Skip to content

OIDC Single Sign-On

Let users sign in to Arcane through your OpenID Connect provider.

OIDC single sign-on lets users sign in to Arcane with an account from your identity provider (Authentik, Keycloak, Pocket ID, Azure AD, and so on) instead of a local password. From the provider you need a client ID, a client secret, and the issuer URL, and you need to register Arcane’s redirect URI, https://<your-arcane-url>/auth/oidc/callback.

  1. Go to Settings → Authentication.
  2. Enter your provider’s client ID, client secret, and issuer URL. The page shows the redirect URI to copy into your provider.
  3. Save and test the connection. The page points out any missing or invalid fields.

Arcane finds the provider’s endpoints from the issuer URL and its .well-known/openid-configuration page. The issuer URL must not end with a trailing slash.

Arcane creates an OIDC user the first time they sign in. You can disable local login if you want everyone to sign in through your provider.

Turn on Auto Redirect to Provider in Settings → Authentication (or set OIDC_AUTO_REDIRECT_TO_PROVIDER=true) to send users straight to your provider instead of showing Arcane’s login page.

If the provider is down or misconfigured, open https://<your-arcane-url>/login/backup. This backup login page never redirects, so you can still sign in with a local account or a passkey and fix the OIDC settings.

You can set the same options with environment variables instead of the UI:

services:
arcane:
environment:
- OIDC_ENABLED=true
- OIDC_CLIENT_ID=your_arcane_client_id_from_provider
- OIDC_CLIENT_SECRET=your_super_secret_client_secret_from_provider
- OIDC_ISSUER_URL=https://auth.example.com
- OIDC_SCOPES=openid email profile groups
- OIDC_GROUPS_CLAIM=groups

In list-form environment: entries, don’t wrap values in quotes. The quotes become part of the value.

Arcane can grant roles based on the groups in a user’s OIDC token. Add groups to the scopes, set the OIDC Groups Claim if your provider uses a different claim name, and add mappings in the UI or with OIDC_ROLE_MAPPINGS. See OIDC group mappings for the setup steps and the JSON format.

Variable Default Description
OIDC_ENABLED false Enable OIDC login.
OIDC_CLIENT_ID — Client ID from your OIDC provider.
OIDC_CLIENT_SECRET — Client secret from your OIDC provider.
OIDC_ISSUER_URL — Issuer URL of your OIDC provider, such as https://your-provider.com. No trailing slash.
OIDC_SCOPES openid email profile Scopes to request. Include the groups claim if you use OIDC group mappings.
OIDC_MERGE_ACCOUNTS false Link OIDC logins to existing local accounts based on email address.
OIDC_SKIP_TLS_VERIFY false Skip TLS verification for the OIDC provider. Use with caution.
OIDC_AUTO_REDIRECT_TO_PROVIDER false Automatically redirect users to the OIDC provider on login.
OIDC_PROVIDER_NAME — Provider display name shown on the login screen.
OIDC_PROVIDER_LOGO_URL — Provider logo URL shown on the login screen.
OIDC_ROLE_MAPPINGS — Declarative OIDC group→role mappings as a JSON array, for example [{"claimValue":"docker-admins","roleId":"role_admin"}]. Reconciled at every boot; rows are read-only in the UI. Set to [] to wipe env-managed mappings. Supports OIDC_ROLE_MAPPINGS_FILE for Docker secrets.

Use these if your OIDC provider does not support standard discovery via the Issuer URL.

Variable Description
OIDC_AUTHORIZATION_ENDPOINT Manual authorization URL, such as https://provider.com/auth.
OIDC_TOKEN_ENDPOINT Manual token URL, such as https://provider.com/token.
OIDC_USERINFO_ENDPOINT Manual userinfo URL, such as https://provider.com/userinfo.
OIDC_JWKS_ENDPOINT Manual JWKS URL for token verification, such as https://provider.com/jwks.
Type Value Description
Redirect URI {APP_URL}/auth/oidc/callback The URL to register with your OIDC provider