Proxmox VE + Casdoor

Single sign-on for Proxmox VE

Proxmox VE can authenticate users against an OpenID Connect realm. With Casdoor as the realm, admins sign in to the Proxmox web interface with their Casdoor account and MFA, and Proxmox permissions follow Casdoor groups.

You need a running Casdoor, self-hosted or on Casdoor Cloud. In the examples, replace https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.

Set up Proxmox VE with Casdoor

  1. 1

    Register Proxmox VE in Casdoor

    In the Casdoor console, open Applications, add an application for Proxmox VE, and on its OIDC/OAuth tab copy the Client ID and Client secret. Add this redirect URL to Redirect URLs:

    • https://pve.example.com:8006

    Proxmox VE sends the address of its web interface as the redirect URL, so add every address you open it at, with the port. To use groups, create them in the application's organization (for example pve-admins) and add users. Then set Token group format to Name on the same tab, so tokens carry pve-admins rather than <organization>/pve-admins.

  2. 2

    Add an OpenID Connect realm

    Run this on a Proxmox VE node, or add the realm under Datacenter → Permissions → Realms → Add → OpenID Connect Server. username takes the preferred_username claim, so users appear as alice@casdoor.

    pveum realm add casdoor --type openid \
      --issuer-url https://auth.example.com \
      --client-id "<client ID>" \
      --client-key "<client secret>" \
      --username-claim username \
      --autocreate 1 \
      --groups-claim groups \
      --groups-autocreate 1
  3. 3

    Give the group permissions

    Proxmox VE appends the realm name to groups from the claim, so pve-admins becomes pve-admins-casdoor. Grant it a role, for example administrator rights on the whole datacenter:

    pveum acl modify / --groups pve-admins-casdoor --roles Administrator
  4. 4

    Sign in

    On the Proxmox VE login screen, choose the casdoor realm and click Login (OpenID redirect); Proxmox sends you to Casdoor and back.

Good to know

  • Users created by --autocreate have no permissions until a group or user ACL grants them some.
  • The group options are in recent Proxmox VE releases; on older versions, leave out the --groups-* lines and grant permissions to users instead.

Proxmox VE settings are from its documentation as of October 2026 (Proxmox VE user management, pveum manual). Proxmox VE is a trademark of its owner.

FAQ

Frequently asked questions

Can I still use root@pam?
Yes. Adding a realm doesn't change the existing PAM and Proxmox VE realms, so keep root@pam as a fallback.
Why username and not the default subject claim?
The default sub claim is Casdoor's user ID, a random string. username gives readable names such as alice@casdoor; Casdoor usernames are unique within an organization.