1.5 KiB
Authentik provider configuration
ThothII uses generic OIDC in the browser. Authentik provides the identity provider and group catalog without adding a proprietary login flow.
sequenceDiagram
participant Browser
participant ThothII
participant Authentik
Browser->>ThothII: Sign in
ThothII->>Authentik: Authorization Code with PKCE
Authentik-->>Browser: Login and consent
Browser->>ThothII: Callback with code
ThothII->>Authentik: Token exchange
Authentik-->>ThothII: Identity and groups
ThothII-->>Browser: Opaque session
OIDC provider
- Create an OAuth2/OIDC application and provider.
- Register exactly
PUBLIC_URL/api/auth/oidc/callback. - Enable the
openid,profile, andemailscopes. - Configure a direct
groupsclaim as an array of strings.
Group catalog
Create a dedicated service account with read-only access to groups. Store its token in the
protected bundle as THT_AUTHENTIK_API_TOKEN.
Map the exact enterprise group names to the ThothII user and admin roles in auth.yaml.
Unmapped groups are ignored. A configured group that does not exist produces a closed error.
Diagnostics
tht auth check checks discovery, the issuer, JWKS, catalog access, and the configured groups.
The --interactive option also verifies identity through device flow when the provider supports it.
Rotate the OIDC secret and group-catalog token separately. Neither may appear in YAML, shell history, logs, or diagnostic output.