Nextcloud + Casdoor

Single sign-on for Nextcloud

Nextcloud's OpenID Connect user backend app (user_oidc) creates Nextcloud accounts from an OpenID Connect provider. With Casdoor as the provider, people sign in to Nextcloud with their Casdoor account, and their Casdoor groups become Nextcloud groups.

You need a running Casdoor, self-hosted or on Casdoor Cloud. In the examples, replace https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.

Set up Nextcloud with Casdoor

  1. 1

    Register Nextcloud in Casdoor

    In the Casdoor console, open Applications, add an application for Nextcloud, and on its OIDC/OAuth tab copy the Client ID and Client secret. Add this redirect URL to Redirect URLs:

    • https://cloud.example.com/apps/user_oidc/code

    If your Nextcloud URLs include /index.php, use https://cloud.example.com/index.php/apps/user_oidc/code instead. To use groups, create them in the application's organization (for example family or finance) and add users. Then set Token group format to Name on the same tab, so tokens carry family rather than <organization>/family.

  2. 2

    Install the OpenID Connect app

    Install OpenID Connect user backend from the Nextcloud app store, or with occ:

    sudo -u www-data php occ app:install user_oidc
  3. 3

    Add Casdoor as a provider

    Run this from the Nextcloud directory. It names the provider Casdoor, maps Nextcloud user IDs to Casdoor usernames instead of hashes, and creates Nextcloud groups from the groups claim.

    sudo -u www-data php occ user_oidc:provider Casdoor \
      --clientid="<client ID>" \
      --clientsecret="<client secret>" \
      --discoveryuri="https://auth.example.com/.well-known/openid-configuration" \
      --scope="openid email profile" \
      --unique-uid=0 \
      --mapping-uid=name \
      --mapping-display-name=displayName \
      --mapping-email=email \
      --mapping-groups=groups \
      --group-provisioning=1
  4. 4

    Sign in

    The Nextcloud login page now has a Log in with Casdoor button. To send everyone straight to Casdoor, turn off the other login methods; administrators can still reach the normal login form by adding ?direct=1 to the login URL.

    sudo -u www-data php occ config:app:set --type=string --value=0 user_oidc allow_multiple_user_backends

Good to know

  • The mappings above read Casdoor's default ID token, where name is the username and displayName the display name. If you switch the application's Token format to JWT-Standard, map the user ID to preferred_username and the display name to name instead; that format doesn't include groups.
  • Without --unique-uid=0, Nextcloud stores each user under a hash of the provider and user ID, which is safe with several providers but hard to read.

Nextcloud settings are from its documentation as of October 2026 (Nextcloud user_oidc). Nextcloud is a trademark of its owner.

FAQ

Frequently asked questions

Does it work with the Nextcloud desktop and mobile apps?
Yes. The apps sign in through the browser using Nextcloud's login flow, which shows the same Log in with Casdoor button.
Can I use LDAP instead?
Casdoor also runs an LDAP server that Nextcloud's LDAP app can use. OpenID Connect is simpler to set up, and it keeps Casdoor's MFA, passkeys and social logins in the sign-in.