OIDC SSO
Configure an OpenID Connect provider connection and identity resolver.
OIDC SSO lets an organization authenticate through an OpenID Connect provider. Before configuring this page, decide how your application stores organization connections and maps a verified provider subject to an Authlier subject ID. The Single sign-on overview explains that boundary.
OIDC is available with cookie sessions in this release.
Register the callback
Register this callback URL with the identity provider:
https://server.example.com/api/auth/sso/oidc/callbackUse the Go server's public origin and Authlier BasePath. Each organization
connection supplies its issuer, server-side client credentials, callback URL,
and scopes.
Provide a connection source
Authlier asks the source for a trusted connection after the client submits a connection ID:
type oidcConnections struct {
connections map[string]oidc.Connection
}
func (source oidcConnections) Find(
ctx context.Context,
connectionID string,
) (oidc.Connection, error) {
connection, ok := source.connections[connectionID]
if !ok {
return oidc.Connection{}, oidc.ErrNotFound
}
return connection, nil
}connections := oidcConnections{connections: map[string]oidc.Connection{
"acme": {
ID: "acme",
Issuer: "https://idp.example.com",
ClientID: os.Getenv("ACME_OIDC_CLIENT_ID"),
ClientSecret: os.Getenv("ACME_OIDC_CLIENT_SECRET"),
RedirectURL: "https://server.example.com/api/auth/sso/oidc/callback",
Scopes: []string{"openid", "profile", "email"},
RequireVerifiedEmail: true,
},
}}Map the verified identity
Connect the source and resolve the verified provider subject:
OIDC: authlier.OIDCConfig{
Enabled: true,
Connections: connections,
ResolveIdentity: func(ctx context.Context, identity oidc.Identity) (string, error) {
return ssoMappings.FindSubject(
ctx,
identity.ConnectionID,
identity.ProviderSubject,
)
},
SuccessRedirectURL: "https://client.example.com/account",
},Start sign-in
const response = await fetch('/api/auth/sso/oidc/sign-in', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ connectionId: 'acme' }),
});
const { url } = await response.json();
window.location.assign(url);The client submits only connectionId; it does not submit an issuer or client
secret. Authlier discovers the trusted provider, uses state, nonce, and S256
PKCE, validates the ID token, calls the resolver, and creates a session.
ResolveIdentity must use the connection ID and immutable provider subject,
not an email match. Returning an error denies sign-in.
SuccessRedirectURL is the frontend page opened after Authlier creates
the cookie session. OIDC is available only in cookie mode in this release; see
Bearer tokens.