OpenID Connect
Sign in with Keycloak, Authentik, Authelia, Zitadel, Microsoft Entra ID, Okta or any other OpenID Connect server.
Use OpenID Connect when your community already has an identity server, or when you want one login for several services. It works with any server that supports OpenID Connect: Keycloak, Authentik, Authelia, Zitadel, Microsoft Entra ID, Okta and others. You pick the button's name, so the login page can say Sign in with NTLAN instead of a product name.
Auto Tournament asks for the openid, profile and email scopes. It keys the account on the sub claim and reads the name, the picture and the email address (only when the server says the address is verified). See Sign-in providers for how accounts and admin access work.
Create a client on your identity server
Create a client for Auto Tournament, often called an application or relying party:
- Type: confidential client, with a client secret. Grant type authorization code.
- Redirect URI: the callback URL from Settings → Sign-in → OpenID Connect in Auto Tournament. It looks like
https://tournament.example.com/api/auth/oidc/callback. - Client authentication: client secret post (
client_secret_post). Most servers accept it next to client secret basic.
Copy the client ID and client secret, and note the issuer URL: the address whose /.well-known/openid-configuration your server publishes.
| Server | Issuer URL |
|---|---|
| Keycloak | https://sso.example.com/realms/<realm> |
| Authentik | https://auth.example.com/application/o/<application-slug> |
| Authelia | https://auth.example.com |
| Zitadel | https://<instance>.zitadel.cloud |
| Microsoft Entra ID | https://login.microsoftonline.com/<tenant-id>/v2.0 |
| Okta | https://<org>.okta.com |
Keycloak: in the realm, go to Clients → Create client, type OpenID Connect, turn on Client authentication, keep Standard flow, and add the redirect URI under Valid redirect URIs. The secret is on the client's Credentials tab.
Turn it on in Auto Tournament
In Settings → Sign-in → OpenID Connect, fill in:
- Issuer URL: from the step above.
- Client ID and Client secret.
- Button name: shown as Sign in with … on the login page and on people's connections page. Leave it empty for OpenID Connect.
Turn it on and save, then click Test. The test reads the discovery document and checks the client ID and secret against the token endpoint. The button appears on the login page right away.
Prefer environment variables? Set AUTH_OIDC_ENABLED=true, OIDC_ISSUER_URL, OIDC_CLIENT_ID, OIDC_CLIENT_SECRET and optionally OIDC_LABEL, and restart. They are imported once.
Test it
Open /login in a private browser window and click the button. You sign in on your identity server and come back signed in.
| What you see | What to check |
|---|---|
| Test says the server is unreachable | The issuer URL. Open <issuer URL>/.well-known/openid-configuration in a browser: it must load, and its issuer must be exactly the issuer URL (no trailing slash difference, right realm or tenant). |
| Test says the credentials are wrong | The client ID and secret, and that the client is confidential. |
| The identity server says the redirect URI is invalid | It does not match the callback URL in Settings exactly. |
| No picture | The server sends no picture claim, or it is not an https address. |