Proxmox VE · App integration
Single sign-on for Proxmox VE
Proxmox VE can authenticate users against an OpenID Connect realm. With Casdoor as the realm, admins sign in to the Proxmox web interface with their Casdoor account and MFA, and Proxmox permissions follow Casdoor groups.
https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.Set up Proxmox VE with Casdoor
- 1
Register Proxmox VE in Casdoor
In the Casdoor console, open Applications, add an application for Proxmox VE, and on its OIDC/OAuth tab copy the Client ID and Client secret. Add this redirect URL to Redirect URLs:
https://pve.example.com:8006
Proxmox VE sends the address of its web interface as the redirect URL, so add every address you open it at, with the port. To use groups, create them in the application's organization (for example
pve-admins) and add users. Then set Token group format to Name on the same tab, so tokens carrypve-adminsrather than<organization>/pve-admins. - 2
Add an OpenID Connect realm
Run this on a Proxmox VE node, or add the realm under Datacenter → Permissions → Realms → Add → OpenID Connect Server.
usernametakes thepreferred_usernameclaim, so users appear asalice@casdoor.pveum realm add casdoor --type openid \ --issuer-url https://auth.example.com \ --client-id "<client ID>" \ --client-key "<client secret>" \ --username-claim username \ --autocreate 1 \ --groups-claim groups \ --groups-autocreate 1 - 3
Give the group permissions
Proxmox VE appends the realm name to groups from the claim, so
pve-adminsbecomespve-admins-casdoor. Grant it a role, for example administrator rights on the whole datacenter:pveum acl modify / --groups pve-admins-casdoor --roles Administrator - 4
Sign in
On the Proxmox VE login screen, choose the casdoor realm and click Login (OpenID redirect); Proxmox sends you to Casdoor and back.
Good to know
- Users created by
--autocreatehave no permissions until a group or user ACL grants them some. - The group options are in recent Proxmox VE releases; on older versions, leave out the
--groups-*lines and grant permissions to users instead.
Proxmox VE settings are from its documentation as of October 2026 (Proxmox VE user management, pveum manual); see also the Casdoor documentation. Proxmox VE is a trademark of its owner.
Frequently asked questions
Can I still use root@pam?
Yes. Adding a realm doesn't change the existing PAM and Proxmox VE realms, so keep root@pam as a fallback.
Why username and not the default subject claim?
The default sub claim is Casdoor's user ID, a random string. username gives readable names such as alice@casdoor; Casdoor usernames are unique within an organization.
More app integrations
View allArgo CD
App integrationConnect Argo CD to Casdoor over OpenID Connect: oidc.config in argocd-cm, the client secret, PKCE, CLI login and RBAC from Casdoor groups.
Gitea
App integrationAdd Casdoor to Gitea as an OpenID Connect authentication source: the add-oauth command, callback URL, and admins from a Casdoor group.
GitLab
App integrationConfigure self-managed GitLab to sign users in with Casdoor over OpenID Connect: gitlab.rb provider settings, account creation and group-based admins.
