Nextcloud + Casdoor
Single sign-on for Nextcloud
Nextcloud's OpenID Connect user backend app (user_oidc) creates Nextcloud accounts from an OpenID Connect provider. With Casdoor as the provider, people sign in to Nextcloud with their Casdoor account, and their Casdoor groups become Nextcloud groups.
https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.Set up Nextcloud with Casdoor
- 1
Register Nextcloud in Casdoor
In the Casdoor console, open Applications, add an application for Nextcloud, and on its OIDC/OAuth tab copy the Client ID and Client secret. Add this redirect URL to Redirect URLs:
https://cloud.example.com/apps/user_oidc/code
If your Nextcloud URLs include
/index.php, usehttps://cloud.example.com/index.php/apps/user_oidc/codeinstead. To use groups, create them in the application's organization (for examplefamilyorfinance) and add users. Then set Token group format to Name on the same tab, so tokens carryfamilyrather than<organization>/family. - 2
Install the OpenID Connect app
Install OpenID Connect user backend from the Nextcloud app store, or with occ:
sudo -u www-data php occ app:install user_oidc - 3
Add Casdoor as a provider
Run this from the Nextcloud directory. It names the provider Casdoor, maps Nextcloud user IDs to Casdoor usernames instead of hashes, and creates Nextcloud groups from the
groupsclaim.sudo -u www-data php occ user_oidc:provider Casdoor \ --clientid="<client ID>" \ --clientsecret="<client secret>" \ --discoveryuri="https://auth.example.com/.well-known/openid-configuration" \ --scope="openid email profile" \ --unique-uid=0 \ --mapping-uid=name \ --mapping-display-name=displayName \ --mapping-email=email \ --mapping-groups=groups \ --group-provisioning=1 - 4
Sign in
The Nextcloud login page now has a Log in with Casdoor button. To send everyone straight to Casdoor, turn off the other login methods; administrators can still reach the normal login form by adding
?direct=1to the login URL.sudo -u www-data php occ config:app:set --type=string --value=0 user_oidc allow_multiple_user_backends
Good to know
- The mappings above read Casdoor's default ID token, where
nameis the username anddisplayNamethe display name. If you switch the application's Token format to JWT-Standard, map the user ID topreferred_usernameand the display name tonameinstead; that format doesn't include groups. - Without
--unique-uid=0, Nextcloud stores each user under a hash of the provider and user ID, which is safe with several providers but hard to read.
Nextcloud settings are from its documentation as of October 2026 (Nextcloud user_oidc). Nextcloud is a trademark of its owner.
FAQ
Frequently asked questions
Does it work with the Nextcloud desktop and mobile apps?
Can I use LDAP instead?
Integrations
Single sign-on for your other apps
Ready to secure your next big move?
Put login, single sign-on, MFA, permissions and AI agent access behind one open-source platform, hosted by us or run by you.
Try Casdoor Cloud free
A dedicated instance in the region you choose, from $24.17/month billed yearly with no per-user fees.
Free trialSelf-host for free
Run the same Apache-2.0 Casdoor on your own servers with Docker or Kubernetes.
Read the docsTalk to an expert
Plan a migration, an on-premises rollout or an authorization model with our team.
Contact sales