Open WebUI + Casdoor
Single sign-on for Open WebUI
Open WebUI, the self-hosted chat interface for local and hosted models, can sign users in through any OpenID Connect provider. With Casdoor, your team signs in with their company account, and Casdoor groups decide which models and tools they see.
https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.Set up Open WebUI with Casdoor
- 1
Register Open WebUI in Casdoor
In the Casdoor console, open Applications, add an application for Open WebUI, and on its OIDC/OAuth tab copy the Client ID and Client secret. Add this redirect URL to Redirect URLs:
https://chat.example.com/oauth/oidc/callback
To use groups, create them in the application's organization (for example
engineeringorsupport) and add users. Then set Token group format to Name on the same tab, so tokens carryengineeringrather than<organization>/engineering. - 2
Set the OAuth environment variables
Add these to the Open WebUI container and restart it.
OPENID_PROVIDER_URLis Casdoor's discovery document.WEBUI_URL=https://chat.example.com ENABLE_OAUTH_SIGNUP=true DEFAULT_USER_ROLE=user OAUTH_PROVIDER_NAME=Casdoor OAUTH_CLIENT_ID=<client ID> OAUTH_CLIENT_SECRET=<client secret> OPENID_PROVIDER_URL=https://auth.example.com/.well-known/openid-configuration OAUTH_SCOPES=openid email profile ENABLE_OAUTH_GROUP_MANAGEMENT=true OAUTH_GROUP_CLAIM=groups - 3
Sign in
The login page now has a Continue with Casdoor button. With group management on, each sign-in syncs the user's Open WebUI groups with their Casdoor groups.
Good to know
- Open WebUI only adds users to groups that already exist in Open WebUI. Create them first, or set
ENABLE_OAUTH_GROUP_CREATION=trueto create them on sign-in. - By default, these environment variables are the source of truth and the OAuth section of the admin panel is read-only.
- Set
OAUTH_MERGE_ACCOUNTS_BY_EMAIL=trueif existing local users should keep their chats when they switch to Casdoor.
Open WebUI settings are from its documentation as of October 2026 (Open WebUI SSO, Open WebUI SSO troubleshooting). Open WebUI is a trademark of its owner.
FAQ
Frequently asked questions
Who becomes an admin?
DEFAULT_USER_ROLE. Left at its default, pending, an admin has to approve each new user; user lets them in straight away. Promote admins in the Open WebUI admin panel.Can I restrict models by Casdoor group?
Integrations
Single sign-on for your other apps
Ready to secure your next big move?
Put login, single sign-on, MFA, permissions and AI agent access behind one open-source platform, hosted by us or run by you.
Try Casdoor Cloud free
A dedicated instance in the region you choose, from $24.17/month billed yearly with no per-user fees.
Free trialSelf-host for free
Run the same Apache-2.0 Casdoor on your own servers with Docker or Kubernetes.
Read the docsTalk to an expert
Plan a migration, an on-premises rollout or an authorization model with our team.
Contact sales