2.0 KiB
Authentik provider setup
Authentik is the first certified provider for PSD acceptance. The ThothII browser protocol remains generic OIDC; these steps configure the provider-specific group catalog only.
-
Create an OAuth2/OIDC application and provider in Authentik. Register exactly
<publicUrl>/api/auth/oidc/callbackas the callback and enableopenid,profile, andemail. -
Configure the provider so the ID token contains a direct
groupsarray of strings. Verify the claim with a disposable test identity before running acceptance. -
Create a dedicated API service account for the group catalog. Grant group-view-only privilege; do not grant write, user-management, or directory-administration privilege. Put its bearer value in the protected bundle under
THT_AUTHENTIK_API_TOKEN. -
Create or confirm the exact groups
TOT UsersandTOT Admin. Map them explicitly inauth.yamltouserandadmin, respectively. Keep other upstream groups out of the mapping. -
Run the static check and then the live interactive check:
tht auth check tht auth check --interactive tht doctor --json -
Run workspace Validate and then workspace Test. Test must prove discovery/JWKS, catalog access, and every configured group. The diagnostic result must contain no secret values.
Only configured exact group names are queried. Additional Authentik or directory groups are ignored
silently, without a warning. A mapped group absent from Authentik fails closed with
oidc_mapped_group_missing; an ambiguous exact-name result uses
oidc_mapped_group_ambiguous. A group visible only in an upstream directory but not represented
in Authentik is missing from ThothII’s catalog and must not be treated as present.
Rotate the two credentials independently through the protected secret-file procedure, then repeat
tht auth check and workspace Test. Never put either value in this guide, YAML, shell history,
diagnostic output, or acceptance evidence.