跳到主内容

Add Alipay as an OAuth provider

This guide explains how to let users sign in to Casdoor with their Alipay account. The Alipay provider signs its requests with certificates.


Learning outcomes​

  • Get the APPID and the certificates of an Alipay application.
  • Store the certificates in Casdoor.
  • Add Alipay as an OAuth provider in Casdoor.

What you need​


Get the APPID and the certificates​

  1. Create an application in the console of the Alipay Open Platform and note its APPID. See Find the APPID.
  2. Generate an RSA2 key pair as the Alipay documentation describes. 会得到 appPrivateKey.txt 和 appPublicKey.txt。
  3. Upload the application certificate in the Alipay application and download three files: alipayRootCert.crt, appCertPublicKey.crt, and alipayCertPublicKey.crt.
  4. Set the callback URL of the Alipay application to the callback URL of Casdoor, https://<your-casdoor-host>/callback. See Redirect URL and callback URL.

Store the certificates in Casdoor​

In the Casdoor admin console, open the Certs page and add two certificates.

The application certificate:

Casdoor fieldValue
Typex509
CertificateappCertPublicKey.crt 的内容
Private keyappPrivateKey.txt 的内容

The root certificate:

字段值
项目类型或类别x509
证书alipayCertPublicKey.crt 的内容
私钥alipayRootCert.crt 的内容

Add the provider in Casdoor​

  1. Go to Identity > Providers and add a provider.
  2. Set Category to OAuth and Type to Alipay.
  3. Enter the APPID as the Client ID, and select the application certificate and the root certificate that you created.
  4. Save the provider.

故障排除​

If the sign-in fails, for example with asn1: syntax error: sequence truncated, check the following:

  • In the application certificate, Certificate is appCertPublicKey.crt and Private key is appPrivateKey.txt.
  • In the root certificate, Certificate is alipayCertPublicKey.crt and Private key is alipayRootCert.crt.
  • The APPID belongs to the Alipay application.
  • The callback URL is set correctly in Alipay and in Casdoor.

See also​