Pular para o conteúdo principal

Application settings reference

This page describes every field of the application edit page in the Casdoor admin console. The page has eight tabs, and the fields are listed by tab, in the order of the page.

Básico​

FieldDescrição
NameInternal application name.
Display nameName shown to users.
CategoryDefault (web apps) or Agent (M2M, e.g. MCP servers, API clients).
TypeFor Default: All, OIDC, OAuth, SAML, CAS. For Agent: MCP, A2A.
Is sharedWhether the app is shared across organizations (global admin only).
LogoBranding image on the sign-in and sign-up pages (URL + preview).
TitlePage title shown on the sign-in and sign-up pages.
FaviconBrowser tab icon (URL + preview).
HomeApplication homepage URL.
DescriptionShort description of the application.
OrganizationOwning organization.
TagsOnly users with one of these tags can sign in. See Application Tags.
OrderSort order in lists.
Menu modeLayout of the edit page navigation: Horizontal or Vertical.

Autenticação​

FieldDescription
Cookie expireSession cookie lifetime in hours (default: 720). Without "Remember me", the session is capped at 24 h regardless.
Default groupGroup automatically assigned to new users signing up through this application, including both direct sign-up and OAuth-based registration. Providers and invitations can override this per-signup: the effective group follows the priority invitation SignupGroup > provider SignupGroup > application Default group.
Default tagTag automatically assigned to new users who sign up through this application.
Enable signupAllow new accounts: on the signup page, by magic link or verification code, and on the first sign-in with one of the application's providers (whose Can signup is on). When off, only admins can create accounts.
Disable self signupShown when Enable signup is on. Users can no longer sign themselves up on the signup page, by magic link or by verification code, and the sign-in page hides the sign-up link. The signup page still works with an invitation code from an admin, and the first sign-in with a provider still creates the account. Use it to close public signup while keeping just-in-time accounts for SSO, e.g. new employees signing in with Lark or DingTalk for the first time.
Disable signinDisable all sign-in for this application.
Enable guest signinAllow unauthenticated guest access by presenting code=guest-user to the token endpoint. Requires Enable signup to be on as well. Not available for the built-in organization. See Guest authentication.
Enable exclusive signinEnforce one active session per user.
Signin sessionEnable persistent sign-in session across browser restarts.
Auto signinAutomatically sign the user back in on revisit. Requires Signin session to be enabled first.
Enable Email linkingAllow linking OAuth accounts to existing accounts by matching email.
Signup URLExternal sign-up URL, replaces Casdoor's built-in sign-up page.
Signin URLExternal sign-in URL, replaces Casdoor's built-in sign-in page.
Forget URLCustom password recovery URL.
Affiliation URLAffiliation or invitation URL.

OIDC/OAuth​

FieldDescription
Client IDOAuth 2.0 client identifier.
Client secretOAuth 2.0 client secret.
Redirect URLsAllowed redirect URLs after sign-in. Matching is URL-based: scheme, port, and path must match exactly, and the host may be the configured host or any subdomain of it (e.g. configuring https://example.com/callback also allows https://api.example.com/callback). Entries that are not valid URLs are matched as anchored regular expressions.
Forced redirect originWhen set, Casdoor forces all redirects to this origin.
Grant typesEnabled OAuth grant types: Authorization Code, Password, Client Credentials, Token, ID Token, Refresh Token, Device Code, Token Exchange, JWT Bearer.
ScopesCustom scopes for Agent-category apps (name, display name, description); exposed in OIDC discovery.
Token formatJWT, JWT-Empty, JWT-Custom, or JWT-Standard. See Token overview.
Token signing methodSigning algorithm: RS256, RS512, ES256, ES384, or ES512.
Token fieldsUser fields included in the token payload (available when format is JWT-Custom). This list also acts as a whitelist for the /userinfo endpoint: when non-empty, only the listed fields are returned. Leave empty to include the full set. See Token overview.
Token attributesCustom claims added to the token (available when format is JWT-Custom). Each row has a Category, Value, and Type. See Token attributes
Token expireAccess token lifetime in hours.
Refresh token expireRefresh token lifetime in hours.

