跳到主内容

Application settings reference

This page describes every field of the application edit page in the Casdoor admin console. The page has eight tabs, and the fields are listed by tab, in the order of the page.

Basic​

Field描述
NameInternal application name.
Display nameName shown to users.
CategoryDefault (web apps) or Agent (M2M, e.g. MCP servers, API clients).
TypeFor Default: All, OIDC, OAuth, SAML, CAS. 对于 Agent:MCP、A2A。
Is sharedWhether the app is shared across organizations (global admin only).
LogoBranding image on the sign-in and sign-up pages (URL + preview).
TitlePage title shown on the sign-in and sign-up pages.
FaviconBrowser tab icon (URL + preview).
HomeApplication homepage URL.
DescriptionShort description of the application.
OrganizationOwning organization.
TagsOnly users with one of these tags can sign in. 查看应用标签。
OrderSort order in lists.
Menu modeLayout of the edit page navigation: Horizontal or Vertical.

身份验证​

FieldDescription
Cookie expireSession cookie lifetime in hours (default: 720). 不含 "Remember me", 该会话是 capped 在 24 h regardless。
Default groupGroup automatically assigned to new users signing up through this application, including both direct sign-up and OAuth-based registration. 提供商和邀请可覆盖此每注册设置:生效的组遵循优先级邀请 SignupGroup>提供商 SignupGroup>应用默认组。
Default tagTag automatically assigned to new users who sign up through this application.
Enable signupAllow new accounts: on the signup page, by magic link or verification code, and on the first sign-in with one of the application's providers (whose Can signup is on). 当关闭, 仅 admins 可创建 accounts。
Disable self signupShown when Enable signup is on. Users can no longer sign themselves up on the signup page, by magic link or by verification code, and the sign-in page hides the sign-up link. The signup page still works with an invitation code from an admin, and the first sign-in with a provider still creates the account. Use it to close public signup while keeping just-in-time accounts for SSO, e.g. new employees signing in with Lark or DingTalk for the first time.
Disable signinDisable all sign-in for this application.
Enable guest signinAllow unauthenticated guest access by presenting code=guest-user to the token endpoint. 需要 启用注册 以被开启作为 well。不适用于内置组织。请参阅访客身份验证。
Enable exclusive signinEnforce one active session per user.
Signin sessionEnable persistent sign-in session across browser restarts.
Auto signinAutomatically sign the user back in on revisit. 需要 登录会话 以被已启用第一。
Enable Email linkingAllow linking OAuth accounts to existing accounts by matching email.
Signup URLExternal sign-up URL, replaces Casdoor's built-in sign-up page.
Signin URLExternal sign-in URL, replaces Casdoor's built-in sign-in page.
Forget URLCustom password recovery URL.
Affiliation URLAffiliation or invitation URL.

OIDC/OAuth​

FieldDescription
Client IDOAuth 2.0 client identifier.
Client secretOAuth 2.0 client secret.
Redirect URLsAllowed redirect URLs after sign-in. 匹配基于 URL:方案、端口和路径必须完全匹配,主机可以是配置的主机,也可以是该主机的任何子域名(例如,配置https://example.com/callback也允许https://api.example.com/callback)。无效的 URL 条目将作为锚定正则表达式进行匹配。
Forced redirect originWhen set, Casdoor forces all redirects to this origin.
Grant typesEnabled OAuth grant types: Authorization Code, Password, Client Credentials, Token, ID Token, Refresh Token, Device Code, Token Exchange, JWT Bearer.
ScopesCustom scopes for Agent-category apps (name, display name, description); exposed in OIDC discovery.
Token formatJWT, JWT-Empty, JWT-Custom, or JWT-Standard. 请参阅令牌概览。
Token signing methodSigning algorithm: RS256, RS512, ES256, ES384, or ES512.
Token fieldsUser fields included in the token payload (available when format is JWT-Custom). 这个列表同时也是 /userinfo 接口的白名单:非空时只返回列出的字段。留空则包含全部字段。请参阅令牌概览。
Token attributesCustom claims added to the token (available when format is JWT-Custom). Each row has a Category, Value, and Type. See Token attributes
Token expireAccess token lifetime in hours.
Refresh token expireRefresh token lifetime in hours.

