mirror of
https://github.com/Lissy93/dashy.git
synced 2026-08-02 04:26:12 -04:00
255 lines
94 KiB
HTML
255 lines
94 KiB
HTML
<!doctype html>
|
||
<html lang="en" dir="ltr" class="docs-wrapper plugin-docs plugin-id-default docs-version-current docs-doc-page docs-doc-id-authentication/authentik" data-has-hydrated="false">
|
||
<head>
|
||
<meta charset="UTF-8">
|
||
<meta name="generator" content="Docusaurus v3.10.1">
|
||
<title data-rh="true">Authentik OIDC | Dashy</title><meta data-rh="true" name="viewport" content="width=device-width,initial-scale=1"><meta data-rh="true" property="og:locale" content="en"><meta data-rh="true" name="docusaurus_locale" content="en"><meta data-rh="true" name="docsearch:language" content="en"><meta data-rh="true" name="keywords" content="dashy, dashboard, homelab, self-hosted, docker, homepage"><meta data-rh="true" property="og:type" content="website"><meta data-rh="true" property="og:url" content="https://dashy.to"><meta data-rh="true" property="og:image" content="https://dashy.to/img/dashy.png"><meta data-rh="true" name="twitter:card" content="summary_large_image"><meta data-rh="true" name="twitter:title" content="Dashy — The Ultimate Homepage for your Homelab"><meta data-rh="true" name="twitter:description" content="Dashy is a self-hosted dashboard app for your homelab. Manage all your services, with status checks, widgets, themes and more."><meta data-rh="true" name="twitter:image" content="https://dashy.to/img/dashy.png"><meta data-rh="true" name="docusaurus_version" content="current"><meta data-rh="true" name="docusaurus_tag" content="docs-default-current"><meta data-rh="true" name="docsearch:version" content="current"><meta data-rh="true" name="docsearch:docusaurus_tag" content="docs-default-current"><meta data-rh="true" property="og:title" content="Authentik OIDC | Dashy"><meta data-rh="true" name="description" content="Dashy supports using Authentik as its OIDC provider."><meta data-rh="true" property="og:description" content="Dashy supports using Authentik as its OIDC provider."><link data-rh="true" rel="icon" href="/img/favicon.ico"><link data-rh="true" rel="canonical" href="https://dashy.to/docs/authentication/authentik"><link data-rh="true" rel="alternate" href="https://dashy.to/docs/authentication/authentik" hreflang="en"><link data-rh="true" rel="alternate" href="https://dashy.to/docs/authentication/authentik" hreflang="x-default"><script data-rh="true" type="application/ld+json">{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Authentication","item":"https://dashy.to/docs/authentication"},{"@type":"ListItem","position":2,"name":"Authentik OIDC","item":"https://dashy.to/docs/authentication/authentik"}]}</script><link rel="preconnect" href="https://pixelflare.cc">
|
||
<link rel="preconnect" href="https://cdn.as93.net">
|
||
<link rel="dns-prefetch" href="https://api.github.com">
|
||
<link rel="dns-prefetch" href="https://no-track.as93.net">
|
||
<script type="application/ld+json">{"@context":"https://schema.org","@type":"WebSite","name":"Dashy","url":"https://dashy.to","description":"The Ultimate Homepage for your Homelab","publisher":{"@type":"Person","name":"Alicia Sykes","url":"https://aliciasykes.com"}}</script>
|
||
<link rel="manifest" href="/manifest.json">
|
||
<link rel="alternate" type="application/rss+xml" title="Dashy — Releases & Updates" href="/rss.xml">
|
||
<meta name="theme-color" content="#54bff7">
|
||
<script src="https://no-track.as93.net/js/script.js" defer="defer" data-domain="dashy.to"></script><link rel="stylesheet" href="/assets/css/styles.283a0681.css">
|
||
<script src="/assets/js/runtime~main.17c323d8.js" defer="defer"></script>
|
||
<script src="/assets/js/main.249792b4.js" defer="defer"></script>
|
||
</head>
|
||
<body>
|
||
<svg style="display: none;"><defs>
|
||
<symbol id="theme-svg-external-link" viewBox="0 0 24 24"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"/></symbol>
|
||
</defs></svg>
|
||
<script>!function(){var t=function(){try{return new URLSearchParams(window.location.search).get("docusaurus-theme")}catch(t){}}()||function(){try{return window.localStorage.getItem("theme")}catch(t){}}();document.documentElement.setAttribute("data-theme",t||"dark"),document.documentElement.setAttribute("data-theme-choice",t||"dark")}(),function(){try{const c=new URLSearchParams(window.location.search).entries();for(var[t,e]of c)if(t.startsWith("docusaurus-data-")){var a=t.replace("docusaurus-data-","data-");document.documentElement.setAttribute(a,e)}}catch(t){}}()</script><div id="__docusaurus"><div class="banner_woPo"><a class="link_ecgS" title="View the changelog, to see what's new!" href="/updates">Dashy <!-- -->V4.3.15<!-- --> is now live 🚀</a><a class="link2_y3x6" title="View the changelog, to see what's new!" href="/updates">See what's new…</a><button class="closeBtn_fC0A" title="Dismiss update, and don't show again" aria-label="Dismiss update, and don't show again">×</button></div><div role="region" aria-label="Skip to main content"><a class="skipToContent_fXgn" href="#__docusaurus_skipToContent_fallback">Skip to main content</a></div><nav aria-label="Main" class="theme-layout-navbar navbar navbar--fixed-top"><div class="navbar__inner"><div class="theme-layout-navbar-left navbar__items"><button aria-label="Toggle navigation bar" aria-expanded="false" class="navbar__toggle clean-btn" type="button"><svg width="30" height="30" viewBox="0 0 30 30" aria-hidden="true"><path stroke="currentColor" stroke-linecap="round" stroke-miterlimit="10" stroke-width="2" d="M4 7h22M4 15h22M4 23h22"></path></svg></button><a class="navbar__brand" href="/"><div class="navbar__logo"><img src="/img/dashy.png" alt="Dashy Logo" class="themedComponent_mlkZ themedComponent--light_NVdE"><img src="/img/dashy.png" alt="Dashy Logo" class="themedComponent_mlkZ themedComponent--dark_xIcU"></div><b class="navbar__title text--truncate">Dashy</b></a><a href="https://github.com/lissy93/dashy" target="_blank" rel="noopener noreferrer" class="navbar__item navbar__link">GitHub<svg width="13.5" height="13.5" aria-label="(opens in new tab)" class="iconExternalLink_nPIU"><use