secret, PKCE, CLI login and RBAC from Casdoor groups.
Gitea
App integrationAdd Casdoor to Gitea as an OpenID Connect authentication source: the add-oauth command, callback URL, and admins from a Casdoor group.
GitLab
App integrationConfigure self-managed GitLab to sign users in with Casdoor over OpenID Connect: gitlab.rb provider settings, account creation and group-based admins.
