Vaultwarden + Casdoor

Single sign-on for Vaultwarden

Since version 1.35.0, Vaultwarden can sign users in through an OpenID Connect provider. With Casdoor, your team signs in to the password manager with the same account and MFA they use everywhere else.

You need a running Casdoor, self-hosted or on Casdoor Cloud. In the examples, replace https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.

Set up Vaultwarden with Casdoor

  1. 1

    Register Vaultwarden in Casdoor

    In the Casdoor console, open Applications, add an application for Vaultwarden, and on its OIDC/OAuth tab copy the Client ID and Client secret. Add this redirect URL to Redirect URLs:

    • https://vault.example.com/identity/connect/oidc-signin
  2. 2

    Configure Vaultwarden

    Set these environment variables on Vaultwarden 1.35.0 or later, for example in Docker Compose, and restart it. Vaultwarden builds the redirect URI from DOMAIN.

    services:
      vaultwarden:
        image: vaultwarden/server:latest
        environment:
          DOMAIN: "https://vault.example.com"
          SSO_ENABLED: "true"
          SSO_AUTHORITY: "https://auth.example.com"
          SSO_CLIENT_ID: "<client ID>"
          SSO_CLIENT_SECRET: "<client secret>"
          SSO_SCOPES: "email profile"
          SSO_PKCE: "true"
  3. 3

    Sign in

    Users can now choose single sign-on on the Vaultwarden login page, sign in at Casdoor, and then unlock their vault. Add SSO_ONLY: "true" once everyone has switched, to turn off email-and-password login.

Good to know

  • SSO_AUTHORITY must equal the issuer in https://auth.example.com/.well-known/openid-configuration exactly, without a trailing slash.
  • Vaultwarden refuses to sign up a user whose ID token says email_verified: false. Casdoor marks an email as verified once the user confirms it with a code or a magic link, for example at sign-up.
  • The Bitwarden mobile apps support Vaultwarden SSO from version 2026.1.0.

Vaultwarden settings are from its documentation as of October 2026 (Vaultwarden SSO wiki, Vaultwarden releases). Vaultwarden is a trademark of its owner.

FAQ

Frequently asked questions

Do users still need a master password?
Yes. Single sign-on replaces the email-and-password login, but the vault is still encrypted with the user's master password, which they enter after signing in with Casdoor.
I don't see the single sign-on option. Why?
Check that the server runs Vaultwarden 1.35.0 or later and that SSO_ENABLED is true, then restart it. If sign-in fails afterwards, compare SSO_AUTHORITY with Casdoor's issuer and check the redirect URI in the Casdoor application.