CasdoorMarketplace
Submit

ZITADEL · Identity provider

Sign in to Casdoor with ZITADEL

Add ZITADEL to Casdoor as an OpenID Connect provider, self-hosted or ZITADEL Cloud, and people sign in to your Casdoor applications with their ZITADEL accounts.

Verified by CasdoorOIDCPKCECloud or self-hosted
You need a running Casdoor, self-hosted or on Casdoor Cloud. In the examples, replace https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.

Set up ZITADEL with Casdoor

  1. 1

    Create a web application

    In the ZITADEL Console, open the project the application belongs to (or create one), click New under its applications and choose Web.

  2. 2

    Choose Code and add the redirect URI

    Pick the Code authentication method: Casdoor sends the client secret with HTTP Basic authentication, which is what Code expects. Then add the redirect URI:

    Redirect URIshttps://auth.example.com/callback
  3. 3

    Copy the credentials

    Create the application. ZITADEL shows the Client ID and Client Secret once, so copy both now.

  4. 4

    Add ZITADEL as a provider in Casdoor

    In the Casdoor console, open Providers, click Add, and fill in:

    CategoryOAuth
    TypeOIDC
    Display nameZITADEL
    Client ID<client ID>
    Client secret<client secret>
    Issuer URLhttps://zitadel.example.com
    Auth URLhttps://zitadel.example.com/oauth/v2/authorize
    Token URLhttps://zitadel.example.com/oauth/v2/token
    Scopeopenid profile email
    UserInfo URLhttps://zitadel.example.com/oidc/v1/userinfo
    Logout URLhttps://zitadel.example.com/oidc/v1/end_session
    Enable PKCEOn

    Request next to Issuer URL fills in the other URLs from ZITADEL's discovery document. Casdoor links users of every OIDC-type provider in an organization through the same field, so if the organization already has one, set Type to Custom Flexible instead, which links accounts per provider.

  5. 5

    Add the provider to an application

    Open Applications, edit the application people sign in to, and add the provider on its Providers tab. Its sign-in page now has a ZITADEL button.

Good to know

  • ZITADEL's preferred_username is the login name, such as alice@acme.zitadel.cloud, and Casdoor uses it as the username of new users. Set a user mapping for username in Casdoor if you want something else.
  • ZITADEL only accepts plain-http redirect URIs in Development mode, so use https for Casdoor.

ZITADEL settings are from its documentation as of October 2026 (ZITADEL OIDC endpoints, ZITADEL claims, ZITADEL applications). ZITADEL is a trademark of its owner.

Frequently asked questions

Do I need User Info inside ID Token?

No. Casdoor also calls ZITADEL's userinfo endpoint, which returns the name and email.

Can I use the PKCE authentication method instead?

That method issues no client secret, while Casdoor's provider is a confidential client. Use Code; Casdoor sends a PKCE challenge on top of the secret anyway.