Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • OIDC picture url returns 404

    Solved Support oidc
    3
    1 Votes
    3 Posts
    73 Views
    klawitterbK
    Great, good to hear and looking forward to the fix. Anyway it’s not very urgent. Thanks and happy Xmas
  • OpenID Connect user backend 8.2.2 update issue

    Nextcloud oidc
    3
    1 Votes
    3 Posts
    85 Views
    osoboO
    Thank you for your reply. I have disabled the Nextcloud standard login a while ago so for now users can only login via their Cloudron’s account (including me ). I will try to figure out how to revert that
  • External site (embeded) OIDC login

    Moved Feature Requests oidc
    4
    1 Votes
    4 Posts
    145 Views
    nebulonN
    So currently the login flow pages are served up with content security policy headers to not allow being embedded in another domain/origin. The reason for this is to prevent clickjacking attacks and was explicitly done that way. I guess for this we would need a csp setting for the OpenID provider where one can allow specific domains/origins.
  • Cloudflare Zero Trust Issue with Cloudron OpenID

    Solved Support cloudflare oidc
    3
    0 Votes
    3 Posts
    89 Views
    firmansiF
    It works now
  • How To Integrate OpenID Cloudron with Cloudflare Access?

    Solved Support oidc cloudflare
    5
    2
    1 Votes
    5 Posts
    113 Views
    I
    @girish Thank you, girish for the update!
  • 3 Votes
    6 Posts
    198 Views
    nebulonN
    So I am not sure what pangolin really needs here, but I did some more testing and the mentioned claims are all included in the JWT in my tests already in the currently released Cloudron OIDC server. How did you see that those aren't included in your case as you mentioned? Are you even getting a valid JWT and can you decode that? How does that json object look after that? The token response should look something like: { "access_token": "OGpFA1siYNbAQiCahuvjUDkKgoRAi4cz00lysJC6jt9", "expires_in": 3600, "id_token": "eyJhbGciOiJSUzI1NiIsImtpZCI6IjFrRF..........", "refresh_token": "IJpU-ULmWoEYmUJmd55HLQF7aVHPbZIzdmWHUYQ1vB0", "scope": "openid profile email", "token_type": "Bearer" } Which then decoded in my case holds: Payload (Claims) sub: "nebulon" family_name: "" given_name: "Firstname" locale: "de-DE" name: "Lastname" preferred_username: "nebulon" picture: "https://my.cloudron/api/v1/profile/avatar/uid-e6e4afd0-f677-45e3-8d61-4dd039c32a11.png" email: "nebulon@..." email_verified: true aud: "cid-b901ffe1294a0683aff450bb86d036b5" exp: 1765189670 (8.12.2025, 11:27:50) iat: 1765186070 (8.12.2025, 10:27:50) iss: "https://my.cloudron..../openid"
  • client is invalid on gitea instances

    Solved Support oidc
    3
    1
    1 Votes
    3 Posts
    78 Views
    SansGuidonS
    I also had similar issues as soon as I migrated to Cloudron 9.x and after a while or maybe after successful login attempts with an alternative auth flow, I had no longer any issues authenticating through OpenID. weird indeed but I have noticed similar complains about Cloudron 9 and OIDC in other threads.
  • 2 Votes
    4 Posts
    151 Views
    jamesJ
    Hello @scooke Glad I could explain/resolve this issue for you.
  • MinIO not working anymore after upgrade to Cloudron 9

    Solved Minio oidc restart loop jwk
    2
    1 Votes
    2 Posts
    129 Views
    M
    Ok nevermind, I found the corresponding update and it works again after updating to the next version.
  • Update 9 - OpenID Broken - VPS OVH

    Solved Support oidc locale
    9
    1 Votes
    9 Posts
    300 Views
    girishG
    @SDEInfo fixed with https://git.cloudron.io/platform/box/-/commit/e87d2e1218ce0e6d5a9ee89e57976e459b73c7d4
  • External Provider (OIDC / OAuth) - Google Workspace

    Unsolved Support oidc
    8
    1 Votes
    8 Posts
    2k Views
    jamesJ
    Hello @Lomeu Did you figure this out or is this still an issue?
  • Clearing OIDC... cookie? user? -- How to log in and out?

    Solved Support oidc
    4
    1 Votes
    4 Posts
    663 Views
    jadudmJ
    @jdaviescoates and @girish: Excellent. Thank you. I can work with this. Very much appreciated.
  • OpenID Connect Error on iOS

    Solved Traccar oidc
    24
    0 Votes
    24 Posts
    3k Views
    H
    I can confirm that this issue was fixed with the changes made in the Cloudron app as well as upstream by the Traccar developers several months ago.
  • 1 Votes
    3 Posts
    569 Views
    Z
    Indeed they're back when they login with OIDC, thanks for the tips. This ticket can be closed I think.
  • Can't use OpenID login due to unknown certificate

    Solved Support oidc certificates
    6
    1
    1 Votes
    6 Posts
    492 Views
    J
    @Mamouti if you need (smallish) changes to the packages, feel free to submit MRs . All the packages are at https://git.cloudron.io/packages/
  • OpenID login page blank on Firefox

    Solved Support firefox openid oidc
    5
    1 Votes
    5 Posts
    376 Views
    J
    MetaMask the crypto wallet? Not sure why that could be causing problems, but maybe a question for the MetaMask people.
  • OIDC login broken with 8.1.0 update

    Solved Directus directus oidc client
    9
    1 Votes
    9 Posts
    1k Views
    M
    thanks @nebulon & @girish, this does indeed fix everything, appreciate it
  • 0 Votes
    6 Posts
    2k Views
    nebulonN
    In OpenID there is no well supported way to log out users from services which used the OpenID for authentication (in Cloudron case the apps). Those app have their own session and session handling. So there is mostly likely no way around this unless an app would start using OAuth2 access and refresh tokens (but implementation of that was spotty in the past which sparked OpenID connect in the first place) For a start if you logout of the dashboard, subsequent app logins (from a state where the app has no login session) then Cloudron will prompt you to login with a username. If that is not happening the Oidc session was still alive. The best way I found was to use container tabs in like firefox and probably other browsers, which maintain isolated sessions. This is also how I use other services like Digitalocean where we have multiple accounts with different roles.
  • OpendID Connect: openid/session/end endpoint

    Solved Support oidc
    2
    0 Votes
    2 Posts
    526 Views
    nebulonN
    Good catch, we have to fixup the docs here. The OpenID provider session logout, triggered by the app used to be there, but we found that no app supports this properly so it got removed. For nextcloud, we have some changes to soon enable OIDC login by default in the package, so may not be worth it to investigate just now in your case.
  • External Wordpress with Cloudron OIDC

    Solved Support oidc wordpress
    2
    0 Votes
    2 Posts
    702 Views
    D
    Oops nm I figured out the right Wordpress login url and redirect pattern to use