Skip to main content

Girder OIDC Plugin

A Girder plugin for OpenID Connect (OIDC) authentication via Keycloak.

Features

  • OIDC/Keycloak integration with automatic user creation
  • Admin panel configuration
  • Secure token exchange using authorization code flow
  • Automatic OIDC endpoint discovery

Installation

pip install -e .

Configuration

In the Girder admin panel, go to OIDC/Keycloak Configuration and set:

  • Keycloak URL (Internal): Internal URL for server communication (e.g., https://keycloak:8443)
  • Keycloak Public URL: Public URL for browser redirects (e.g., https://localhost:8443)
  • Keycloak Realm: Realm name (e.g., girder)
  • Client ID: OIDC client ID
  • Client Secret: OIDC client secret
  • Enable OIDC: Enable authentication
  • Auto Create Users: Create Girder users automatically
  • Allow Registration: Allow new user registration

Keycloak Setup

  1. Create an OIDC client in Keycloak:

    • Access Type: confidential
    • Valid Redirect URIs: https://your-girder-host/api/v1/oidc/callback
  2. Copy the client credentials to Girder configuration

API Endpoints

  • GET /api/v1/oidc/configuration - Get config (admin only)
  • PUT /api/v1/oidc/configuration - Update config (admin only)
  • GET /api/v1/oidc/login?redirect=URL - Get authorization URL
  • GET /api/v1/oidc/callback - Callback from Keycloak

Development

pytest plugin_tests/

Issues

When using Girder behind a reverse proxy, the https scheme is not returned by the "getApiUrl" function using default settings. For the redirect address to be valid, you need to manually set the base address of the server (with https) in the admin -> advanced settings panel.

License

Apache 2.0

Metadata

Release files for girder-oidc 0.4.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for girder-oidc 0.4.1
File Size Uploaded
girder_oidc-0.4.1.tar.gz 25.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for girder-oidc 0.4.1
File Interpreter ABI Platform
girder_oidc-0.4.1-py3-none-any.whl Python 3 none any Details

Total release size: 53.7 kB

Release files / girder_oidc-0.4.1.tar.gz

Download URL girder_oidc-0.4.1.tar.gz
Size 25.7 kB
Tags Source
SHA-256 checksum
How to use checksums
58be426248b9d389b6e54d3137b5fe6a77a7eed9e198f781928edf22d656fcb8
BLAKE2b-256 checksum
How to use checksums
f6490dedce01651d528868bd92b84147816b3f04a6d232949edf1bf6efe3fbdd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.0

Release files / girder_oidc-0.4.1-py3-none-any.whl

Download URL girder_oidc-0.4.1-py3-none-any.whl
Size 28.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
a449d6531841d34406c7957bca57c80707439fb28748f7e874e1c46d683e06d4
BLAKE2b-256 checksum
How to use checksums
a1fc22e772b5cd21ebdcb2bccdf4250ea462e8392d3efc45a3baf4f3b6253b76
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.0

Release history Release notifications | RSS feed

0.5.0

2 release files

This release

0.4.1 This release

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.0.2

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page