Chuyển tới nội dung chính

Connect an application to Casdoor

Your application signs users in with Casdoor through a standard protocol. This page helps you choose the protocol and the kind of client, and links to the guide for each choice.

Choose a protocol​

Casdoor is an identity provider (IdP) for the following protocols:

ProtocolUse it whenGuide
OAuth 2.0 and OpenID Connect (OIDC)You build a new application, or your application already supports OIDC. This is the recommended protocolOAuth 2.0
SAML 2.0Your application or a product that you bought supports only SAMLSAML
CAS 1.0, 2.0, and 3.0You connect an existing application that supports only CASCAS

Casdoor is also a service provider (SP): it lets users sign in with accounts from external identity providers over OAuth 2.0, OIDC, and SAML. See Providers.

OAuth 2.0 and OpenID Connect​

OAuth 2.0 is an authorization framework. It lets an application get limited access to a user's account at a service, without seeing the user's password. OpenID Connect adds an identity layer on top of OAuth 2.0: a standard way for the application to learn who the user is, and single sign-on (SSO) across applications.

The sign-in flow of Casdoor is the OAuth 2.0 authorization code flow, and Casdoor is a complete OIDC provider. Choose one of three kinds of client:

ClientUse it whenGuide
Standard OIDC client libraryYour language or framework has an OIDC library, or your application already uses another OIDC provider. Switching to Casdoor is then a change of the discovery URL and the credentialsStandard OIDC client
Casdoor SDKYou also want to call the Casdoor API from your application, for example to manage users or upload files. The SDKs build on OIDC and add these functionsCasdoor SDKs
Casdoor plugin or middlewareYour application runs on a platform that has one. This is the fastest way to add Casdoor to that platformCasdoor plugins

Plugins and middleware include:

SAML​

Security Assertion Markup Language (SAML) is an XML-based standard through which an IdP passes authentication and authorization information to an SP. It is common in enterprise SSO.

Casdoor is a SAML 2.0 IdP and supports the main features of SAML 2.0. See SAML. For an example, see Add Casdoor as a SAML IdP in Keycloak.

SAML is a large protocol with many optional parts. For a new application, OAuth 2.0 and OIDC are simpler. Choose SAML when you have to connect a system that supports only SAML.

CAS​

The Central Authentication Service (CAS) is a web SSO protocol. Applications authenticate users through the CAS server and never handle passwords.

Casdoor supports CAS 1.0, 2.0, and 3.0. See CAS.

CAS is lightweight but limited. The CAS client and the server establish trust through back-channel calls, not through cryptographic signatures. For a new application, prefer OAuth 2.0 and OIDC.

Step-by-step guides for specific applications​

To connect a specific product, such as GitLab, Grafana, or Jenkins, see Integrations.

See also​