Pocket ID
Connect Windshift to Pocket ID for single sign-on using OpenID Connect.
Prerequisites
- A running Windshift instance with admin access.
- A running Pocket ID instance with admin access.
Step 1: Open SSO Configuration in Windshift
- Navigate to Admin > Single Sign-On.
- Click Add Provider.
- Enter a display name, such as "Pocket-ID". Windshift fills the slug automatically.
- Copy the Callback URL in the dialog.
Step 2: Create an OIDC Client in Pocket ID
- In Pocket ID admin, go to OIDC Clients and click Create.
- Enter a name, such as "Windshift".
- Paste the Windshift Callback URL into the Callback URLs field.
- Leave the other fields at their defaults.
- Click Save.
- Copy the Client ID and Client Secret.
Step 3: Complete Windshift Configuration
- In the Windshift SSO dialog, paste the Client ID and Client Secret.
- Set the Issuer URL to your Pocket ID instance URL, such as
https://id.example.com. - Leave Scopes as
openid email profile. - Set the checkboxes you need:
- Enable provider: Makes the provider available on the login page.
- Auto-provision: Creates accounts for new users automatically.
- Allow password login: Lets provisioned users set a password.
- Trust IdP email verification: Skips Windshift email verification.
- Click Save Changes.
Step 4: Mark Email as Trusted in Pocket ID
- In Pocket ID admin, go to Users and select the user.
- Click the green icon next to the Email field to mark the email as trusted.
- Do this when Trust IdP email verification is enabled in Windshift.
Test the Connection
- In the Windshift SSO dialog, click Test Connection to verify the configuration.
- Or sign out and use Sign in with Pocket-ID on the login page.