Token attributes​

Each row of Token attributes adds a custom claim to the token and has a Category, a Value, and a Type:

CategoryValueResult
Static ValueA template string. It supports ${user.xxx} substitutionType sets whether the claim is a String or an Array
Existing FieldA user field from the list, such as Owner, Name, Id, DisplayName, Email, Phone, Tag, Roles, Permissions, or Groups. Reference a key of the properties map as Properties.<key>Casdoor reads the field from the user when it issues the token

SAML​

FieldDescription
SAML reply URLAssertion Consumer Service (ACS) URL where Casdoor posts the SAML response.
Enable SAML compressionCompress SAML requests and responses.
Enable SAML C14N10Use C14N 1.0 canonicalization when signing SAML documents.
SAML C14N prefixNamespace prefix list used for the C14N 1.0 canonicalization (applies when Enable SAML C14N10 is on; default xs).
Use Email as NameIDUse the user's email address as the SAML NameID instead of username.
Enable SAML POST bindingUse HTTP POST binding instead of Redirect binding.
SAML hash algorithmSignature hash algorithm: SHA1, SHA256, or SHA512.
Disable SAML attributesSend only NameID in the assertion, omit all other user attributes.
Enable SAML assertion signatureSign the assertion element in addition to the response envelope.
SAML attributesCustom attribute statements included in the SAML assertion (available when Disable SAML attributes is off).
SAML metadataRead-only XML metadata for this application; includes a button to copy the metadata URL.

Fornecedores​

FieldDescription
ProvidersOAuth, email, SMS, storage, and other providers attached to this application. Controls which sign-in methods and integrations are available.

Each OAuth, Web3, and SAML provider in the Providers table has the following settings:

ColumnDescription
Can sign upAllow new users to register via this provider.
Can sign inAllow existing users to sign in via this provider.
Pode desvincularAllow users to unlink this provider from their account.
Regra de ligaçãoFields used to match an OAuth identity to an existing Casdoor user. Available fields: Email, Phone, Name. Checked in order — the first match links the accounts. Default is Email, Phone, Name. Only applies to OAuth, Web3, and SAML providers.
Country codesRestrict phone-based providers to specific country calling codes.
SolicitadoShow a prompt asking users to bind this provider after sign-up if they haven't already.
Grupo de cadastroOverride the application's Default group for users who sign up via this provider.

Personalização da interface​

FieldDescription
Org choice modeHow users select their organization at sign-in: None, Select (dropdown), or Input (text field).
Signin methodsOrdered list of sign-in methods shown on the sign-in page (e.g. Password, Verification code, WebAuthn).
Signup HTMLCustom HTML injected into the sign-up page. Embedded <script> tags are executed, so only use trusted content.
Signin HTMLCustom HTML injected into the sign-in page. Embedded <script> tags are executed, so only use trusted content.
Page HTMLCustom HTML injected into the page <head> (e.g. meta tags, analytics snippets, or custom styles/scripts) for all of the application's pages.
Signin itemsConfigure which fields and controls appear on the sign-in form.
Signup itemsConfigure the registration form fields (visible only when Enable signup is on).
Background URLDesktop sign-in page background image (URL + preview).
Background URL MobileMobile sign-in page background image (URL + preview).
Custom CSSCSS applied to the sign-in form (desktop).
Custom CSS MobileCSS applied to the sign-in form (mobile).
Form positionHorizontal alignment of the sign-in form: Left, Center, Right, or Enable side panel.
Side panel HTMLHTML shown in the panel beside the sign-in form (visible when Form position is set to Enable side panel).
ThemeUse the organization theme or define a custom color/border-radius for this application.
Header HTMLCustom HTML rendered above the sign-in and sign-up forms.
Footer HTMLCustom HTML rendered below the sign-in and sign-up forms.

Segurança​

FieldDescription
Token certCertificate used to sign tokens issued by this application.
Client certCertificate used to verify client identity. For mutual TLS it authenticates the client connection; for the JWT Bearer grant (RFC 7523), the public key in this certificate is used to verify the client's JWT assertion signature.
Failed signin limitNumber of consecutive failed sign-in attempts before the account is locked. This limit also applies to the /api/verify-code OTP endpoint: too many wrong verification codes will temporarily block that user+destination combination using the same counter and freeze time.
Failed signin frozen timeLock duration in minutes after hitting the failed sign-in limit.
Code resend timeoutSeconds a user must wait before requesting another verification code (default: 60; set to 0 for the global default).
IP whitelistComma-separated list of allowed IP addresses or CIDR ranges. Overrides the organization-level whitelist. See IP allowlist.
Terms of UseURL or path to the terms-of-use page (up to 200 characters). An HTML file can be uploaded directly and the resulting URL is filled in automatically.

Proxy reverso​

FieldDescription
DomainPrimary domain this application is served on (e.g. blog.example.com).
Other domainsAdditional domains that should route to this application.
Upstream hostThe backend service address Casdoor proxies requests to (e.g. localhost:8080).
SSL modeTLS handling: None, HTTP, HTTPS and HTTP, or HTTPS Only.
SSL certCertificate used for HTTPS when acting as a reverse proxy.

See also​