href="#theme-svg-external-link"></use></svg></a><a href="https://demo.dashy.to" target="_blank" rel="noopener noreferrer" class="navbar__item navbar__link">Live Demo<svg width="13.5" height="13.5" aria-label="(opens in new tab)" class="iconExternalLink_nPIU"><use href="#theme-svg-external-link"></use></svg></a><a class="navbar__item navbar__link" href="/docs/quick-start">Quick Start</a><a aria-current="page" class="navbar__item navbar__link navbar__link--active" href="/docs">Documentation</a><a class="navbar__item navbar__link" href="/api">API</a><a class="navbar__item navbar__link" href="/updates">Changelog</a></div><div class="theme-layout-navbar-right navbar__items navbar__items--right"><div class="toggle_vylO colorModeToggle_DEke"><button class="clean-btn toggleButton_gllP toggleButtonDisabled_aARS" type="button" disabled="" title="system mode" aria-label="Switch between dark and light mode (currently system mode)"><svg viewBox="0 0 24 24" width="24" height="24" aria-hidden="true" class="toggleIcon_g3eP lightToggleIcon_pyhR"><path fill="currentColor" d="M12,9c1.65,0,3,1.35,3,3s-1.35,3-3,3s-3-1.35-3-3S10.35,9,12,9 M12,7c-2.76,0-5,2.24-5,5s2.24,5,5,5s5-2.24,5-5 S14.76,7,12,7L12,7z M2,13l2,0c0.55,0,1-0.45,1-1s-0.45-1-1-1l-2,0c-0.55,0-1,0.45-1,1S1.45,13,2,13z M20,13l2,0c0.55,0,1-0.45,1-1 s-0.45-1-1-1l-2,0c-0.55,0-1,0.45-1,1S19.45,13,20,13z M11,2v2c0,0.55,0.45,1,1,1s1-0.45,1-1V2c0-0.55-0.45-1-1-1S11,1.45,11,2z M11,20v2c0,0.55,0.45,1,1,1s1-0.45,1-1v-2c0-0.55-0.45-1-1-1C11.45,19,11,19.45,11,20z M5.99,4.58c-0.39-0.39-1.03-0.39-1.41,0 c-0.39,0.39-0.39,1.03,0,1.41l1.06,1.06c0.39,0.39,1.03,0.39,1.41,0s0.39-1.03,0-1.41L5.99,4.58z M18.36,16.95 c-0.39-0.39-1.03-0.39-1.41,0c-0.39,0.39-0.39,1.03,0,1.41l1.06,1.06c0.39,0.39,1.03,0.39,1.41,0c0.39-0.39,0.39-1.03,0-1.41 L18.36,16.95z M19.42,5.99c0.39-0.39,0.39-1.03,0-1.41c-0.39-0.39-1.03-0.39-1.41,0l-1.06,1.06c-0.39,0.39-0.39,1.03,0,1.41 s1.03,0.39,1.41,0L19.42,5.99z M7.05,18.36c0.39-0.39,0.39-1.03,0-1.41c-0.39-0.39-1.03-0.39-1.41,0l-1.06,1.06 c-0.39,0.39-0.39,1.03,0,1.41s1.03,0.39,1.41,0L7.05,18.36z"></path></svg><svg viewBox="0 0 24 24" width="24" height="24" aria-hidden="true" class="toggleIcon_g3eP darkToggleIcon_wfgR"><path fill="currentColor" d="M9.37,5.51C9.19,6.15,9.1,6.82,9.1,7.5c0,4.08,3.32,7.4,7.4,7.4c0.68,0,1.35-0.09,1.99-0.27C17.45,17.19,14.93,19,12,19 c-3.86,0-7-3.14-7-7C5,9.07,6.81,6.55,9.37,5.51z M12,3c-4.97,0-9,4.03-9,9s4.03,9,9,9s9-4.03,9-9c0-0.46-0.04-0.92-0.1-1.36 c-0.98,1.37-2.58,2.26-4.4,2.26c-2.98,0-5.4-2.42-5.4-5.4c0-1.81,0.89-3.42,2.26-4.4C12.92,3.04,12.46,3,12,3L12,3z"></path></svg><svg viewBox="0 0 24 24" width="24" height="24" aria-hidden="true" class="toggleIcon_g3eP systemToggleIcon_QzmC"><path fill="currentColor" d="m12 21c4.971 0 9-4.029 9-9s-4.029-9-9-9-9 4.029-9 9 4.029 9 9 9zm4.95-13.95c1.313 1.313 2.05 3.093 2.05 4.95s-0.738 3.637-2.05 4.95c-1.313 1.313-3.093 2.05-4.95 2.05v-14c1.857 0 3.637 0.737 4.95 2.05z"></path></svg></button></div><div class="navbarSearchContainer_Bca1"><div class="navbar__search searchBarContainer_NW3z" dir="ltr"><input placeholder="Search" aria-label="Search" class="navbar__search-input searchInput_YFbd" value=""><div class="loadingRing_RJI3 searchBarLoadingRing_YnHq"><div></div><div></div><div></div><div></div></div></div></div></div></div><div role="presentation" class="navbar-sidebar__backdrop"></div></nav><div id="__docusaurus_skipToContent_fallback" class="theme-layout-main main-wrapper mainWrapper_z2l0"><div class="docsWrapper_hBAB"><button aria-label="Scroll back to top" class="clean-btn theme-back-to-top-button backToTopButton_sjWU" type="button"></button><div class="docRoot_UBD9"><aside class="theme-doc-sidebar-container docSidebarContainer_YfHR"><div class="sidebarViewport_aRkj"><div class="sidebar_njMd"><nav aria-label="Docs sidebar" class="menu thin-scrollbar menu_SIkG"><ul class="theme-doc-sidebar-menu menu__list"><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="categoryLink_byQd menu__link menu__link--sublist menu__link--sublist-caret" role="button" aria-expanded="false" href="/docs/quick-start"><span title="Running Dashy" class="categoryLinkLabel_W154">Running Dashy</span></a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item"><div class="menu__list-item-collapsible"><a class="categoryLink_byQd menu__link menu__link--sublist menu__link--sublist-caret menu__link--active" role="button" aria-expanded="true" href="/docs/icons"><span title="Feature Docs" class="categoryLinkLabel_W154">Feature Docs</span></a></div><ul class="menu__list"><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/docs/icons"><span title="Icons" class="linkLabel_WmDU">Icons</span></a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/docs/widgets"><span title="Widgets" class="linkLabel_WmDU">Widgets</span></a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/docs/theming"><span title="Theming" class="linkLabel_WmDU">Theming</span></a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/docs/status-indicators"><span title="Status Indicators" class="linkLabel_WmDU">Status Indicators</span></a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item"><div class="menu__list-item-collapsible"><a class="categoryLink_byQd menu__link menu__link--sublist menu__link--active" tabindex="0" href="/docs/authentication"><span title="Authentication" class="categoryLinkLabel_W154">Authentication</span></a><button aria-label="Collapse sidebar category 'Authentication'" aria-expanded="true" type="button" class="clean-btn menu__caret"></button></div><ul class="menu__list"><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link" tabindex="0" href="/docs/authentication/authelia-oidc"><span title="Authelia OIDC" class="linkLabel_WmDU">Authelia OIDC</span></a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link menu__link--active" aria-current="page" tabindex="0" href="/docs/authentication/authentik"><span title="Authentik OIDC" class="linkLabel_WmDU">Authentik OIDC</span></a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link" tabindex="0" href="/docs/authentication/built-in"><span title="Built-In Auth" class="linkLabel_WmDU">Built-In