Skip to main content

Girder OIDC Plugin

A Girder plugin for OpenID Connect (OIDC) authentication via Keycloak.

Features

  • OIDC/Keycloak integration with automatic user creation
  • Admin panel configuration
  • Secure token exchange using authorization code flow
  • Automatic OIDC endpoint discovery

Installation

pip install -e .

Configuration

In the Girder admin panel, go to OIDC/Keycloak Configuration and set:

  • Keycloak URL (Internal): Internal URL for server communication (e.g., https://keycloak:8443)
  • Keycloak Public URL: Public URL for browser redirects (e.g., https://localhost:8443)
  • Keycloak Realm: Realm name (e.g., girder)
  • Client ID: OIDC client ID
  • Client Secret: OIDC client secret
  • Enable OIDC: Enable authentication
  • Auto Create Users: Create Girder users automatically
  • Allow Registration: Allow new user registration

Keycloak Setup

  1. Create an OIDC client in Keycloak:

    • Access Type: confidential
    • Valid Redirect URIs: https://your-girder-host/api/v1/oidc/callback
  2. Copy the client credentials to Girder configuration

API Endpoints

  • GET /api/v1/oidc/configuration - Get config (admin only)
  • PUT /api/v1/oidc/configuration - Update config (admin only)
  • GET /api/v1/oidc/login?redirect=URL - Get authorization URL
  • GET /api/v1/oidc/callback - Callback from Keycloak

Development

pytest plugin_tests/

Issues

When using Girder behind a reverse proxy, the https scheme is not returned by the "getApiUrl" function using default settings. For the redirect address to be valid, you need to manually set the base address of the server (with https) in the admin -> advanced settings panel.

License

Apache 2.0

Metadata

Release files for girder-oidc 0.4.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for girder-oidc 0.4.0
File Size Uploaded
girder_oidc-0.4.0.tar.gz 25.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for girder-oidc 0.4.0
File Interpreter ABI Platform
girder_oidc-0.4.0-py3-none-any.whl Python 3 none any Details

Total release size: 53.0 kB

Release files / girder_oidc-0.4.0.tar.gz

Download URL girder_oidc-0.4.0.tar.gz
Size 25.4 kB
Tags Source
SHA-256 checksum
How to use checksums
295d8a7f6b10bf9707542d1054fa9cc4911e8c43482add7cb10dd1f77c8a20ed
BLAKE2b-256 checksum
How to use checksums
68ada7d4929718d0dc30c0c971e2e923c4d2efe6f96f8c7d4637d88ee83db642
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.0

Release files / girder_oidc-0.4.0-py3-none-any.whl

Download URL girder_oidc-0.4.0-py3-none-any.whl
Size 27.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
8e8d5087c0befd92e77359da81919deceaf472bac47e9ae425a00eb8c14e9a36
BLAKE2b-256 checksum
How to use checksums
21614515d6bc8217289ed8e56bbe275a1d2a9b999790229eb062fd9dd2d26bc3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.0

Release history Release notifications | RSS feed

0.5.0

2 release files

0.4.1

2 release files

This release

0.4.0 This release

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.0.2

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page