Grafana + Casdoor

Single sign-on for Grafana

Grafana's Generic OAuth works with any OpenID Connect provider. Point it at Casdoor and people sign in to Grafana with their Casdoor accounts, MFA and social logins included, with their Grafana role set from Casdoor groups.

You need a running Casdoor, self-hosted or on Casdoor Cloud. In the examples, replace https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.

Set up Grafana with Casdoor

  1. 1

    Register Grafana in Casdoor

    In the Casdoor console, open Applications, add an application for Grafana, and on its OIDC/OAuth tab copy the Client ID and Client secret. Add this redirect URL to Redirect URLs:

    • https://grafana.example.com/login/generic_oauth

    To use groups, create them in the application's organization (for example grafana-admins and grafana-editors) and add users. Then set Token group format to Name on the same tab, so tokens carry grafana-admins rather than <organization>/grafana-admins.

  2. 2

    Configure Grafana

    Add this section to grafana.ini, or set the same keys as GF_AUTH_GENERIC_OAUTH_* environment variables. root_url must be the address people open in the browser, because Grafana builds the callback URL from it.

    [server]
    root_url = https://grafana.example.com/
    
    [auth.generic_oauth]
    enabled = true
    name = Casdoor
    client_id = <client ID>
    client_secret = <client secret>
    scopes = openid profile email
    auth_url = https://auth.example.com/login/oauth/authorize
    token_url = https://auth.example.com/api/login/oauth/access_token
    api_url = https://auth.example.com/api/userinfo
    use_pkce = true
    allow_sign_up = true
    login_attribute_path = preferred_username
    email_attribute_path = email
    groups_attribute_path = groups
    role_attribute_path = contains(groups[*], 'grafana-admins') && 'Admin' || contains(groups[*], 'grafana-editors') && 'Editor' || 'Viewer'
  3. 3

    Sign in

    Restart Grafana. The login page now has a Sign in with Casdoor button. Members of grafana-admins become Admins, members of grafana-editors Editors, and everyone else a Viewer.

Good to know

  • Grafana evaluates role_attribute_path against the ID token first, then the userinfo response. Casdoor's ID token also lists the user's roles as objects, so contains(roles[*].name, 'admin') works too if you prefer Casdoor roles to groups.
  • Grafana needs an email address for every user, so make sure your Casdoor users have one.

Grafana settings are from its documentation as of October 2026 (Grafana Generic OAuth); see also the Casdoor documentation. Grafana is a trademark of its owner.

FAQ

Frequently asked questions

Can I use SAML instead?
Grafana's SAML sign-in is part of Grafana Enterprise and Grafana Cloud. On open-source Grafana, OpenID Connect through Generic OAuth, as shown here, is the way to connect Casdoor.
Do Casdoor groups become Grafana teams?
groups_attribute_path feeds Grafana's Team Sync, which is a Grafana Enterprise and Grafana Cloud feature. On open-source Grafana, use the groups to set roles as shown above.