Vaultwarden + Casdoor
Single sign-on for Vaultwarden
Since version 1.35.0, Vaultwarden can sign users in through an OpenID Connect provider. With Casdoor, your team signs in to the password manager with the same account and MFA they use everywhere else.
https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.Set up Vaultwarden with Casdoor
- 1
Register Vaultwarden in Casdoor
In the Casdoor console, open Applications, add an application for Vaultwarden, and on its OIDC/OAuth tab copy the Client ID and Client secret. Add this redirect URL to Redirect URLs:
https://vault.example.com/identity/connect/oidc-signin
- 2
Configure Vaultwarden
Set these environment variables on Vaultwarden 1.35.0 or later, for example in Docker Compose, and restart it. Vaultwarden builds the redirect URI from
DOMAIN.services: vaultwarden: image: vaultwarden/server:latest environment: DOMAIN: "https://vault.example.com" SSO_ENABLED: "true" SSO_AUTHORITY: "https://auth.example.com" SSO_CLIENT_ID: "<client ID>" SSO_CLIENT_SECRET: "<client secret>" SSO_SCOPES: "email profile" SSO_PKCE: "true" - 3
Sign in
Users can now choose single sign-on on the Vaultwarden login page, sign in at Casdoor, and then unlock their vault. Add
SSO_ONLY: "true"once everyone has switched, to turn off email-and-password login.
Good to know
SSO_AUTHORITYmust equal theissuerinhttps://auth.example.com/.well-known/openid-configurationexactly, without a trailing slash.- Vaultwarden refuses to sign up a user whose ID token says
email_verified: false. Casdoor marks an email as verified once the user confirms it with a code or a magic link, for example at sign-up. - The Bitwarden mobile apps support Vaultwarden SSO from version 2026.1.0.
Vaultwarden settings are from its documentation as of October 2026 (Vaultwarden SSO wiki, Vaultwarden releases). Vaultwarden is a trademark of its owner.
FAQ
Frequently asked questions
Do users still need a master password?
I don't see the single sign-on option. Why?
SSO_ENABLED is true, then restart it. If sign-in fails afterwards, compare SSO_AUTHORITY with Casdoor's issuer and check the redirect URI in the Casdoor application.Integrations
Single sign-on for your other apps
Ready to secure your next big move?
Put login, single sign-on, MFA, permissions and AI agent access behind one open-source platform, hosted by us or run by you.
Try Casdoor Cloud free
A dedicated instance in the region you choose, from $24.17/month billed yearly with no per-user fees.
Free trialSelf-host for free
Run the same Apache-2.0 Casdoor on your own servers with Docker or Kubernetes.
Read the docsTalk to an expert
Plan a migration, an on-premises rollout or an authorization model with our team.
Contact sales