Gitea + Casdoor

Single sign-on for Gitea

Gitea signs users in through OAuth2 authentication sources, including OpenID Connect providers. Add Casdoor as one, and developers sign in to your Git server with their Casdoor account.

You need a running Casdoor, self-hosted or on Casdoor Cloud. In the examples, replace https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.

Set up Gitea with Casdoor

  1. 1

    Register Gitea in Casdoor

    In the Casdoor console, open Applications, add an application for Gitea, and on its OIDC/OAuth tab copy the Client ID and Client secret. Add this redirect URL to Redirect URLs:

    • https://git.example.com/user/oauth2/Casdoor/callback

    Casdoor in the path is the authentication source name in the next step; the two must match, including case. To use groups, create them in the application's organization (for example gitea-admins) and add users. Then set Token group format to Name on the same tab, so tokens carry gitea-admins rather than <organization>/gitea-admins.

  2. 2

    Add the authentication source

    Run this on the Gitea server (with Docker, prefix it with docker exec -u git <container>), or fill in the same values under Site Administration → Authentication Sources with OAuth2 and the OpenID Connect provider.

    gitea admin auth add-oauth \
      --name Casdoor \
      --provider openidConnect \
      --key "<client ID>" \
      --secret "<client secret>" \
      --auto-discover-url https://auth.example.com/.well-known/openid-configuration \
      --scopes "profile email" \
      --group-claim-name groups \
      --admin-group gitea-admins
  3. 3

    Sign in

    The Gitea sign-in page now has a Sign in with Casdoor button. On first sign-in, users register a new Gitea account or link an existing one. Members of gitea-admins become Gitea administrators.

Good to know

  • To skip the registration form and create accounts straight away, set ENABLE_AUTO_REGISTRATION = true in the [oauth2_client] section of app.ini.

Gitea settings are from its documentation as of October 2026 (Gitea command line); see also the Casdoor documentation. Gitea is a trademark of its owner.

FAQ

Frequently asked questions

Does this work with Forgejo?
Forgejo keeps Gitea's OAuth2 authentication sources, so the same settings apply; check the Forgejo documentation for the exact command name.
Can I require Casdoor for everyone?
Yes. Once your users have linked Casdoor, turn off password sign-in in Gitea's [service] settings so the Casdoor button is the way in.