Vaultwarden · App integration
Single sign-on for Vaultwarden
Since version 1.35.0, Vaultwarden can sign users in through an OpenID Connect provider. With Casdoor, your team signs in to the password manager with the same account and MFA they use everywhere else.
https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.Set up Vaultwarden with Casdoor
- 1
Register Vaultwarden in Casdoor
In the Casdoor console, open Applications, add an application for Vaultwarden, and on its OIDC/OAuth tab copy the Client ID and Client secret. Add this redirect URL to Redirect URLs:
https://vault.example.com/identity/connect/oidc-signin
- 2
Configure Vaultwarden
Set these environment variables on Vaultwarden 1.35.0 or later, for example in Docker Compose, and restart it. Vaultwarden builds the redirect URI from
DOMAIN.services: vaultwarden: image: vaultwarden/server:latest environment: DOMAIN: "https://vault.example.com" SSO_ENABLED: "true" SSO_AUTHORITY: "https://auth.example.com" SSO_CLIENT_ID: "<client ID>" SSO_CLIENT_SECRET: "<client secret>" SSO_SCOPES: "email profile" SSO_PKCE: "true" - 3
Sign in
Users can now choose single sign-on on the Vaultwarden login page, sign in at Casdoor, and then unlock their vault. Add
SSO_ONLY: "true"once everyone has switched, to turn off email-and-password login.
Good to know
SSO_AUTHORITYmust equal theissuerinhttps://auth.example.com/.well-known/openid-configurationexactly, without a trailing slash.- Vaultwarden refuses to sign up a user whose ID token says
email_verified: false. Casdoor marks an email as verified once the user confirms it with a code or a magic link, for example at sign-up. - The Bitwarden mobile apps support Vaultwarden SSO from version 2026.1.0.
Vaultwarden settings are from its documentation as of October 2026 (Vaultwarden SSO wiki, Vaultwarden releases); see also the Casdoor documentation. Vaultwarden is a trademark of its owner.
Frequently asked questions
Do users still need a master password?
Yes. Single sign-on replaces the email-and-password login, but the vault is still encrypted with the user's master password, which they enter after signing in with Casdoor.
I don't see the single sign-on option. Why?
Check that the server runs Vaultwarden 1.35.0 or later and that SSO_ENABLED is true, then restart it. If sign-in fails afterwards, compare SSO_AUTHORITY with Casdoor's issuer and check the redirect URI in the Casdoor application.
More app integrations
View allArgo CD
App integrationConnect Argo CD to Casdoor over OpenID Connect: oidc.config in argocd-cm, the client secret, PKCE, CLI login and RBAC from Casdoor groups.
Gitea
App integrationAdd Casdoor to Gitea as an OpenID Connect authentication source: the add-oauth command, callback URL, and admins from a Casdoor group.
GitLab
App integrationConfigure self-managed GitLab to sign users in with Casdoor over OpenID Connect: gitlab.rb provider settings, account creation and group-based admins.
