Portainer + Casdoor

Single sign-on for Portainer

Portainer's custom OAuth provider works with Casdoor's OAuth 2.0 endpoints, so people manage containers with their Casdoor account instead of a separate Portainer password.

You need a running Casdoor, self-hosted or on Casdoor Cloud. In the examples, replace https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.

Set up Portainer with Casdoor

  1. 1

    Register Portainer in Casdoor

    In the Casdoor console, open Applications, add an application for Portainer, and on its OIDC/OAuth tab copy the Client ID and Client secret. Add this redirect URL to Redirect URLs:

    • https://portainer.example.com
  2. 2

    Configure OAuth in Portainer

    In Portainer, open Settings → Authentication, choose OAuth, turn on Use SSO and Automatic user provisioning, pick the Custom provider and fill in:

    Client ID<client ID>
    Client secret<client secret>
    Authorization URLhttps://auth.example.com/login/oauth/authorize
    Access token URLhttps://auth.example.com/api/login/oauth/access_token
    Resource URLhttps://auth.example.com/api/userinfo
    Redirect URLhttps://portainer.example.com
    User identifierpreferred_username
    Scopesopenid profile email
  3. 3

    Sign in

    Save and log out. The Portainer login page now has a Login with OAuth button that sends users to Casdoor.

Good to know

  • New users created by automatic provisioning have no access until you add them to a team or give them access to an environment.
  • The Redirect URL in Portainer and in Casdoor must be the address people open Portainer at, exactly.

Portainer settings are from its documentation as of October 2026 (Portainer OAuth); see also the Casdoor documentation. Portainer is a trademark of its owner.

FAQ

Frequently asked questions

Can Casdoor groups become Portainer teams?
Mapping OAuth groups to Portainer teams is a Portainer Business Edition feature. In the Community Edition, assign users to teams in Portainer.
Why preferred_username as the user identifier?
It is the Casdoor username in the userinfo response, so Portainer usernames match Casdoor's. You can use email instead if you prefer.