OIDC Single Sign-On
Let users sign in to Arcane through your OpenID Connect provider.
OIDC single sign-on lets users sign in to Arcane with an account from your identity provider (Authentik, Keycloak, Pocket ID, Azure AD, and so on) instead of a local password. From the provider you need a client ID, a client secret, and the issuer URL, and you need to register Arcane’s redirect URI, https://<your-arcane-url>/auth/oidc/callback.
Configure OIDC in the UI
- Go to Settings → Authentication.
- Enter your provider’s client ID, client secret, and issuer URL. The page shows the redirect URI to copy into your provider.
- Save and test the connection. The page points out any missing or invalid fields.
Arcane finds the provider’s endpoints from the issuer URL and its .well-known/openid-configuration page. The issuer URL must not end with a trailing slash.
Arcane creates an OIDC user the first time they sign in. You can disable local login if you want everyone to sign in through your provider.
Configure OIDC with Compose
You can set the same options with environment variables instead of the UI:
services:
arcane:
environment:
- OIDC_ENABLED=true
- OIDC_CLIENT_ID=your_arcane_client_id_from_provider
- OIDC_CLIENT_SECRET=your_super_secret_client_secret_from_provider
- OIDC_ISSUER_URL=https://auth.example.com
- OIDC_SCOPES=openid email profile groups
- OIDC_GROUPS_CLAIM=groupsIn list-form environment: entries, don’t wrap values in quotes. The quotes become part of the value.
Map provider groups to roles
Arcane can grant roles based on the groups in a user’s OIDC token. Add groups to the scopes, set the OIDC Groups Claim if your provider uses a different claim name, and add mappings in the UI or with OIDC_ROLE_MAPPINGS. See OIDC group mappings for the setup steps and the JSON format.
Reference
Primary Configuration
| Variable | Description | Value |
|---|---|---|
OIDC_ENABLED | Enable OIDC login | Default: false |
OIDC_CLIENT_ID | Client ID from your OIDC provider | Default: —Example: your_arcane_client_id_from_provider |
OIDC_CLIENT_SECRET | Client Secret from provider | Default: —Example: your_super_secret_client_secret_from_provider |
OIDC_ISSUER_URL | Issuer URL of your OIDC provider. No trailing slash. | Default: —Example: https://your-provider.com |
OIDC_SCOPES | Scopes to request. Include the groups claim if you use OIDC group mappings. | Default: openid email profile |
OIDC_MERGE_ACCOUNTS | Link OIDC logins to existing local accounts based on email address | Default: false |
OIDC_SKIP_TLS_VERIFY | Skip TLS verification for the OIDC provider (use with caution) | Default: false |
OIDC_AUTO_REDIRECT_TO_PROVIDER | Automatically redirect users to the OIDC provider on login | Default: false |
OIDC_PROVIDER_NAME | Provider display name shown on the login screen | Default: — |
OIDC_PROVIDER_LOGO_URL | Provider logo URL shown on the login screen | Default: — |
OIDC_ROLE_MAPPINGS | Declarative OIDC group→role mappings as a JSON array. Reconciled at every boot; rows are read-only in the UI. Set to [] to wipe env-managed mappings. Supports OIDC_ROLE_MAPPINGS_FILE for Docker secrets. | Default: —Example: [{"claimValue":"docker-admins","roleId":"role_admin"},{"claimValue":"devops","roleId":"role_editor","environmentId":"env-prod"}] |
Manual Endpoint Overrides (Advanced)
Use these if your OIDC provider does not support standard discovery via the Issuer URL.
| Variable | Description | Value |
|---|---|---|
OIDC_AUTHORIZATION_ENDPOINT | Override/Manual authorization URL (e.g., https://provider.com/auth) | Default: — |
OIDC_TOKEN_ENDPOINT | Override/Manual token URL (e.g., https://provider.com/token) | Default: — |
OIDC_USERINFO_ENDPOINT | Override/Manual userinfo URL (e.g., https://provider.com/userinfo) | Default: — |
OIDC_JWKS_ENDPOINT | Override/Manual JWKS URL for token verification (e.g., https://provider.com/jwks) | Default: — |
Arcane Configuration Values
| Type | Value | Description |
|---|---|---|
| Redirect URI | {APP_URL}/auth/oidc/callback | The URL to register with your OIDC provider |