Skip to main content

OAuth providers

An OAuth provider lets users sign in to Casdoor with an account at an external identity provider, such as Google, GitHub, or WeChat. The icon of the provider appears on the sign-in and sign-up pages of the applications that use it.

Supported providers​

ProviderLogoProviderLogoProviderLogoProviderLogo
ADFSAlipayAmazonApple
Auth0Azure ADAzure AD B2CBaidu
BilibiliBitbucketBoxCasdoor
Cloud FoundryDailymotionDeezerDigitalOcean
DingTalkDiscordTiktokDropbox
Eve OnlineFacebookFitbitGitea
GiteeGitHubGitLabGoogle
HerokuInfluxCloudInfoflowInstagram
IntercomKakaoLarkLastfm
LineLinkedInMailruMeetup
MicrosoftNaverNextcloudOkta
OneDriveOuraPatreonPayPal
QQSalesforceShopifySlack
SoundCloudSpotifySteamStrava
StripeTelegramTikTokTumblr
TwitchTwitterTypetalkUber
VKWeChatWeComWeibo
WePayXeroYahooYammer
YandexZoomEmailSMS
Battle.net

Each provider type has its own guide in this section. For a provider that isn't listed, use a custom OAuth provider.

Add an OAuth provider​

  1. At the identity provider, register an OAuth application:

    • Set its callback URL, which the provider may call the redirect URI, to the callback URL of Casdoor: https://<your-casdoor-host>/callback.
    • Choose the scopes, which determine the user data that Casdoor receives.
    • Copy the client ID and the client secret. Keep the client secret private.

    The callback URL at the provider is the URL of Casdoor, not the URL of your own application. See Redirect URL and callback URL.

  2. In the Casdoor admin console, go to Identity > Providers and add a provider.

  3. Set Category to OAuth and select the Type, such as Google or GitHub.

  4. Enter the Client ID and the Client secret from the identity provider.

  5. Save the provider.

Add the provider to an application​

  1. Open the edit page of the application and go to the Providers tab.
  2. Add the provider and choose whether users can sign up, sign in, and unlink with it. See Add providers to an application.
  3. Save the application.

How Casdoor links accounts​

When a user signs in with an OAuth provider, Casdoor looks for the Casdoor user to link the external account to. It matches by the identity at the provider, by email address or phone number if the Binding rule of the provider in the application allows it, and by username, without regard to case. You can therefore add an OAuth provider to an existing user base without linking accounts by hand.

Map additional user fields​

Casdoor reads the username, the email address, and the avatar from the provider. To fill in more fields, such as the phone number or the job title, map the claims of the provider to user fields. See Map OAuth claims to user fields.

Use the access token of the provider​

After an OAuth sign-in, Casdoor stores the access token of the provider on the user. Your application can read it from /api/get-account and call the API of the provider, such as the GitHub API or the Google Drive API, on behalf of the user. Only the user and the administrators of the organization can see the token. See Get the access token of an external provider.

Route requests through a proxy​

If the identity provider is reachable only through a proxy, turn on Enable proxy on the provider. Casdoor then sends the requests of the sign-in flow through the SOCKS5 proxy that socks5Proxy in conf/app.conf sets. Some provider types always use the proxy, whatever this setting.

See also​