Auth</span></a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link" tabindex="0" href="/docs/authentication/cloudflare-tunnel"><span title="Cloudflare Tunnel" class="linkLabel_WmDU">Cloudflare Tunnel</span></a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link" tabindex="0" href="/docs/authentication/header-auth"><span title="Header Authentication" class="linkLabel_WmDU">Header Authentication</span></a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link" tabindex="0" href="/docs/authentication/keycloak"><span title="Keycloak" class="linkLabel_WmDU">Keycloak</span></a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link" tabindex="0" href="/docs/authentication/oidc"><span title="OIDC" class="linkLabel_WmDU">OIDC</span></a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link" tabindex="0" href="/docs/authentication/other-auth-methods"><span title="Other Auth Methods" class="linkLabel_WmDU">Other Auth Methods</span></a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link" tabindex="0" href="/docs/authentication/pocketid"><span title="Pocket ID OIDC" class="linkLabel_WmDU">Pocket ID OIDC</span></a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link" tabindex="0" href="/docs/authentication/tailscale"><span title="Tailscale" class="linkLabel_WmDU">Tailscale</span></a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link" tabindex="0" href="/docs/authentication/zitadel"><span title="Zitadel OIDC" class="linkLabel_WmDU">Zitadel OIDC</span></a></li></ul></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/docs/searching"><span title="Search & Shortcuts" class="linkLabel_WmDU">Search & Shortcuts</span></a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/docs/alternate-views"><span title="Alternate Views & Opening Methods" class="linkLabel_WmDU">Alternate Views & Opening Methods</span></a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/docs/multi-language-support"><span title="Internationalization" class="linkLabel_WmDU">Internationalization</span></a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/docs/backup-restore"><span title="Cloud Backup and Restore" class="linkLabel_WmDU">Cloud Backup and Restore</span></a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/docs/pages-and-sections"><span title="Pages and Sections" class="linkLabel_WmDU">Pages and Sections</span></a></li></ul></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="categoryLink_byQd menu__link menu__link--sublist menu__link--sublist-caret" role="button" aria-expanded="false" href="/docs/showcase"><span title="Community" class="categoryLinkLabel_W154">Community</span></a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="categoryLink_byQd menu__link menu__link--sublist menu__link--sublist-caret" role="button" aria-expanded="false" href="/docs/privacy"><span title="Misc" class="categoryLinkLabel_W154">Misc</span></a></div></li></ul></nav></div><div class="sidebar-ad"><script async="" src="//cdn.carbonads.com/carbon.js?serve=CWYIC53L&placement=dashyto" id="_carbonads_js"></script></div></div></aside><main class="docMainContainer_TBSr"><div class="container padding-top--md padding-bottom--lg"><div class="row"><div class="col docItemCol_VOVn"><div class="docItemContainer_Djhp"><article><nav class="theme-doc-breadcrumbs breadcrumbsContainer_Z_bl" aria-label="Breadcrumbs"><ul class="breadcrumbs"><li class="breadcrumbs__item"><a aria-label="Home page" class="breadcrumbs__link" href="/"><svg viewBox="0 0 24 24" class="breadcrumbHomeIcon_YNFT"><path d="M10 19v-5h4v5c0 .55.45 1 1 1h3c.55 0 1-.45 1-1v-7h1.7c.46 0 .68-.57.33-.87L12.67 3.6c-.38-.34-.96-.34-1.34 0l-8.36 7.53c-.34.3-.13.87.33.87H5v7c0 .55.45 1 1 1h3c.55 0 1-.45 1-1z" fill="currentColor"></path></svg></a></li><li class="breadcrumbs__item"><span class="breadcrumbs__link">Feature Docs</span></li><li class="breadcrumbs__item"><a class="breadcrumbs__link" href="/docs/authentication"><span>Authentication</span></a></li><li class="breadcrumbs__item breadcrumbs__item--active"><span class="breadcrumbs__link">Authentik OIDC</span></li></ul></nav><div class="tocCollapsible_ETCw theme-doc-toc-mobile tocMobile_ITEo"><button type="button" class="clean-btn tocCollapsibleButton_TO0P">On this page</button></div><div class="theme-doc-markdown markdown"><header><h1>Authentik OIDC</h1></header>
|
||
<p>Dashy supports using <a href="https://goauthentik.io/" target="_blank" rel="noopener noreferrer" class="">Authentik</a> as its OIDC provider.</p>
|
||
<p><a href="https://goauthentik.io/" target="_blank" rel="noopener noreferrer" class="">Authentik</a> is an <a href="https://github.com/goauthentik/authentik" target="_blank" rel="noopener noreferrer" class="">open source</a> identity provider that speaks OIDC, OAuth 2.0, SAML 2.0 and LDAP. It runs in Docker, has a polished admin UI, and supports MFA, social login, and per-application group policies, which makes it a good fit for self-hosted setups where you want a single login across many services.</p>
|
||
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="contents">Contents<a href="#contents" class="hash-link" aria-label="Direct link to Contents" title="Direct link to Contents" translate="no"></a></h3>
|
||
<ul>
|
||
<li class=""><a href="#1-deploy-authentik" class="">1. Deploy Authentik</a></li>
|
||
<li class=""><a href="#2-configure-authentik" class="">2. Configure Authentik</a>
|
||
<ul>
|
||
<li class=""><a href="#create-the-groups-scope" class="">Create the groups scope</a></li>
|
||
<li class=""><a href="#create-the-oidc-provider" class="">Create the OIDC provider</a></li>
|
||
<li class=""><a href="#create-the-application" class="">Create the application</a></li>
|
||
<li class=""><a href="#create-the-admin-group" class="">Create the admin group</a></li>
|
||
<li class=""><a href="#create-test-users" class="">Create test users</a></li>
|
||
<li class=""><a href="#restrict-who-can-access-dashy-optional" class="">Restrict who can access Dashy (optional)</a></li>
|
||
</ul>
|
||
</li>
|
||
<li class=""><a href="#3-enabling-authentik-in-dashy" class="">3. Enabling Authentik in Dashy</a></li>
|
||
