GitLab + Casdoor
Single sign-on for self-managed GitLab
Self-managed GitLab signs users in through OmniAuth providers, including any OpenID Connect provider. With Casdoor as the provider, developers use one account for GitLab and the rest of your tools.
https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.Set up GitLab with Casdoor
- 1
Register GitLab in Casdoor
In the Casdoor console, open Applications, add an application for GitLab, and on its OIDC/OAuth tab copy the Client ID and Client secret. Add this redirect URL to Redirect URLs:
https://gitlab.example.com/users/auth/openid_connect/callback
- 2
Add Casdoor to gitlab.rb
GitLab only talks to OpenID providers over HTTPS, so serve Casdoor over HTTPS. Add this to
/etc/gitlab/gitlab.rband runsudo gitlab-ctl reconfigure.gitlab_rails['omniauth_allow_single_sign_on'] = ['openid_connect'] gitlab_rails['omniauth_block_auto_created_users'] = false gitlab_rails['omniauth_providers'] = [ { name: "openid_connect", label: "Casdoor", args: { name: "openid_connect", scope: ["openid", "profile", "email"], response_type: "code", issuer: "https://auth.example.com", discovery: true, client_auth_method: "query", uid_field: "sub", pkce: true, client_options: { identifier: "<client ID>", secret: "<client secret>", redirect_uri: "https://gitlab.example.com/users/auth/openid_connect/callback" } } } ] - 3
Map Casdoor groups (GitLab Premium and Ultimate)
To make members of a Casdoor group GitLab administrators, or to mark contractors as external users, add a
gitlabblock insideclient_options. Set the Casdoor application's Token group format to Name so the values match.gitlab: { groups_attribute: "groups", admin_groups: ["gitlab-admins"], external_groups: ["contractors"] } - 4
Sign in
The sign-in page now has a Casdoor button. People who already have a GitLab account can connect Casdoor under User settings → Account → Service sign-in.
Good to know
omniauth_allow_single_sign_onlets GitLab create an account on first sign-in, andomniauth_block_auto_created_users = falselets new users in without waiting for an administrator to approve them.uid_field: "sub"ties each GitLab identity to the Casdoor user ID, which doesn't change when a user is renamed.
GitLab settings are from its documentation as of October 2026 (GitLab OpenID Connect); see also the Casdoor documentation. GitLab is a trademark of its owner.
FAQ
Frequently asked questions
Do I need GitLab Premium?
I compiled GitLab from source. Where do the settings go?
omniauth in config/gitlab.yml; GitLab's OpenID Connect documentation shows that format next to the gitlab.rb one.Integrations
Single sign-on for your other apps
Ready to secure your next big move?
Put login, single sign-on, MFA, permissions and AI agent access behind one open-source platform, hosted by us or run by you.
Try Casdoor Cloud free
A dedicated instance in the region you choose, from $24.17/month billed yearly with no per-user fees.
Free trialSelf-host for free
Run the same Apache-2.0 Casdoor on your own servers with Docker or Kubernetes.
Read the docsTalk to an expert
Plan a migration, an on-premises rollout or an authorization model with our team.
Contact sales