Token attributes​

Each row of Token attributes adds a custom claim to the token and has a Category, a Value, and a Type:

CategoryValueResult
Static ValueA template string. It supports ${user.xxx} substitutionType sets whether the claim is a String or an Array
Existing FieldA user field from the list, such as Owner, Name, Id, DisplayName, Email, Phone, Tag, Roles, Permissions, or Groups. Reference a key of the properties map as Properties.<key>Casdoor reads the field from the user when it issues the token

SAML​

FieldDescription
SAML reply URLAssertion Consumer Service (ACS) URL where Casdoor posts the SAML response.
Enable SAML compressionCompress SAML requests and responses.
Enable SAML C14N10Use C14N 1.0 canonicalization when signing SAML documents.
SAML C14N prefixNamespace prefix list used for the C14N 1.0 canonicalization (applies when Enable SAML C14N10 is on; default xs).
Use Email as NameIDUse the user's email address as the SAML NameID instead of username.
Enable SAML POST bindingUse HTTP POST binding instead of Redirect binding.
SAML hash algorithmSignature hash algorithm: SHA1, SHA256, or SHA512.
Disable SAML attributesSend only NameID in the assertion, omit all other user attributes.
Enable SAML assertion signatureSign the assertion element in addition to the response envelope.
SAML attributesCustom attribute statements included in the SAML assertion (available when Disable SAML attributes is off).
SAML metadataRead-only XML metadata for this application; includes a button to copy the metadata URL.

提供商​

FieldDescription
ProvidersOAuth, email, SMS, storage, and other providers attached to this application. 控制可用的登录方式和集成。

Each OAuth, Web3, and SAML provider in the Providers table has the following settings:

列Description
可注册允许新用户通过此提供商注册。
可登录可取消关联
可取消关联允许用户从其账户中取消链接此提供商。
绑定规则用于将OAuth身份与现有Casdoor用户匹配的字段。可用字段:电子邮件, 电话, 姓名。已检查订单——首个匹配项会关联账户。默认为 Email、Phone、Name。仅适用于OAuth、Web3和SAML提供商。
国家代码将基于电话的提供商限制在特定国家/地区呼叫代码范围内。
已提示如果用户尚未绑定此提供商,注册后显示提示,要求用户进行绑定。
注册组覆盖通过此提供商注册的用户的应用程序默认组。

UI Customization​

FieldDescription
Org choice modeHow users select their organization at sign-in: None, Select (dropdown), or Input (text field).
Signin methodsOrdered list of sign-in methods shown on the sign-in page (e.g. Password, Verification code, WebAuthn).
Signup HTMLCustom HTML injected into the sign-up page. 嵌入的 <script> 标签会被执行,所以只能使用可信的内容。
Signin HTMLCustom HTML injected into the sign-in page. 嵌入的 <script> 标签会被执行,所以只能使用可信的内容。
Page HTMLCustom HTML injected into the page <head> (e.g. meta tags, analytics snippets, or custom styles/scripts) for all of the application's pages.
Signin itemsConfigure which fields and controls appear on the sign-in form.
Signup itemsConfigure the registration form fields (visible only when Enable signup is on).
Background URLDesktop sign-in page background image (URL + preview).
Background URL MobileMobile sign-in page background image (URL + preview).
Custom CSSCSS applied to the sign-in form (desktop).
Custom CSS MobileCSS applied to the sign-in form (mobile).
Form positionHorizontal alignment of the sign-in form: Left, Center, Right, or Enable side panel.
Side panel HTMLHTML shown in the panel beside the sign-in form (visible when Form position is set to Enable side panel).
ThemeUse the organization theme or define a custom color/border-radius for this application.
Header HTMLCustom HTML rendered above the sign-in and sign-up forms.
Footer HTMLCustom HTML rendered below the sign-in and sign-up forms.

安全​

FieldDescription
Token certCertificate used to sign tokens issued by this application.
Client certCertificate used to verify client identity. 对于双向TLS,它会验证客户端连接;对于JWT持有者授权(RFC 7523),此证书中的公钥用于验证客户端JWT断言的签名。
Failed signin limitNumber of consecutive failed sign-in attempts before the account is locked. 该限制同样适用于 /api/verify-code OTP 接口:输错验证码次数过多时,会用同一个计数器和冻结时间,暂时封禁该“用户 + 目标地址”组合。
Failed signin frozen timeLock duration in minutes after hitting the failed sign-in limit.
Code resend timeoutSeconds a user must wait before requesting another verification code (default: 60; set to 0 for the global default).
IP whitelistComma-separated list of allowed IP addresses or CIDR ranges. 覆盖组织级允许列表。查看IP允许列表。
Terms of UseURL or path to the terms-of-use page (up to 200 characters). 可直接上传 HTML 文件,生成的 URL 将自动填充。

反向代理​

FieldDescription
DomainPrimary domain this application is served on (e.g. blog.example.com).
Other domainsAdditional domains that should route to this application.
Upstream hostThe backend service address Casdoor proxies requests to (e.g. localhost:8080).
SSL modeTLS handling: None, HTTP, HTTPS and HTTP, or HTTPS Only.
SSL certCertificate used for HTTPS when acting as a reverse proxy.

See also​