<li class=""><a href="#4-groups-and-visibility" class="">4. Groups and Visibility</a></li>
|
||
<li class=""><a href="#5-silent-token-renewal-optional" class="">5. Silent token renewal (optional)</a></li>
|
||
<li class=""><a href="#troubleshooting-common-authentik-issues" class="">Troubleshooting</a></li>
|
||
<li class=""><a href="#config-example" class="">Config Example</a></li>
|
||
<li class=""><a href="#how-it-works" class="">How it Works</a></li>
|
||
</ul>
|
||
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="1-deploy-authentik">1. Deploy Authentik<a href="#1-deploy-authentik" class="hash-link" aria-label="Direct link to 1. Deploy Authentik" title="Direct link to 1. Deploy Authentik" translate="no"></a></h2>
|
||
<p>If you've not already done so, spin up an Authentik instance, following the <a href="https://docs.goauthentik.io/docs/install-config/install/docker-compose" target="_blank" rel="noopener noreferrer" class="">official docs</a>. The compose file below is a minimal local setup.</p>
|
||
<p>A <code>.env</code> file alongside the compose file (generate fresh secrets with <code>openssl rand -hex 32</code>):</p>
|
||
<div class="language-env codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#F8F8F2;--prism-background-color:#282A36"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-env codeBlock_bY9V thin-scrollbar" style="color:#F8F8F2;background-color:#282A36"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#F8F8F2"><span class="token plain">AUTHENTIK_TAG=2024.12</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain">PG_PASS=replace-me-with-random-hex</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain">AUTHENTIK_SECRET_KEY=replace-me-with-random-hex</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain">AUTHENTIK_BOOTSTRAP_PASSWORD=change-me-now</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain">AUTHENTIK_BOOTSTRAP_EMAIL=you@example.com</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain">AUTHENTIK_BOOTSTRAP_TOKEN=replace-me-with-random-hex</span><br></div></code></pre></div></div>
|
||
<p><code>AUTHENTIK_TAG</code> pins the Authentik version. <code>2024.12</code> is a tested baseline; any <code>2024.10</code>+ release works too (the Invalidation flow field below needs 2024.10 or newer).</p>
|
||
<details class="details_lb9f alert alert--info details_b_Ee" data-collapsed="true"><summary>Example <code>docker-compose.yml</code></summary><div><div class="collapsibleContent_i85q">
|
||
<!-- -->
|
||
<div class="language-yaml codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#F8F8F2;--prism-background-color:#282A36"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-yaml codeBlock_bY9V thin-scrollbar" style="color:#F8F8F2;background-color:#282A36"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#F8F8F2"><span class="token key atrule">name</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> authentik</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"></span><span class="token key atrule">services</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">postgresql</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">image</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> docker.io/library/postgres</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain">16</span><span class="token punctuation" style="color:rgb(248, 248, 242)">-</span><span class="token plain">alpine</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">restart</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> unless</span><span class="token punctuation" style="color:rgb(248, 248, 242)">-</span><span class="token plain">stopped</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">healthcheck</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">test</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> </span><span class="token punctuation" style="color:rgb(248, 248, 242)">[</span><span class="token string" style="color:rgb(255, 121, 198)">"CMD-SHELL"</span><span class="token punctuation" style="color:rgb(248, 248, 242)">,</span><span class="token plain"> </span><span class="token string" style="color:rgb(255, 121, 198)">"pg_isready -d $${POSTGRES_DB} -U $${POSTGRES_USER}"</span><span class="token punctuation" style="color:rgb(248, 248, 242)">]</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">start_period</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> 20s</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">interval</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> 10s</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">retries</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> </span><span class="token number">5</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">timeout</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> 5s</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">volumes</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token punctuation" style="color:rgb(248, 248, 242)">-</span><span class="token plain"> ./data/postgres</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain">/var/lib/postgresql/data</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">environment</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">POSTGRES_PASSWORD</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> $</span><span class="token punctuation" style="color:rgb(248, 248, 242)">{</span><span class="token plain">PG_PASS</span><span class="token punctuation" style="color:rgb(248, 248, 242)">}</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">POSTGRES_USER</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> authentik</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">POSTGRES_DB</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> authentik</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">redis</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">image</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> docker.io/library/redis</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain">7</span><span class="token punctuation" style="color:rgb(248, 248, 242)">-</span><span class="token