OIDC Single Sign-On
Let users sign in to Arcane through your OpenID Connect provider.
OIDC single sign-on lets users sign in to Arcane with an account from your identity provider (Authentik, Keycloak, Pocket ID, Azure AD, and so on) instead of a local password. From the provider you need a client ID, a client secret, and the issuer URL, and you need to register Arcane’s redirect URI, https://<your-arcane-url>/auth/oidc/callback.
Configure OIDC in the UI
Section titled “Configure OIDC in the UI”- Go to Settings → Authentication.
- Enter your provider’s client ID, client secret, and issuer URL. The page shows the redirect URI to copy into your provider.
- Save and test the connection. The page points out any missing or invalid fields.
Arcane finds the provider’s endpoints from the issuer URL and its .well-known/openid-configuration page. The issuer URL must not end with a trailing slash.
Arcane creates an OIDC user the first time they sign in. You can disable local login if you want everyone to sign in through your provider.
Skip the login screen
Section titled “Skip the login screen”Turn on Auto Redirect to Provider in Settings → Authentication (or set OIDC_AUTO_REDIRECT_TO_PROVIDER=true) to send users straight to your provider instead of showing Arcane’s login page.
If the provider is down or misconfigured, open https://<your-arcane-url>/login/backup. This backup login page never redirects, so you can still sign in with a local account or a passkey and fix the OIDC settings.
Configure OIDC with Compose
Section titled “Configure OIDC with Compose”You can set the same options with environment variables instead of the UI:
services: arcane: environment: - OIDC_ENABLED=true - OIDC_CLIENT_ID=your_arcane_client_id_from_provider - OIDC_CLIENT_SECRET=your_super_secret_client_secret_from_provider - OIDC_ISSUER_URL=https://auth.example.com - OIDC_SCOPES=openid email profile groups - OIDC_GROUPS_CLAIM=groupsIn list-form environment: entries, don’t wrap values in quotes. The quotes become part of the value.
Map provider groups to roles
Section titled “Map provider groups to roles”Arcane can grant roles based on the groups in a user’s OIDC token. Add groups to the scopes, set the OIDC Groups Claim if your provider uses a different claim name, and add mappings in the UI or with OIDC_ROLE_MAPPINGS. See OIDC group mappings for the setup steps and the JSON format.
Reference
Section titled “Reference”Primary Configuration
Section titled “Primary Configuration”| Variable | Default | Description |
|---|---|---|
OIDC_ENABLED |
false |
Enable OIDC login. |
OIDC_CLIENT_ID |
— | Client ID from your OIDC provider. |
OIDC_CLIENT_SECRET |
— | Client secret from your OIDC provider. |
OIDC_ISSUER_URL |
— | Issuer URL of your OIDC provider, such as https://your-provider.com. No trailing slash. |
OIDC_SCOPES |
openid email profile |
Scopes to request. Include the groups claim if you use OIDC group mappings. |
OIDC_MERGE_ACCOUNTS |
false |
Link OIDC logins to existing local accounts based on email address. |
OIDC_SKIP_TLS_VERIFY |
false |
Skip TLS verification for the OIDC provider. Use with caution. |
OIDC_AUTO_REDIRECT_TO_PROVIDER |
false |
Automatically redirect users to the OIDC provider on login. |
OIDC_PROVIDER_NAME |
— | Provider display name shown on the login screen. |
OIDC_PROVIDER_LOGO_URL |
— | Provider logo URL shown on the login screen. |
OIDC_ROLE_MAPPINGS |
— | Declarative OIDC group→role mappings as a JSON array, for example [{"claimValue":"docker-admins","roleId":"role_admin"}]. Reconciled at every boot; rows are read-only in the UI. Set to [] to wipe env-managed mappings. Supports OIDC_ROLE_MAPPINGS_FILE for Docker secrets. |
Manual Endpoint Overrides (Advanced)
Section titled “Manual Endpoint Overrides (Advanced)”Use these if your OIDC provider does not support standard discovery via the Issuer URL.
| Variable | Description |
|---|---|
OIDC_AUTHORIZATION_ENDPOINT |
Manual authorization URL, such as https://provider.com/auth. |
OIDC_TOKEN_ENDPOINT |
Manual token URL, such as https://provider.com/token. |
OIDC_USERINFO_ENDPOINT |
Manual userinfo URL, such as https://provider.com/userinfo. |
OIDC_JWKS_ENDPOINT |
Manual JWKS URL for token verification, such as https://provider.com/jwks. |
Arcane Configuration Values
Section titled “Arcane Configuration Values”| Type | Value | Description |
|---|---|---|
| Redirect URI | {APP_URL}/auth/oidc/callback |
The URL to register with your OIDC provider |