Proxmox VE + Casdoor
Single sign-on for Proxmox VE
Proxmox VE can authenticate users against an OpenID Connect realm. With Casdoor as the realm, admins sign in to the Proxmox web interface with their Casdoor account and MFA, and Proxmox permissions follow Casdoor groups.
https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.Set up Proxmox VE with Casdoor
- 1
Register Proxmox VE in Casdoor
In the Casdoor console, open Applications, add an application for Proxmox VE, and on its OIDC/OAuth tab copy the Client ID and Client secret. Add this redirect URL to Redirect URLs:
https://pve.example.com:8006
Proxmox VE sends the address of its web interface as the redirect URL, so add every address you open it at, with the port. To use groups, create them in the application's organization (for example
pve-admins) and add users. Then set Token group format to Name on the same tab, so tokens carrypve-adminsrather than<organization>/pve-admins. - 2
Add an OpenID Connect realm
Run this on a Proxmox VE node, or add the realm under Datacenter → Permissions → Realms → Add → OpenID Connect Server.
usernametakes thepreferred_usernameclaim, so users appear asalice@casdoor.pveum realm add casdoor --type openid \ --issuer-url https://auth.example.com \ --client-id "<client ID>" \ --client-key "<client secret>" \ --username-claim username \ --autocreate 1 \ --groups-claim groups \ --groups-autocreate 1 - 3
Give the group permissions
Proxmox VE appends the realm name to groups from the claim, so
pve-adminsbecomespve-admins-casdoor. Grant it a role, for example administrator rights on the whole datacenter:pveum acl modify / --groups pve-admins-casdoor --roles Administrator - 4
Sign in
On the Proxmox VE login screen, choose the casdoor realm and click Login (OpenID redirect); Proxmox sends you to Casdoor and back.
Good to know
- Users created by
--autocreatehave no permissions until a group or user ACL grants them some. - The group options are in recent Proxmox VE releases; on older versions, leave out the
--groups-*lines and grant permissions to users instead.
Proxmox VE settings are from its documentation as of October 2026 (Proxmox VE user management, pveum manual). Proxmox VE is a trademark of its owner.
FAQ
Frequently asked questions
Can I still use root@pam?
Why username and not the default subject claim?
sub claim is Casdoor's user ID, a random string. username gives readable names such as alice@casdoor; Casdoor usernames are unique within an organization.Integrations
Single sign-on for your other apps
Ready to secure your next big move?
Put login, single sign-on, MFA, permissions and AI agent access behind one open-source platform, hosted by us or run by you.
Try Casdoor Cloud free
A dedicated instance in the region you choose, from $24.17/month billed yearly with no per-user fees.
Free trialSelf-host for free
Run the same Apache-2.0 Casdoor on your own servers with Docker or Kubernetes.
Read the docsTalk to an expert
Plan a migration, an on-premises rollout or an authorization model with our team.
Contact sales