plain">alpine</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">command</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> </span><span class="token punctuation" style="color:rgb(248, 248, 242)">-</span><span class="token punctuation" style="color:rgb(248, 248, 242)">-</span><span class="token plain">save 60 1 </span><span class="token punctuation" style="color:rgb(248, 248, 242)">-</span><span class="token punctuation" style="color:rgb(248, 248, 242)">-</span><span class="token plain">loglevel warning</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">restart</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> unless</span><span class="token punctuation" style="color:rgb(248, 248, 242)">-</span><span class="token plain">stopped</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">healthcheck</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">test</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> </span><span class="token punctuation" style="color:rgb(248, 248, 242)">[</span><span class="token string" style="color:rgb(255, 121, 198)">"CMD-SHELL"</span><span class="token punctuation" style="color:rgb(248, 248, 242)">,</span><span class="token plain"> </span><span class="token string" style="color:rgb(255, 121, 198)">"redis-cli ping | grep PONG"</span><span class="token punctuation" style="color:rgb(248, 248, 242)">]</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">start_period</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> 20s</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">interval</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> 10s</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">retries</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> </span><span class="token number">5</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">timeout</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> 3s</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">volumes</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token punctuation" style="color:rgb(248, 248, 242)">-</span><span class="token plain"> ./data/redis</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain">/data</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">server</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">image</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> ghcr.io/goauthentik/server</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain">$</span><span class="token punctuation" style="color:rgb(248, 248, 242)">{</span><span class="token plain">AUTHENTIK_TAG</span><span class="token punctuation" style="color:rgb(248, 248, 242)">}</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">restart</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> unless</span><span class="token punctuation" style="color:rgb(248, 248, 242)">-</span><span class="token plain">stopped</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">command</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> server</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">environment</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> </span><span class="token important">&authentik-env</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">AUTHENTIK_REDIS__HOST</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> redis</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">AUTHENTIK_POSTGRESQL__HOST</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> postgresql</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">AUTHENTIK_POSTGRESQL__USER</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> authentik</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">AUTHENTIK_POSTGRESQL__NAME</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> authentik</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">AUTHENTIK_POSTGRESQL__PASSWORD</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> $</span><span class="token punctuation" style="color:rgb(248, 248, 242)">{</span><span class="token plain">PG_PASS</span><span class="token punctuation" style="color:rgb(248, 248, 242)">}</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">AUTHENTIK_SECRET_KEY</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> $</span><span class="token punctuation" style="color:rgb(248, 248, 242)">{</span><span class="token plain">AUTHENTIK_SECRET_KEY</span><span class="token punctuation" style="color:rgb(248, 248, 242)">}</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">AUTHENTIK_BOOTSTRAP_PASSWORD</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> $</span><span class="token punctuation" style="color:rgb(248, 248, 242)">{</span><span class="token plain">AUTHENTIK_BOOTSTRAP_PASSWORD</span><span class="token punctuation" style="color:rgb(248, 248, 242)">}</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">AUTHENTIK_BOOTSTRAP_TOKEN</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> $</span><span class="token punctuation" style="color:rgb(248, 248, 242)">{</span><span class="token plain">AUTHENTIK_BOOTSTRAP_TOKEN</span><span class="token punctuation" style="color:rgb(248, 248, 242)">}</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">AUTHENTIK_BOOTSTRAP_EMAIL</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> $</span><span class="token punctuation" style="color:rgb(248, 248, 242)">{</span><span class="token plain">AUTHENTIK_BOOTSTRAP_EMAIL</span><span class="token punctuation" style="color:rgb(248, 248, 242)">}</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">AUTHENTIK_ERROR_REPORTING__ENABLED</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> </span><span class="token string" style="color:rgb(255, 121, 198)">"false"</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">ports</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token punctuation" style="color:rgb(248, 248, 242)">-</span><span class="token plain"> </span><span class="token string" style="color:rgb(255, 121, 198)">"9000:9000"</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token punctuation" style="color:rgb(248, 248, 242)">-</span><span class="token plain"> </span><span class="token string" style="color:rgb(255, 121, 