mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
93 lines
4.5 KiB
Plaintext
93 lines
4.5 KiB
Plaintext
---
|
||
title: "Auth0 OIDC"
|
||
description: "Learn how to configure Auth0 OIDC for Infisical SSO."
|
||
---
|
||
|
||
<Info>
|
||
Auth0 OIDC SSO is a paid feature. If you're using Infisical Cloud, then it is
|
||
available under the **Pro Tier**. If you're self-hosting Infisical, then you
|
||
should contact sales@infisical.com to purchase an enterprise license to use
|
||
it.
|
||
</Info>
|
||
|
||
<Steps>
|
||
<Step title="Setup application in Auth0">
|
||
1.1. From the Application's Page, navigate to the settings tab of the Auth0 application you want to integrate with Infisical.
|
||

|
||
|
||
1.2. In the Application URIs section, set the **Application Login URI** and **Allowed Web Origins** fields to `https://app.infisical.com` and the **Allowed Callback URL** field to `https://app.infisical.com/api/v1/sso/oidc/callback`.
|
||

|
||

|
||
<Info>
|
||
If you’re self-hosting Infisical, then you will want to replace https://app.infisical.com with your own domain.
|
||
</Info>
|
||
|
||
Once done, click **Save Changes**.
|
||
|
||
1.3. Proceed to the Connections Tab and enable desired connections.
|
||

|
||
|
||
</Step>
|
||
<Step title="Retrieve Identity Provider (IdP) Information from Auth0">
|
||
2.1. From the application settings page, retrieve the **Client ID** and **Client Secret**
|
||

|
||
|
||
2.2. In the advanced settings (bottom-most section), retrieve the **OpenID Configuration URL** from the Endpoints tab.
|
||

|
||
|
||
Keep these values handy as we will need them in the next steps.
|
||
|
||
</Step>
|
||
<Step title="Finish configuring OIDC in Infisical">
|
||
3.1. Back in Infisical, in the Organization settings > Security > OIDC, click **Connect**.
|
||

|
||
|
||
3.2. For configuration type, select **Discovery URL**. Then, set **Discovery Document URL**, **JWT Signature Algorithm**, **Client ID**, and **Client Secret** from step 2.1 and 2.2.
|
||

|
||
|
||
<Info>
|
||
Currently, the following JWT signature algorithms are supported: RS256, RS512, HS256, and EdDSA
|
||
</Info>
|
||
|
||
Once you've done that, press **Update** to complete the required configuration.
|
||
|
||
</Step>
|
||
<Step title="Enable OIDC in Infisical">
|
||
Enabling OIDC allows members in your organization to log into Infisical via Auth0.
|
||
|
||

|
||
|
||
</Step>
|
||
<Step title="Enforce OIDC SSO in Infisical">
|
||
Enforcing OIDC SSO ensures that members in your organization can only access Infisical
|
||
by logging into the organization via Auth0.
|
||
|
||
To enforce OIDC SSO, you're required to test out the OpenID connection by successfully authenticating at least one Auth0 user with Infisical.
|
||
Once you've completed this requirement, you can toggle the **Enforce OIDC SSO** button to enforce OIDC SSO.
|
||
|
||
<Warning>
|
||
We recommend ensuring that your account is provisioned using the application in Auth0
|
||
prior to enforcing OIDC SSO to prevent any unintended issues.
|
||
</Warning>
|
||
<Info>
|
||
In case of a lockout, an organization admin can use the admin login portal in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
||
</Info>
|
||
</Step>
|
||
</Steps>
|
||
|
||
<Tip>
|
||
If you are only using one organization on your Infisical instance, you can configure a default organization in the [Server Admin Console](../admin-panel/server-admin#default-organization) to expedite OIDC login.
|
||
</Tip>
|
||
|
||
<Note>
|
||
If you're configuring OIDC SSO on a self-hosted instance of Infisical, make
|
||
sure to set the `AUTH_SECRET` and `SITE_URL` environment variable for it to
|
||
work:
|
||
<div class="height:1px;"/>
|
||
- `AUTH_SECRET`: A secret key used for signing and verifying JWT. This
|
||
can be a random 32-byte base64 string generated with `openssl rand -base64
|
||
32`.
|
||
<div class="height:1px;"/>
|
||
- `SITE_URL`: The absolute URL of your self-hosted instance of Infisical including the protocol (e.g. https://app.infisical.com)
|
||
</Note>
|