Argo CD + Casdoor
Single sign-on for Argo CD
Argo CD can use an existing OpenID Connect provider directly, without its bundled Dex. With Casdoor, people sign in to the Argo CD UI and CLI with their Casdoor account, and Casdoor groups decide what they can do.
https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.Set up Argo CD with Casdoor
- 1
Register Argo CD in Casdoor
In the Casdoor console, open Applications, add an application for Argo CD, and on its OIDC/OAuth tab copy the Client ID and Client secret. Add these redirect URLs to Redirect URLs:
https://argocd.example.com/auth/callbackhttp://localhost:8085/auth/callback
The second URL is for
argocd login --ssofrom the CLI. To use groups, create them in the application's organization (for exampleargocd-admins) and add users. Then set Token group format to Name on the same tab, so tokens carryargocd-adminsrather than<organization>/argocd-admins. - 2
Store the client secret
Put the client secret in the
argocd-secretSecret, whereoidc.configcan reference it.kubectl -n argocd patch secret argocd-secret \ --patch='{"stringData": {"oidc.casdoor.clientSecret": "<client secret>"}}' - 3
Configure OIDC in argocd-cm
Add Casdoor to the
argocd-cmConfigMap. Casdoor puts the user's groups in the ID token, which is where Argo CD reads them.apiVersion: v1 kind: ConfigMap metadata: name: argocd-cm namespace: argocd data: url: https://argocd.example.com oidc.config: | name: Casdoor issuer: https://auth.example.com clientID: <client ID> clientSecret: $oidc.casdoor.clientSecret requestedScopes: ["openid", "profile", "email"] enablePKCEAuthentication: true - 4
Grant permissions by group
Map Casdoor groups to Argo CD roles in
argocd-rbac-cm. Here members ofargocd-adminsget full access and everyone else can only look.apiVersion: v1 kind: ConfigMap metadata: name: argocd-rbac-cm namespace: argocd data: policy.default: role:readonly policy.csv: | g, argocd-admins, role:admin scopes: "[groups]" - 5
Sign in
The Argo CD login page now has a Log in via Casdoor button, and
argocd login argocd.example.com --ssoopens Casdoor in the browser.
Good to know
- Argo CD reads
oidc.configchanges without a restart, but users have to sign in again to pick up new group memberships.
Argo CD settings are from its documentation as of October 2026 (Argo CD user management). Argo CD is a trademark of its owner.
FAQ
Frequently asked questions
Do I still need Dex?
oidc.config, Argo CD talks to Casdoor directly, and you can leave Dex unconfigured.Can the argocd CLI sign in through Casdoor?
argocd login <server> --sso opens the browser and receives the result on http://localhost:8085/auth/callback, which is why that URL is in the Casdoor application.Integrations
Single sign-on for your other apps
Ready to secure your next big move?
Put login, single sign-on, MFA, permissions and AI agent access behind one open-source platform, hosted by us or run by you.
Try Casdoor Cloud free
A dedicated instance in the region you choose, from $24.17/month billed yearly with no per-user fees.
Free trialSelf-host for free
Run the same Apache-2.0 Casdoor on your own servers with Docker or Kubernetes.
Read the docsTalk to an expert
Plan a migration, an on-premises rollout or an authorization model with our team.
Contact sales