GitLab + Casdoor

Single sign-on for self-managed GitLab

Self-managed GitLab signs users in through OmniAuth providers, including any OpenID Connect provider. With Casdoor as the provider, developers use one account for GitLab and the rest of your tools.

You need a running Casdoor, self-hosted or on Casdoor Cloud. In the examples, replace https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.

Set up GitLab with Casdoor

  1. 1

    Register GitLab in Casdoor

    In the Casdoor console, open Applications, add an application for GitLab, and on its OIDC/OAuth tab copy the Client ID and Client secret. Add this redirect URL to Redirect URLs:

    • https://gitlab.example.com/users/auth/openid_connect/callback
  2. 2

    Add Casdoor to gitlab.rb

    GitLab only talks to OpenID providers over HTTPS, so serve Casdoor over HTTPS. Add this to /etc/gitlab/gitlab.rb and run sudo gitlab-ctl reconfigure.

    gitlab_rails['omniauth_allow_single_sign_on'] = ['openid_connect']
    gitlab_rails['omniauth_block_auto_created_users'] = false
    gitlab_rails['omniauth_providers'] = [
      {
        name: "openid_connect",
        label: "Casdoor",
        args: {
          name: "openid_connect",
          scope: ["openid", "profile", "email"],
          response_type: "code",
          issuer: "https://auth.example.com",
          discovery: true,
          client_auth_method: "query",
          uid_field: "sub",
          pkce: true,
          client_options: {
            identifier: "<client ID>",
            secret: "<client secret>",
            redirect_uri: "https://gitlab.example.com/users/auth/openid_connect/callback"
          }
        }
      }
    ]
  3. 3

    Map Casdoor groups (GitLab Premium and Ultimate)

    To make members of a Casdoor group GitLab administrators, or to mark contractors as external users, add a gitlab block inside client_options. Set the Casdoor application's Token group format to Name so the values match.

    gitlab: {
      groups_attribute: "groups",
      admin_groups: ["gitlab-admins"],
      external_groups: ["contractors"]
    }
  4. 4

    Sign in

    The sign-in page now has a Casdoor button. People who already have a GitLab account can connect Casdoor under User settings → Account → Service sign-in.

Good to know

  • omniauth_allow_single_sign_on lets GitLab create an account on first sign-in, and omniauth_block_auto_created_users = false lets new users in without waiting for an administrator to approve them.
  • uid_field: "sub" ties each GitLab identity to the Casdoor user ID, which doesn't change when a user is renamed.

GitLab settings are from its documentation as of October 2026 (GitLab OpenID Connect); see also the Casdoor documentation. GitLab is a trademark of its owner.

FAQ

Frequently asked questions

Do I need GitLab Premium?
Not for single sign-on: any self-managed GitLab can use Casdoor as its OpenID Connect provider. Rules based on OIDC group membership (required, external and admin groups) need GitLab Premium or Ultimate.
I compiled GitLab from source. Where do the settings go?
Put the same provider settings under omniauth in config/gitlab.yml; GitLab's OpenID Connect documentation shows that format next to the gitlab.rb one.