Skip to main content

Girder OIDC Plugin

A Girder plugin for OpenID Connect (OIDC) authentication via Keycloak.

Features

  • OIDC/Keycloak integration with automatic user creation
  • Admin panel configuration
  • Secure token exchange using authorization code flow
  • Automatic OIDC endpoint discovery

Installation

pip install -e .

Configuration

In the Girder admin panel, go to OIDC/Keycloak Configuration and set:

  • Keycloak URL (Internal): Internal URL for server communication (e.g., https://keycloak:8443)
  • Keycloak Public URL: Public URL for browser redirects (e.g., https://localhost:8443)
  • Keycloak Realm: Realm name (e.g., girder)
  • Client ID: OIDC client ID
  • Client Secret: OIDC client secret
  • Enable OIDC: Enable authentication
  • Auto Create Users: Create Girder users automatically
  • Allow Registration: Allow new user registration

Keycloak Setup

  1. Create an OIDC client in Keycloak:

    • Access Type: confidential
    • Valid Redirect URIs: https://your-girder-host/api/v1/oidc/callback
  2. Copy the client credentials to Girder configuration

API Endpoints

  • GET /api/v1/oidc/configuration - Get config (admin only)
  • PUT /api/v1/oidc/configuration - Update config (admin only)
  • GET /api/v1/oidc/login?redirect=URL - Get authorization URL
  • GET /api/v1/oidc/callback - Callback from Keycloak

Development

pytest plugin_tests/

Issues

When using Girder behind a reverse proxy, the https scheme is not returned by the "getApiUrl" function using default settings. For the redirect address to be valid, you need to manually set the base address of the server (with https) in the admin -> advanced settings panel.

License

Apache 2.0

Metadata

Release files for girder-oidc 0.3.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for girder-oidc 0.3.0
File Size Uploaded
girder_oidc-0.3.0.tar.gz 24.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for girder-oidc 0.3.0
File Interpreter ABI Platform
girder_oidc-0.3.0-py3-none-any.whl Python 3 none any Details

Total release size: 50.2 kB

Release files / girder_oidc-0.3.0.tar.gz

Download URL girder_oidc-0.3.0.tar.gz
Size 24.1 kB
Tags Source
SHA-256 checksum
How to use checksums
a93188aff07aa2532c59ec4e50c2664c9f5c305825eaba1619ef2f260afe2b03
BLAKE2b-256 checksum
How to use checksums
e8018130a084d087404603d0cb3f1b538deb38f16f622002095fce6111b646bd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.0

Release files / girder_oidc-0.3.0-py3-none-any.whl

Download URL girder_oidc-0.3.0-py3-none-any.whl
Size 26.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ed0224c07e325be1c15eaa3e13629b64a28cc4b3b2097978242c67004fd10a05
BLAKE2b-256 checksum
How to use checksums
b1324241318d78141667b8a40a2491563d548478d6994f4310b52214e99bf720
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.0

Release history Release notifications | RSS feed

0.5.0

2 release files

0.4.1

2 release files

0.4.0

2 release files

This release

0.3.0 This release

2 release files

0.2.0

2 release files

0.0.2

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page