Skip to main content

Core concepts

Casdoor has four core objects: organizations, users, applications, and providers. An organization contains users and applications. Users sign in through an application. An application uses providers to offer sign-in methods and to send messages.

The examples on this page use the demo site https://door.casdoor.com.

Organization​

An organization is a container for users and applications. An organization typically stands for the employees of a company or the customers of a product. Several organizations can share one Casdoor instance, and each organization has its own users, applications, password rules, and branding.

PropertyDescription
ownerAlways admin for organizations
nameUnique name of the organization, for example built-in
displayNameName shown in the UI
websiteUrlWebsite of the organization
passwordTypeAlgorithm used to store the passwords of the organization's users
defaultAvatarAvatar given to new users
enableSoftDeletionMarks deleted users as deleted but keeps them in the database
accountItemsFields shown on the account page of a user, and who can view and edit them

For all settings of an organization, see Organizations.

User​

A user is an account that can sign in. Each user belongs to exactly one organization and can sign in to every application of that organization.

Casdoor has two kinds of users:

  • Users of the built-in organization, such as built-in/admin: Global administrators with full control over the Casdoor instance.
  • Users of other organizations, such as my-company/alice: Regular users who can sign up, sign in, sign out, and manage their own profile.

User IDs​

A user has two identifiers:

IdentifierExampleUse it for
<organization>/<username>built-in/adminCalls to the Casdoor API
idd835a48f-2e88-4c1f-b907-60ac6b6c1b40A stable user ID in your own application. It is a UUID
tip

If your application uses one organization only, you can use <username> alone as the user ID in your application.

User properties​

PropertyDescription
ownerName of the organization that the user belongs to
nameUsername, unique within the organization
idUUID of the user
displayNameName shown in the UI
avatarURL of the avatar image
email, phoneContact details, also used for verification codes
passwordPassword, stored in the form that the organization's passwordType defines
isAdminWhether the user is an administrator of the organization
isForbiddenWhether the user is blocked from signing in
isDeletedWhether the user is soft-deleted
signupApplicationApplication through which the user signed up
github, google, wechat, and so onID of the user at each linked identity provider
ldapID of the user in the LDAP directory that the user was synchronized from
propertiesKey-value map for your own attributes

Use properties for attributes that Casdoor has no field for. See Using the Properties field. For the full list of fields, see Users.

Application​

An application is a web service that signs users in with Casdoor, for example a forum, an internal office system, or a customer relationship management system. An application belongs to one organization and holds the settings for how users of that organization sign in to it.

PropertyDescription
ownerAlways admin for applications
nameUnique name of the application, for example app-built-in
organizationOrganization whose users can sign in to the application
clientId, clientSecretOAuth 2.0 credentials of the application
redirectUrisURLs that Casdoor may send users back to after sign-in
providersProviders that the application offers on its sign-in and sign-up pages
signupItemsFields of the sign-up page
enablePasswordWhether users can sign in with a password
enableSignUpWhether new users can sign up
tokenFormatFormat of the access tokens that Casdoor issues for the application
expireInHours, refreshExpireInHoursLifetime of access tokens and refresh tokens
certCertificate that signs the tokens

For all settings of an application, see Application configuration.

Sign-in and sign-up pages​

Users always sign in through an application. Each application has its own sign-in and sign-up pages. The root path /login is the sign-in page of app-built-in, the application that Casdoor creates for its own admin console.

ApplicationSign-up pageSign-in page
app-built-inhttps://door.casdoor.com/signuphttps://door.casdoor.com/login
app-casnodehttps://door.casdoor.com/signup/app-casnodehttps://door.casdoor.com/login/oauth/authorize?client_id=014ae4bd048734ca2dea&response_type=code&redirect_uri=http://localhost:9000/callback&scope=read&state=casdoor
app-casbin-oahttps://door.casdoor.com/signup/app-casbin-oahttps://door.casdoor.com/login/oauth/authorize?client_id=0ba528121ea87b3eb54d&response_type=code&redirect_uri=http://localhost:9000/callback&scope=read&state=casdoor

Sign-in and sign-up URLs​

To send users to the pages of your own application, build the URLs yourself or let an SDK build them.

Build the URLs yourself​

PageURL
Sign-up page of an application<casdoor-host>/signup/<application-name>
Sign-up page that continues with OAuth 2.0<casdoor-host>/signup/oauth/authorize?client_id=<client-id>&response_type=code&redirect_uri=<redirect-uri>&scope=read&state=<state>
Sign-in page of an organization<casdoor-host>/login/<organization-name>
Sign-in page that continues with OAuth 2.0<casdoor-host>/login/oauth/authorize?client_id=<client-id>&response_type=code&redirect_uri=<redirect-uri>&scope=read&state=<state>

Use a frontend SDK​

In React, Vue, and Angular applications, call getSignupUrl() and getSigninUrl() of casdoor-js-sdk.

Use a backend SDK​

In Go, Java, and other backends, call the equivalent functions of the SDK, for example GetSignupUrl() and GetSigninUrl() of casdoor-go-sdk.

Provider​

A provider connects Casdoor to an external service. Casdoor federates sign-in to external identity providers over OAuth 2.0, OpenID Connect (OIDC), and SAML. It also uses external services to send email and SMS, store files, show captchas, and take payments. Each of these connections is a provider.

You create a provider once and then add it to the applications that use it.

PropertyDescription
owneradmin for a provider that all organizations share, or the name of the organization that owns it
nameUnique name of the provider
categoryKind of provider, for example OAuth, SAML, Email, SMS, Storage, Captcha, or Payment
typeService behind the provider, for example GitHub, Google, or Twilio SMS
clientId, clientSecretCredentials that the external service issues to Casdoor
host, portServer address, for example of an SMTP server
endpoint, bucket, domainLocation settings of storage providers
metadata, issuerUrlSettings of SAML identity providers

For every provider category and type, see Providers.

Built-in objects​

Casdoor manages itself with the same four objects. On first start, it creates:

ObjectNamePurpose
Organizationbuilt-inHolds the administrators of the Casdoor instance
Userbuilt-in/adminFirst global administrator
Applicationapp-built-inThe Casdoor admin console itself

Every user of the built-in organization is a global administrator. To add administrators, create more users in built-in. To keep strangers from becoming administrators, turn off sign-up for app-built-in.

caution

You can't rename or delete the built-in organization, the built-in/admin user, or the app-built-in application in the admin console or through the API. Their names are hardcoded. Changing or removing them in the database can break Casdoor.

See also​