198)">"9443:9443"</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">depends_on</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">postgresql</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> </span><span class="token punctuation" style="color:rgb(248, 248, 242)">{</span><span class="token key atrule">condition</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> service_healthy</span><span class="token punctuation" style="color:rgb(248, 248, 242)">}</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">redis</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> </span><span class="token punctuation" style="color:rgb(248, 248, 242)">{</span><span class="token key atrule">condition</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> service_healthy</span><span class="token punctuation" style="color:rgb(248, 248, 242)">}</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">worker</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">image</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> ghcr.io/goauthentik/server</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain">$</span><span class="token punctuation" style="color:rgb(248, 248, 242)">{</span><span class="token plain">AUTHENTIK_TAG</span><span class="token punctuation" style="color:rgb(248, 248, 242)">}</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">restart</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> unless</span><span class="token punctuation" style="color:rgb(248, 248, 242)">-</span><span class="token plain">stopped</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">command</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> worker</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">environment</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> </span><span class="token important">*authentik-env</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">depends_on</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">postgresql</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> </span><span class="token punctuation" style="color:rgb(248, 248, 242)">{</span><span class="token key atrule">condition</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> service_healthy</span><span class="token punctuation" style="color:rgb(248, 248, 242)">}</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">redis</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> </span><span class="token punctuation" style="color:rgb(248, 248, 242)">{</span><span class="token key atrule">condition</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> service_healthy</span><span class="token punctuation" style="color:rgb(248, 248, 242)">}</span><br></div></code></pre></div></div>
|
||
</div></div></details>
|
||
<p>Bring it up:</p>
|
||
<div class="language-bash codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#F8F8F2;--prism-background-color:#282A36"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-bash codeBlock_bY9V thin-scrollbar" style="color:#F8F8F2;background-color:#282A36"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#F8F8F2"><span class="token plain">docker compose up -d</span><br></div></code></pre></div></div>
|
||
<p>First boot runs database migrations and takes a minute or two. Once the <code>server</code> container is healthy, open <code>http://localhost:9000</code> and sign in as <code>akadmin</code> with the bootstrap password.</p>
|
||
<hr>
|
||
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="2-configure-authentik">2. Configure Authentik<a href="#2-configure-authentik" class="hash-link" aria-label="Direct link to 2. Configure Authentik" title="Direct link to 2. Configure Authentik" translate="no"></a></h2>
|
||
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="create-the-groups-scope">Create the groups scope<a href="#create-the-groups-scope" class="hash-link" aria-label="Direct link to Create the groups scope" title="Direct link to Create the groups scope" translate="no"></a></h3>
|
||
<p>Authentik doesn't expose group membership in the id_token by default. Dashy needs it for the <code>adminGroup</code> check and for the <code>showForKeycloakUsers</code> / <code>hideForKeycloakUsers</code> visibility rules.</p>
|
||
<ol>
|
||
<li class="">Go to <strong>Customization > Property Mappings</strong></li>
|
||
<li class="">Click <strong>Create > Scope Mapping</strong></li>
|
||
<li class="">Set <strong>Name</strong> to <code>groups</code></li>
|
||
<li class="">Set <strong>Scope name</strong> to <code>groups</code></li>
|
||
<li class="">Set <strong>Expression</strong> to:</li>
|
||
</ol>
|
||
<div class="language-python codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#F8F8F2;--prism-background-color:#282A36"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-python codeBlock_bY9V thin-scrollbar" style="color:#F8F8F2;background-color:#282A36"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#F8F8F2"><span class="token keyword" style="color:rgb(189, 147, 249);font-style:italic">return</span><span class="token plain"> </span><span class="token punctuation" style="color:rgb(248, 248, 242)">{</span><span class="token string" style="color:rgb(255, 121, 198)">"groups"</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> </span><span class="token punctuation" style="color:rgb(248, 248, 242)">[</span><span class="token plain">g</span><span class="token punctuation" style="color:rgb(248, 248, 242)">.</span><span class="token plain">name </span><span class="token keyword" style="color:rgb(189, 147, 249);font-style:italic">for</span><span class="token plain"> g </span><span class="token keyword" style="color:rgb(189, 147, 249);font-style:italic">in</span><span class="token plain"> request</span><span class="token punctuation" style="color:rgb(248, 248, 242)">.</span><span class="token plain">user</span><span class="token punctuation" style="color:rgb(248, 248, 242)">.</span><span class="token plain">ak_groups</span><span class="token punctuation" style="color:rgb(248, 248, 242)">.</span><span class="token builtin" style="color:rgb(189, 147, 249)">all</span><span class="token punctuation" style="color:rgb(248, 248, 242)">(</span><span class="token punctuation" style="color:rgb(248, 248, 242)">)</span><span class="token punctuation" style="color:rgb(248, 248, 242)">]</span><span class="token punctuation" style="color:rgb(248, 248, 242)">}</span><br></div></code></pre></div></div>
