Open WebUI + Casdoor

Single sign-on for Open WebUI

Open WebUI, the self-hosted chat interface for local and hosted models, can sign users in through any OpenID Connect provider. With Casdoor, your team signs in with their company account, and Casdoor groups decide which models and tools they see.

You need a running Casdoor, self-hosted or on Casdoor Cloud. In the examples, replace https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.

Set up Open WebUI with Casdoor

  1. 1

    Register Open WebUI in Casdoor

    In the Casdoor console, open Applications, add an application for Open WebUI, and on its OIDC/OAuth tab copy the Client ID and Client secret. Add this redirect URL to Redirect URLs:

    • https://chat.example.com/oauth/oidc/callback

    To use groups, create them in the application's organization (for example engineering or support) and add users. Then set Token group format to Name on the same tab, so tokens carry engineering rather than <organization>/engineering.

  2. 2

    Set the OAuth environment variables

    Add these to the Open WebUI container and restart it. OPENID_PROVIDER_URL is Casdoor's discovery document.

    WEBUI_URL=https://chat.example.com
    ENABLE_OAUTH_SIGNUP=true
    DEFAULT_USER_ROLE=user
    OAUTH_PROVIDER_NAME=Casdoor
    OAUTH_CLIENT_ID=<client ID>
    OAUTH_CLIENT_SECRET=<client secret>
    OPENID_PROVIDER_URL=https://auth.example.com/.well-known/openid-configuration
    OAUTH_SCOPES=openid email profile
    ENABLE_OAUTH_GROUP_MANAGEMENT=true
    OAUTH_GROUP_CLAIM=groups
  3. 3

    Sign in

    The login page now has a Continue with Casdoor button. With group management on, each sign-in syncs the user's Open WebUI groups with their Casdoor groups.

Good to know

  • Open WebUI only adds users to groups that already exist in Open WebUI. Create them first, or set ENABLE_OAUTH_GROUP_CREATION=true to create them on sign-in.
  • By default, these environment variables are the source of truth and the OAuth section of the admin panel is read-only.
  • Set OAUTH_MERGE_ACCOUNTS_BY_EMAIL=true if existing local users should keep their chats when they switch to Casdoor.

Open WebUI settings are from its documentation as of October 2026 (Open WebUI SSO, Open WebUI SSO troubleshooting). Open WebUI is a trademark of its owner.

FAQ

Frequently asked questions

Who becomes an admin?
Users signing up through Casdoor get the role in DEFAULT_USER_ROLE. Left at its default, pending, an admin has to approve each new user; user lets them in straight away. Promote admins in the Open WebUI admin panel.
Can I restrict models by Casdoor group?
Yes. Once groups sync from Casdoor, give each Open WebUI group access to the models, knowledge bases and tools it should see.