Application settings reference
This page describes every field of the application edit page in the Casdoor admin console. The page has eight tabs, and the fields are listed by tab, in the order of the page.
Basic
| Field | 描述 |
|---|---|
| Name | Internal application name. |
| Display name | Name shown to users. |
| Category | Default (web apps) or Agent (M2M, e.g. MCP servers, API clients). |
| Type | For Default: All, OIDC, OAuth, SAML, CAS. 对于 Agent:MCP、A2A。 |
| Is shared | Whether the app is shared across organizations (global admin only). |
| Logo | Branding image on the sign-in and sign-up pages (URL + preview). |
| Title | Page title shown on the sign-in and sign-up pages. |
| Favicon | Browser tab icon (URL + preview). |
| Home | Application homepage URL. |
| Description | Short description of the application. |
| Organization | Owning organization. |
| Tags | Only users with one of these tags can sign in. 查看应用标签。 |
| Order | Sort order in lists. |
| Menu mode | Layout of the edit page navigation: Horizontal or Vertical. |
身份验证
| Field | Description |
|---|---|
| Cookie expire | Session cookie lifetime in hours (default: 720). 不含 "Remember me", 该会话是 capped 在 24 h regardless。 |
| Default group | Group automatically assigned to new users signing up through this application, including both direct sign-up and OAuth-based registration. 提供商和邀请可覆盖此每注册设置:生效的组遵循优先级邀请 SignupGroup>提供商 SignupGroup>应用默认组。 |
| Default tag | Tag automatically assigned to new users who sign up through this application. |
| Enable signup | Allow new accounts: on the signup page, by magic link or verification code, and on the first sign-in with one of the application's providers (whose Can signup is on). 当关闭, 仅 admins 可创建 accounts。 |
| Disable self signup | Shown when Enable signup is on. Users can no longer sign themselves up on the signup page, by magic link or by verification code, and the sign-in page hides the sign-up link. The signup page still works with an invitation code from an admin, and the first sign-in with a provider still creates the account. Use it to close public signup while keeping just-in-time accounts for SSO, e.g. new employees signing in with Lark or DingTalk for the first time. |
| Disable signin | Disable all sign-in for this application. |
| Enable guest signin | Allow unauthenticated guest access by presenting code=guest-user to the token endpoint. 需要 启用注册 以被开启作为 well。不适用于内置组织。请参阅访客身份验证。 |
| Enable exclusive signin | Enforce one active session per user. |
| Signin session | Enable persistent sign-in session across browser restarts. |
| Auto signin | Automatically sign the user back in on revisit. 需要 登录会话 以被已启用第一。 |
| Enable Email linking | Allow linking OAuth accounts to existing accounts by matching email. |
| Signup URL | External sign-up URL, replaces Casdoor's built-in sign-up page. |
| Signin URL | External sign-in URL, replaces Casdoor's built-in sign-in page. |
| Forget URL | Custom password recovery URL. |
| Affiliation URL | Affiliation or invitation URL. |
OIDC/OAuth
| Field | Description |
|---|---|
| Client ID | OAuth 2.0 client identifier. |
| Client secret | OAuth 2.0 client secret. |
| Redirect URLs | Allowed redirect URLs after sign-in. 匹配基于 URL:方案、端口和路径必须完全匹配,主机可以是配置的主机,也可以是该主机的任何子域名(例如,配置https://example.com/callback也允许https://api.example.com/callback)。无效的 URL 条目将作为锚定正则表达式进行匹配。 |
| Forced redirect origin | When set, Casdoor forces all redirects to this origin. |
| Grant types | Enabled OAuth grant types: Authorization Code, Password, Client Credentials, Token, ID Token, Refresh Token, Device Code, Token Exchange, JWT Bearer. |
| Scopes | Custom scopes for Agent-category apps (name, display name, description); exposed in OIDC discovery. |
| Token format | JWT, JWT-Empty, JWT-Custom, or JWT-Standard. 请参阅令牌概览。 |
| Token signing method | Signing algorithm: RS256, RS512, ES256, ES384, or ES512. |
| Token fields | User fields included in the token payload (available when format is JWT-Custom). 这个列表同时也是 /userinfo 接口的白名单:非空时只返回列出的字段。留空则包含全部字段。请参阅令牌概览。 |
| Token attributes | Custom claims added to the token (available when format is JWT-Custom). Each row has a Category, Value, and Type. See Token attributes |
| Token expire | Access token lifetime in hours. |
| Refresh token expire | Refresh token lifetime in hours. |
Token attributes
Each row of Token attributes adds a custom claim to the token and has a Category, a Value, and a Type:
| Category | Value | Result |
|---|---|---|
Static Value | A template string. It supports ${user.xxx} substitution | Type sets whether the claim is a String or an Array |
