authentik
Connect Windshift to authentik for single sign-on using OpenID Connect.
Prerequisites
- A running Windshift instance with admin access.
- A running authentik instance with admin access.
Step 1: Open SSO Configuration in Windshift
- Navigate to Admin > Single Sign-On.
- Click Add Provider.
- Enter a display name, such as "authentik". Windshift fills the slug automatically.
- Copy the Callback URL in the dialog.
Step 2: Create an OAuth2/OpenID Provider in authentik
- In authentik admin, go to Applications > Providers and click Create.
- Select OAuth2/OpenID Provider and click Next.
- Enter a name, such as "Windshift".
- Set Client type to Confidential.
- Paste the Windshift Callback URL into the Redirect URIs field.
- Click Finish.
- Copy the Client ID and Client Secret on the provider detail page.
Step 3: Create an Application in authentik
- Go to Applications > Applications and click Create.
- Enter a name, such as "Windshift", and note the slug, such as
windshift. - Select the provider you created from the Provider dropdown.
- Click Create.
Step 4: Complete Windshift Configuration
- In the Windshift SSO dialog, paste the Client ID and Client Secret.
- Set the Issuer URL to
https://auth.example.com/application/o/<app-slug>/. Replaceauth.example.comwith your authentik domain. Replace<app-slug>with the application slug from Step 3. Include the trailing slash. - Leave Scopes as
openid email profile. - Set the checkboxes you need:
- Enable provider: Makes the provider available on the login page.
- Auto-provision: Creates accounts for new users automatically.
- Allow password login: Lets provisioned users set a password.
- Trust IdP email verification: Skips Windshift email verification.
- Click Save Changes.
Test the Connection
- In the Windshift SSO dialog, click Test Connection to verify the configuration.
- Or sign out and use Sign in with authentik on the login page.