|
||
<ol start="6">
|
||
<li class="">Click <strong>Finish</strong></li>
|
||
</ol>
|
||
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="create-the-oidc-provider">Create the OIDC provider<a href="#create-the-oidc-provider" class="hash-link" aria-label="Direct link to Create the OIDC provider" title="Direct link to Create the OIDC provider" translate="no"></a></h3>
|
||
<ol>
|
||
<li class="">Go to <strong>Applications > Providers</strong></li>
|
||
<li class="">Click <strong>Create</strong>, pick <strong>OAuth2/OpenID Provider</strong>, click <strong>Next</strong></li>
|
||
<li class="">Set <strong>Name</strong> to <code>Dashy</code></li>
|
||
<li class="">Set <strong>Authorization flow</strong> to <code>default-provider-authorization-implicit-consent</code> (use <code>default-provider-authorization-explicit-consent</code> if you want users to confirm sign-in each time)</li>
|
||
<li class="">Set <strong>Invalidation flow</strong> to <code>default-provider-invalidation-flow</code> (required on Authentik 2024.10 and newer)</li>
|
||
<li class="">Under <strong>Protocol settings</strong>:
|
||
<ul>
|
||
<li class=""><strong>Client type</strong>: <code>Public</code></li>
|
||
<li class=""><strong>Client ID</strong>: <code>dashy</code>, or leave the auto-generated value and copy it for later</li>
|
||
<li class=""><strong>Redirect URIs</strong> with matching mode <code>Strict</code>, one URL per line. Register both the bare URL and the trailing-slash version:
|
||
<ul>
|
||
<li class=""><code>https://dashy.example.com</code></li>
|
||
<li class=""><code>https://dashy.example.com/</code></li>
|
||
</ul>
|
||
</li>
|
||
<li class=""><strong>Signing Key</strong>: the built-in <code>authentik Self-signed Certificate</code> is fine</li>
|
||
</ul>
|
||
</li>
|
||
<li class="">Expand <strong>Advanced protocol settings</strong>:
|
||
<ul>
|
||
<li class="">Add <code>openid</code>, <code>profile</code>, <code>email</code>, and the <code>groups</code> scope you just created to <strong>Selected Scopes</strong></li>
|
||
<li class="">Turn <strong>Include claims in id_token</strong> on</li>
|
||
</ul>
|
||
</li>
|
||
<li class="">Click <strong>Finish</strong></li>
|
||
</ol>
|
||
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="create-the-application">Create the application<a href="#create-the-application" class="hash-link" aria-label="Direct link to Create the application" title="Direct link to Create the application" translate="no"></a></h3>
|
||
<ol>
|
||
<li class="">Go to <strong>Applications > Applications</strong></li>
|
||
<li class="">Click <strong>Create</strong></li>
|
||
<li class="">Set <strong>Name</strong> to <code>Dashy</code></li>
|
||
<li class="">Set <strong>Slug</strong> to <code>dashy</code> (this becomes part of the issuer URL: <code><host>/application/o/<slug>/</code>)</li>
|
||
<li class="">Set <strong>Provider</strong> to the <code>Dashy</code> provider you just made</li>
|
||
<li class="">Click <strong>Create</strong></li>
|
||
</ol>
|
||
<p>Now open the <code>Dashy</code> provider again (<strong>Applications > Providers > Dashy</strong>) and copy the <strong>OpenID Configuration Issuer URL</strong> shown on the page (e.g. <code>https://auth.example.com/application/o/dashy/</code>). The provider only displays a valid URL once it's bound to an application. You'll need this for Dashy's <code>endpoint</code> setting later.</p>
|
||
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="create-the-admin-group">Create the admin group<a href="#create-the-admin-group" class="hash-link" aria-label="Direct link to Create the admin group" title="Direct link to Create the admin group" translate="no"></a></h3>
|
||
<ol>
|
||
<li class="">Go to <strong>Directory > Groups</strong></li>
|
||
<li class="">Click <strong>Create</strong></li>
|
||
<li class="">Set <strong>Name</strong> to <code>dashy-admins</code></li>
|
||
<li class="">Click <strong>Create</strong></li>
|
||
<li class="">Open the new group, click <strong>Users</strong>, and add any users who should have admin rights in Dashy</li>
|
||
</ol>
|
||
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="create-test-users">Create test users<a href="#create-test-users" class="hash-link" aria-label="Direct link to Create test users" title="Direct link to Create test users" translate="no"></a></h3>
|
||
<p>If you want separate accounts beyond <code>akadmin</code>:</p>
|
||
<ol>
|
||
<li class="">Go to <strong>Directory > Users</strong></li>
|
||
<li class="">Click <strong>Create</strong>, fill in <strong>Username</strong>, <strong>Name</strong> and <strong>Email</strong>, click <strong>Create</strong></li>
|
||
<li class="">On the new user's page, click <strong>Set password</strong>, set a password, click <strong>Update</strong></li>
|
||
<li class="">Add the user to <code>dashy-admins</code> for admin access, or leave them out for a non-admin</li>
|
||
</ol>
|
||
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="restrict-who-can-access-dashy-optional">Restrict who can access Dashy (optional)<a href="#restrict-who-can-access-dashy-optional" class="hash-link" aria-label="Direct link to Restrict who can access Dashy (optional)" title="Direct link to Restrict who can access Dashy (optional)" translate="no"></a></h3>
|
||
<p>By default any Authentik user can sign in to Dashy. To limit access to one or more groups, bind a group policy to the <code>Dashy</code> application; Authentik then denies sign-in to anyone outside those groups. This is separate from <code>adminGroup</code>, which only controls who gets admin rights inside Dashy, not who can access it at all.</p>
|
||
<ol>
|
||
<li class="">Go to <strong>Applications > Applications</strong> and open the <code>Dashy</code> application</li>
|
||
</ol>
|
||
