ZITADEL · Identity provider
Sign in to Casdoor with ZITADEL
Add ZITADEL to Casdoor as an OpenID Connect provider, self-hosted or ZITADEL Cloud, and people sign in to your Casdoor applications with their ZITADEL accounts.
https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.Set up ZITADEL with Casdoor
- 1
Create a web application
In the ZITADEL Console, open the project the application belongs to (or create one), click New under its applications and choose Web.
- 2
Choose Code and add the redirect URI
Pick the Code authentication method: Casdoor sends the client secret with HTTP Basic authentication, which is what Code expects. Then add the redirect URI:
Redirect URIs https://auth.example.com/callback - 3
Copy the credentials
Create the application. ZITADEL shows the Client ID and Client Secret once, so copy both now.
- 4
Add ZITADEL as a provider in Casdoor
In the Casdoor console, open Providers, click Add, and fill in:
Category OAuth Type OIDC Display name ZITADEL Client ID <client ID> Client secret <client secret> Issuer URL https://zitadel.example.com Auth URL https://zitadel.example.com/oauth/v2/authorize Token URL https://zitadel.example.com/oauth/v2/token Scope openid profile email UserInfo URL https://zitadel.example.com/oidc/v1/userinfo Logout URL https://zitadel.example.com/oidc/v1/end_session Enable PKCE On Request next to Issuer URL fills in the other URLs from ZITADEL's discovery document. Casdoor links users of every OIDC-type provider in an organization through the same field, so if the organization already has one, set Type to Custom Flexible instead, which links accounts per provider.
- 5
Add the provider to an application
Open Applications, edit the application people sign in to, and add the provider on its Providers tab. Its sign-in page now has a ZITADEL button.
Good to know
- ZITADEL's
preferred_usernameis the login name, such asalice@acme.zitadel.cloud, and Casdoor uses it as the username of new users. Set a user mapping forusernamein Casdoor if you want something else. - ZITADEL only accepts plain-http redirect URIs in Development mode, so use https for Casdoor.
ZITADEL settings are from its documentation as of October 2026 (ZITADEL OIDC endpoints, ZITADEL claims, ZITADEL applications). ZITADEL is a trademark of its owner.
Frequently asked questions
Do I need User Info inside ID Token?
No. Casdoor also calls ZITADEL's userinfo endpoint, which returns the name and email.
Can I use the PKCE authentication method instead?
That method issues no client secret, while Casdoor's provider is a confidential client. Use Code; Casdoor sends a PKCE challenge on top of the secret anyway.
More identity providers
View allAuthelia
Identity providerLet people sign in to Casdoor through Authelia over OpenID Connect: the provider settings, and the client to add to Authelia's configuration.
authentik
Identity providerLet people sign in to Casdoor with their authentik accounts over OpenID Connect: the provider settings, and the application and OAuth2 provider to create in authentik.
GitLab Self-Managed
Identity providerLet people sign in to Casdoor with accounts on your own GitLab over OpenID Connect: the provider settings, and the OAuth application to create in GitLab.
