1.9 KiB
Authentik provider configuration
For full with direct OIDC, ThothII uses generic OIDC in the browser. Authentik provides the identity provider and group catalog without adding a proprietary flow. The provider/client/group setup below applies to that case only.
For embedded in Omics, retain Omics's existing Authentik authentication and
configure ThothII as upstream. Omics verifies datamart_builder.access and
administrator status and the proxy supplies the identity; no additional ThothII
OIDC client, login or local user is required for that path. Follow the
portal integration guide.
sequenceDiagram
participant Browser
participant ThothII
participant Authentik
Browser->>ThothII: Sign in
ThothII->>Authentik: Authorization Code with PKCE
Authentik-->>Browser: Login and consent
Browser->>ThothII: Callback with code
ThothII->>Authentik: Token exchange
Authentik-->>ThothII: Identity and groups
ThothII-->>Browser: Opaque session
OIDC provider
- Create an OAuth2/OIDC application and provider.
- Register exactly
PUBLIC_URL/api/auth/oidc/callback. - Enable the
openid,profile, andemailscopes. - Configure a direct
groupsclaim as an array of strings.
Group catalog
Create a dedicated service account with read-only access to groups. Store its token in the
protected bundle as THT_AUTHENTIK_API_TOKEN.
Map the exact enterprise group names to the ThothII user and admin roles in auth.yaml.
Unmapped groups are ignored. A configured group that does not exist produces a closed error.
Diagnostics
tht auth check checks discovery, the issuer, JWKS, catalog access, and the configured groups.
The --interactive option also verifies identity through device flow when the provider supports it.
Rotate the OIDC secret and group-catalog token separately. Neither may appear in YAML, shell history, logs, or diagnostic output.