Skip to main content

Pyramid Oidc client library for caerp

python setup.py install

Add a client in your OpenId Authentication (e.g: Keycloak)

To configure your open id connect client in a SSO server like Keycloak.

Host : https://caerp.mycae.coop

Important Create a custom realm (don't use the master realm, you'll face serious security problems : all users would have admin rights on Keycloak)

Add a client

For security reasons, always use HTTPS protocol in URLs. Certificates must be provided by well known authorities.

The REQUESTS_CA_BUNDLE environment variable may be used to specify your custom trusted certificates.

Retrieve the client secret

In the "Credentials" section of the keycloak client view, retrieve the client's secret (you need it to configure caerp)

Configure your client : caerp

In your caerp application's ini file

pyramid.includes = ...
                   caerp_oidc_client.models

Later in the same ini file

caerp.authentification_module=caerp_oidc_client

oidc.client_secret=<Secret token from the OIDC server>
oidc.client_id=caerp_client_id
oidc.scope=openid roles
oidc.auth_endpoint_url=<Keycloak auth endpoint url>
oidc.token_endpoint_url=<Keycloak id token endpoint url>
oidc.logout_endpoint_url=<Keycloak logout endpoint url>

JWKS Token validation

Due to backward compatibility, by default, caerp_oidc_client doesn't validate the JWT token using the JWKS encryption data.

JWKS validation is highly recommended and is mandatory for obvious security reasons when the JWT token is transmitted by a third_party (for example frontend or api gateway).

To configure JWKS Token validation, add the following lines :

oidc.jwks_service=caerp_oidc_client.services.JWKSService
oidc.jwks_endpoint_url=<Keycloak jwks endpoint url>
oidc.token_signature_algorithms=<use one of HS256 HS384 HS512 RS256 RS384 RS512>

Keycloak's url are in the form

https://keycloak/realms/my custom realm name/protocol/openid-connect/auth

https://keycloak/realms/my custom realm name/protocol/openid-connect/token

https://keycloak/realms/my custom realm name/protocol/openid-connect/logout

https://keycloak/realms/my custom realm name/protocol/openid-connect/certs

Some advices for security

Metadata

Release files for caerp-oidc-client 2026.0.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for caerp-oidc-client 2026.0.2
File Size Uploaded
caerp_oidc_client-2026.0.2.tar.gz 22.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for caerp-oidc-client 2026.0.2
File Interpreter ABI Platform
caerp_oidc_client-2026.0.2-py3-none-any.whl Python 3 none any Details

Total release size: 43.6 kB

Release files / caerp_oidc_client-2026.0.2.tar.gz

Download URL caerp_oidc_client-2026.0.2.tar.gz
Size 22.1 kB
Tags Source
SHA-256 checksum
How to use checksums
c627f30ecafda87e2a7c911e47bfc727df400ec10996d9639d0d7cf50ef0d4dd
BLAKE2b-256 checksum
How to use checksums
ac5adfdb1288816f76085b174a1cdf4fc396851084506cff61fe6d7dc7821c51
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.13

Release files / caerp_oidc_client-2026.0.2-py3-none-any.whl

Download URL caerp_oidc_client-2026.0.2-py3-none-any.whl
Size 21.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
00c5a547b5d4135dd3c89bf7f3d5cf86643f18ba305ecb1a10fa401ecdf6774d
BLAKE2b-256 checksum
How to use checksums
8a86a6a5a875ef728de3b99350652b9dad8917b1dbee31093fe56c20e37c6d3d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.13
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page