Existing Field | A user field from the list, such as Owner, Name, Id, DisplayName, Email, Phone, Tag, Roles, Permissions, or Groups. Reference a key of the properties map as Properties.<key> | Casdoor reads the field from the user when it issues the token |
SAML
| Field | Description |
|---|---|
| SAML reply URL | Assertion Consumer Service (ACS) URL where Casdoor posts the SAML response. |
| Enable SAML compression | Compress SAML requests and responses. |
| Enable SAML C14N10 | Use C14N 1.0 canonicalization when signing SAML documents. |
| SAML C14N prefix | Namespace prefix list used for the C14N 1.0 canonicalization (applies when Enable SAML C14N10 is on; default xs). |
| Use Email as NameID | Use the user's email address as the SAML NameID instead of username. |
| Enable SAML POST binding | Use HTTP POST binding instead of Redirect binding. |
| SAML hash algorithm | Signature hash algorithm: SHA1, SHA256, or SHA512. |
| Disable SAML attributes | Send only NameID in the assertion, omit all other user attributes. |
| Enable SAML assertion signature | Sign the assertion element in addition to the response envelope. |
| SAML attributes | Custom attribute statements included in the SAML assertion (available when Disable SAML attributes is off). |
| SAML metadata | Read-only XML metadata for this application; includes a button to copy the metadata URL. |
提 供商
| Field | Description |
|---|---|
| Providers | OAuth, email, SMS, storage, and other providers attached to this application. 控制可用的登录方式和集成。 |
Each OAuth, Web3, and SAML provider in the Providers table has the following settings:
| 列 | Description |
|---|---|
| 可注册 | 允许新用户通过此提供商注册。 |
| 可登录 | 可取消关联 |
| 可取消关联 | 允许用户从其账户中取消链接此提供商。 |
| 绑定规则 | 用于将OAuth身份与现有Casdoor用户匹配的字段。可用字段:电子邮件, 电话, 姓名。已检查订单——首个匹配项会关联账户。默认为 Email、Phone、Name。仅适用于OAuth、Web3和SAML提供商。 |
| 国家代码 | 将基于电话的提供商限制在特定国家/地区呼叫代码范围内。 |
| 已提示 | 如果用户尚未绑定此提供商,注册后显示提示,要求用户进行绑定。 |
| 注册组 | 覆盖通过此提供商注册的用户的应用程序默认组。 |
UI Customization
| Field | Description |
|---|---|
| Org choice mode | How users select their organization at sign-in: None, Select (dropdown), or Input (text field). |
| Signin methods | Ordered list of sign-in methods shown on the sign-in page (e.g. Password, Verification code, WebAuthn). |
| Signup HTML | Custom HTML injected into the sign-up page. 嵌入的 <script> 标签会被执行,所以只能使用可信的内容。 |
| Signin HTML | Custom HTML injected into the sign-in page. 嵌入的 <script> 标签会被执行,所以只能使用可信的内容。 |
| Page HTML | Custom HTML injected into the page <head> (e.g. meta tags, analytics snippets, or custom styles/scripts) for all of the application's pages. |
| Signin items | Configure which fields and controls appear on the sign-in form. |
| Signup items | Configure the registration form fields (visible only when Enable signup is on). |
| Background URL | Desktop sign-in page background image (URL + preview). |
| Background URL Mobile | Mobile sign-in page background image (URL + preview). |
| Custom CSS | CSS applied to the sign-in form (desktop). |
| Custom CSS Mobile | CSS applied to the sign-in form (mobile). |
| Form position | Horizontal alignment of the sign-in form: Left, Center, Right, or Enable side panel. |
| Side panel HTML | HTML shown in the panel beside the sign-in form (visible when Form position is set to Enable side panel). |
| Theme | Use the organization theme or define a custom color/border-radius for this application. |
| Header HTML | Custom HTML rendered above the sign-in and sign-up forms. |
| Footer HTML | Custom HTML rendered below the sign-in and sign-up forms. |
安全
| Field | Description |
|---|---|
| Token cert | Certificate used to sign tokens issued by this application. |
| Client cert | Certificate used to verify client identity. 对于双向TLS,它会验证客户端连接;对于JWT持有者授权(RFC 7523),此证书中的公钥用于验证客户端JWT断言的签名。 |
| Failed signin limit | Number of consecutive failed sign-in attempts before the account is locked. 该限制同样适用于 /api/verify-code OTP 接口:输错验证码次数过多时,会用同一个计数器和冻结时间,暂时封禁该“用户 + 目标地址”组合。 |
| Failed signin frozen time | Lock duration in minutes after hitting the failed sign-in limit. |
| Code resend timeout | Seconds a user must wait before requesting another verification code (default: 60; set to 0 for the global default). |
| IP whitelist | Comma-separated list of allowed IP addresses or CIDR ranges. 覆盖组织级允许列表。查看IP允许列表。 |
| Terms of Use | URL or path to the terms-of-use page (up to 200 characters). 可直接上传 HTML 文件,生成的 URL 将自动填充。 |
反向代理
| Field | Description |
|---|---|
| Domain | Primary domain this application is served on (e.g. blog.example.com). |
| Other domains | Additional domains that should route to this application. |
| Upstream host | The backend service address Casdoor proxies requests to (e.g. localhost:8080). |
| SSL mode | TLS handling: None, HTTP, HTTPS and HTTP, or HTTPS Only. |
| SSL cert | Certificate used for HTTPS when acting as a reverse proxy. |