mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
113 lines
5.9 KiB
Plaintext
113 lines
5.9 KiB
Plaintext
---
|
||
title: "Keycloak OIDC"
|
||
description: "Learn how to configure Keycloak OIDC for Infisical SSO."
|
||
---
|
||
|
||
<Info>
|
||
Keycloak OIDC SSO is a paid feature. If you're using Infisical Cloud, then it
|
||
is available under the **Pro Tier**. If you're self-hosting Infisical, then
|
||
you should contact sales@infisical.com to purchase an enterprise license to
|
||
use it.
|
||
</Info>
|
||
|
||
<Steps>
|
||
<Step title="Create an OIDC client application in Keycloak">
|
||
1.1. In your realm, navigate to the **Clients** tab and click **Create client** to create a new client application.
|
||
|
||

|
||
|
||
<Info>
|
||
You don’t typically need to make a realm dedicated to Infisical. We recommend adding Infisical as a client to your primary realm.
|
||
</Info>
|
||
|
||
1.2. In the General Settings step, set **Client type** to **OpenID Connect**, the **Client ID** field to an appropriate identifier, and the **Name** field to a friendly name like **Infisical**.
|
||
|
||

|
||
|
||
1.3. Next, in the Capability Config step, ensure that **Client Authentication** is set to On and that **Standard flow** is enabled in the Authentication flow section.
|
||
|
||

|
||
|
||
1.4. In the Login Settings step, set the following values:
|
||
- Root URL: `https://app.infisical.com`.
|
||
- Home URL: `https://app.infisical.com`.
|
||
- Valid Redirect URIs: `https://app.infisical.com/api/v1/sso/oidc/callback`.
|
||
- Web origins: `https://app.infisical.com`.
|
||
|
||

|
||
<Info>
|
||
If you’re self-hosting Infisical, then you will want to replace https://app.infisical.com (base URL) with your own domain.
|
||
</Info>
|
||
|
||
1.5. Next, navigate to the **Client scopes** tab and select the client's dedicated scope.
|
||
|
||

|
||
|
||
1.6. Next, click **Add predefined mapper**.
|
||
|
||

|
||
|
||
1.7. Select the **email**, **given name**, **family name** attributes and click **Add**.
|
||
|
||

|
||

|
||
|
||
Once you've completed the above steps, the list of mappers should look like the following:
|
||

|
||
|
||
</Step>
|
||
<Step title="Retrieve Identity Provider (IdP) Information from Keycloak">
|
||
2.1. Back in Keycloak, navigate to Configure > Realm settings > General tab > Endpoints > OpenID Endpoint Configuration and copy the opened URL. This is what is to referred to as the Discovery Document URL and it takes the form: `https://keycloak-mysite.com/realms/myrealm/.well-known/openid-configuration`.
|
||

|
||
|
||
2.2. From the Clients page, navigate to the Credential tab and copy the **Client Secret** to be used in the next steps.
|
||

|
||
|
||
</Step>
|
||
<Step title="Finish configuring OIDC in Infisical">
|
||
3.1. Back in Infisical, in the Organization settings > Security > OIDC, click Connect.
|
||

|
||
|
||
3.2. For configuration type, select Discovery URL. Then, set the appropriate values for **Discovery Document URL**, **Client ID**, and **Client Secret**.
|
||

|
||
|
||
Once you've done that, press **Update** to complete the required configuration.
|
||
|
||
</Step>
|
||
<Step title="Enable OIDC SSO in Infisical">
|
||
Enabling OIDC SSO allows members in your organization to log into Infisical via Keycloak.
|
||
|
||

|
||
|
||
</Step>
|
||
<Step title="Enforce OIDC SSO in Infisical">
|
||
Enforcing OIDC SSO ensures that members in your organization can only access Infisical
|
||
by logging into the organization via Keycloak.
|
||
|
||
To enforce OIDC SSO, you're required to test out the OpenID connection by successfully authenticating at least one Keycloak user with Infisical.
|
||
Once you've completed this requirement, you can toggle the **Enforce OIDC SSO** button to enforce OIDC SSO.
|
||
|
||
<Warning>
|
||
We recommend ensuring that your account is provisioned using the application in Keycloak
|
||
prior to enforcing OIDC SSO to prevent any unintended issues.
|
||
</Warning>
|
||
|
||
</Step>
|
||
</Steps>
|
||
|
||
<Tip>
|
||
If you are only using one organization on your Infisical instance, you can configure a default organization in the [Server Admin Console](../admin-panel/server-admin#default-organization) to expedite OIDC login.
|
||
</Tip>
|
||
|
||
<Note>
|
||
If you're configuring OIDC SSO on a self-hosted instance of Infisical, make
|
||
sure to set the `AUTH_SECRET` and `SITE_URL` environment variable for it to
|
||
work:
|
||
<div class="height:1px;"/>
|
||
- `AUTH_SECRET`: A secret key used for signing and verifying JWT. This
|
||
can be a random 32-byte base64 string generated with `openssl rand -base64
|
||
32`.
|
||
<div class="height:1px;"/>
|
||
- `SITE_URL`: The absolute URL of your self-hosted instance of Infisical including the protocol (e.g. https://app.infisical.com)
|
||
</Note>
|