Girder OIDC Plugin
A Girder plugin for OpenID Connect (OIDC) authentication via Keycloak.
Features
- OIDC/Keycloak integration with automatic user creation
- Admin panel configuration
- Secure token exchange using authorization code flow
- Automatic OIDC endpoint discovery
Installation
pip install -e .
Configuration
In the Girder admin panel, go to OIDC/Keycloak Configuration and set:
- Keycloak URL (Internal): Internal URL for server communication (e.g.,
https://keycloak:8443) - Keycloak Public URL: Public URL for browser redirects (e.g.,
https://localhost:8443) - Keycloak Realm: Realm name (e.g.,
girder) - Client ID: OIDC client ID
- Client Secret: OIDC client secret
- Enable OIDC: Enable authentication
- Auto Create Users: Create Girder users automatically
- Allow Registration: Allow new user registration
Keycloak Setup
-
Create an OIDC client in Keycloak:
- Access Type:
confidential - Valid Redirect URIs:
https://your-girder-host/api/v1/oidc/callback
- Access Type:
-
Copy the client credentials to Girder configuration
API Endpoints
GET /api/v1/oidc/configuration- Get config (admin only)PUT /api/v1/oidc/configuration- Update config (admin only)GET /api/v1/oidc/login?redirect=URL- Get authorization URLGET /api/v1/oidc/callback- Callback from Keycloak
Development
pytest plugin_tests/
Issues
When using Girder behind a reverse proxy, the https scheme is not returned by the "getApiUrl" function using default settings. For the redirect address to be valid, you need to manually set the base address of the server (with https) in the admin -> advanced settings panel.
License
Apache 2.0
Metadata
Release files for girder-oidc 0.4.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| girder_oidc-0.4.1.tar.gz | 25.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| girder_oidc-0.4.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 53.7 kB
Release files / girder_oidc-0.4.1.tar.gz
| Download URL | girder_oidc-0.4.1.tar.gz |
|---|---|
| Size | 25.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
58be426248b9d389b6e54d3137b5fe6a77a7eed9e198f781928edf22d656fcb8
|
|
BLAKE2b-256 checksum How to use checksums |
f6490dedce01651d528868bd92b84147816b3f04a6d232949edf1bf6efe3fbdd
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.14.0
|
Release files / girder_oidc-0.4.1-py3-none-any.whl
| Download URL | girder_oidc-0.4.1-py3-none-any.whl |
|---|---|
| Size | 28.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
a449d6531841d34406c7957bca57c80707439fb28748f7e874e1c46d683e06d4
|
|
BLAKE2b-256 checksum How to use checksums |
a1fc22e772b5cd21ebdcb2bccdf4250ea462e8392d3efc45a3baf4f3b6253b76
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.14.0
|