0 Try the Demo

OIDC Single Sign-On

Let users sign in to Arcane through your OpenID Connect provider.

OIDC single sign-on lets users sign in to Arcane with an account from your identity provider (Authentik, Keycloak, Pocket ID, Azure AD, and so on) instead of a local password. From the provider you need a client ID, a client secret, and the issuer URL, and you need to register Arcane’s redirect URI, https://<your-arcane-url>/auth/oidc/callback.

Configure OIDC in the UI

  1. Go to Settings → Authentication.
  2. Enter your provider’s client ID, client secret, and issuer URL. The page shows the redirect URI to copy into your provider.
  3. Save and test the connection. The page points out any missing or invalid fields.

Arcane finds the provider’s endpoints from the issuer URL and its .well-known/openid-configuration page. The issuer URL must not end with a trailing slash.

Arcane creates an OIDC user the first time they sign in. You can disable local login if you want everyone to sign in through your provider.

Configure OIDC with Compose

You can set the same options with environment variables instead of the UI:

services:
  arcane:
    environment:
      - OIDC_ENABLED=true
      - OIDC_CLIENT_ID=your_arcane_client_id_from_provider
      - OIDC_CLIENT_SECRET=your_super_secret_client_secret_from_provider
      - OIDC_ISSUER_URL=https://auth.example.com
      - OIDC_SCOPES=openid email profile groups
      - OIDC_GROUPS_CLAIM=groups

In list-form environment: entries, don’t wrap values in quotes. The quotes become part of the value.

Map provider groups to roles

Arcane can grant roles based on the groups in a user’s OIDC token. Add groups to the scopes, set the OIDC Groups Claim if your provider uses a different claim name, and add mappings in the UI or with OIDC_ROLE_MAPPINGS. See OIDC group mappings for the setup steps and the JSON format.

Reference

Primary Configuration

Variable Description Value
OIDC_ENABLED Enable OIDC login
Default: false
OIDC_CLIENT_ID Client ID from your OIDC provider
Default: —
Example: your_arcane_client_id_from_provider
OIDC_CLIENT_SECRET Client Secret from provider
Default: —
Example: your_super_secret_client_secret_from_provider
OIDC_ISSUER_URL Issuer URL of your OIDC provider. No trailing slash.
Default: —
Example: https://your-provider.com
OIDC_SCOPES Scopes to request. Include the groups claim if you use OIDC group mappings.
Default: openid email profile
OIDC_MERGE_ACCOUNTS Link OIDC logins to existing local accounts based on email address
Default: false
OIDC_SKIP_TLS_VERIFY Skip TLS verification for the OIDC provider (use with caution)
Default: false
OIDC_AUTO_REDIRECT_TO_PROVIDER Automatically redirect users to the OIDC provider on login
Default: false
OIDC_PROVIDER_NAME Provider display name shown on the login screen
Default: —
OIDC_PROVIDER_LOGO_URL Provider logo URL shown on the login screen
Default: —
OIDC_ROLE_MAPPINGS Declarative OIDC group→role mappings as a JSON array. Reconciled at every boot; rows are read-only in the UI. Set to [] to wipe env-managed mappings. Supports OIDC_ROLE_MAPPINGS_FILE for Docker secrets.
Default: —
Example: [{"claimValue":"docker-admins","roleId":"role_admin"},{"claimValue":"devops","roleId":"role_editor","environmentId":"env-prod"}]

Manual Endpoint Overrides (Advanced)

Use these if your OIDC provider does not support standard discovery via the Issuer URL.

Variable Description Value
OIDC_AUTHORIZATION_ENDPOINT Override/Manual authorization URL (e.g., https://provider.com/auth)
Default: —
OIDC_TOKEN_ENDPOINT Override/Manual token URL (e.g., https://provider.com/token)
Default: —
OIDC_USERINFO_ENDPOINT Override/Manual userinfo URL (e.g., https://provider.com/userinfo)
Default: —
OIDC_JWKS_ENDPOINT Override/Manual JWKS URL for token verification (e.g., https://provider.com/jwks)
Default: —

Arcane Configuration Values

Type Value Description
Redirect URI {APP_URL}/auth/oidc/callback The URL to register with your OIDC provider