<details class="details_lb9f alert alert--info details_b_Ee" data-collapsed="true"><summary>screenshot</summary><div><div class="collapsibleContent_i85q">
|
||
<!-- -->
|
||
<p><img decoding="async" loading="lazy" src="https://github.com/user-attachments/assets/613fafe7-881f-4664-a903-945854ac65e2" alt="Open the Dashy application" class="img_ev3q"></p>
|
||
</div></div></details>
|
||
<ol start="2">
|
||
<li class="">Open the <strong>Policy / Group / User Bindings</strong> tab and click <strong>Bind existing policy</strong></li>
|
||
</ol>
|
||
<details class="details_lb9f alert alert--info details_b_Ee" data-collapsed="true"><summary>screenshot</summary><div><div class="collapsibleContent_i85q">
|
||
<!-- -->
|
||
<p><img decoding="async" loading="lazy" src="https://github.com/user-attachments/assets/10fca15b-e77d-4624-ae03-0ece3910904c" alt="Open the bindings tab" class="img_ev3q"></p>
|
||
</div></div></details>
|
||
<ol start="3">
|
||
<li class="">Switch to the <strong>Group</strong> tab, choose the group that should have access, make sure <strong>Enabled</strong> is on, and click <strong>Create</strong></li>
|
||
</ol>
|
||
<details class="details_lb9f alert alert--info details_b_Ee" data-collapsed="true"><summary>screenshot</summary><div><div class="collapsibleContent_i85q">
|
||
<!-- -->
|
||
<p><img decoding="async" loading="lazy" src="https://github.com/user-attachments/assets/ebf680ab-696f-4c08-ae89-d73fe92b398f" alt="Bind a group to the application" class="img_ev3q"></p>
|
||
</div></div></details>
|
||
<p>Access is now limited to members of the bound group. Add another binding for each additional group that should be allowed in.</p>
|
||
<hr>
|
||
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="3-enabling-authentik-in-dashy">3. Enabling Authentik in Dashy<a href="#3-enabling-authentik-in-dashy" class="hash-link" aria-label="Direct link to 3. Enabling Authentik in Dashy" title="Direct link to 3. Enabling Authentik in Dashy" translate="no"></a></h2>
|
||
<p>Finally, you need to tell Dashy to use Authentik. This goes in the <code>appConfig.auth</code> section of your main <code>/user-data/conf.yml</code>.</p>
|
||
<div class="language-yaml codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#F8F8F2;--prism-background-color:#282A36"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-yaml codeBlock_bY9V thin-scrollbar" style="color:#F8F8F2;background-color:#282A36"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#F8F8F2"><span class="token key atrule">appConfig</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token punctuation" style="color:rgb(248, 248, 242)">...</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">disableConfigurationForNonAdmin</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> </span><span class="token boolean important">true</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">auth</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">enableOidc</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> </span><span class="token boolean important">true</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">oidc</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">clientId</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> dashy</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">endpoint</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> https</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain">//auth.example.com/application/o/dashy/</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">adminGroup</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> dashy</span><span class="token punctuation" style="color:rgb(248, 248, 242)">-</span><span class="token plain">admins</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">scope</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> openid profile email groups</span><br></div></code></pre></div></div>
|
||
<p>Where:</p>
|
||
<ul>
|
||
<li class=""><code>disableConfigurationForNonAdmin</code> - Prevent read/write config access to non-admin users</li>
|
||
<li class=""><code>auth.enableOidc</code> - Set the auth mode to OIDC</li>
|
||
<li class=""><code>clientId</code> - The Client ID from the Authentik provider (exact, case-sensitive)</li>
|
||
<li class=""><code>endpoint</code> - The OpenID Configuration Issuer URL from the provider page. Use the bare issuer, not the discovery URL; Dashy appends <code>/.well-known/openid-configuration</code> itself</li>
|
||
<li class=""><code>adminGroup</code> - Name of the Authentik group that grants admin in Dashy (matches the <code>dashy-admins</code> group above). To use roles instead, set <code>adminRole</code>, but Authentik has no <code>roles</code> claim by default, so groups are the simpler path here</li>
|
||
<li class=""><code>scope</code> - Space-separated list of scopes to request. Must include <code>groups</code> when <code>adminGroup</code> is set, otherwise the id_token won't carry the claim</li>
|
||
</ul>
|
||
<p>To let visitors view a read-only dashboard without signing in, add <code>enableGuestAccess: true</code> under <code>auth</code>; they skip the Authentik login, and admins still get edit access after signing in. See <a class="" href="/docs/oidc#guest-access">guest access</a> for the details.</p>
|
||
<p>Restart Dashy for these changes to take effect.</p>
|
||
<p>If Authentik runs on a different host or behind a reverse proxy, make sure <code>endpoint</code> is reachable from inside the Dashy container, and that the issuer URL the provider advertises matches <code>endpoint</code> exactly.</p>
|
||
<p>Everything should now be fully configured and working 🎉
|
||
When you load Dashy, you'll be redirected to Authentik's login page. After signing in you will land back on Dashy's homepage with full access, and all of Dashy's client, server and asset endpoints will be locked behind authentication.</p>
|
||
<hr>
|
||
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="4-groups-and-visibility">4. Groups and Visibility<a href="#4-groups-and-visibility" class="hash-link" aria-label="Direct link to 4. Groups and Visibility" title="Direct link to 4. Groups and Visibility" translate="no"></a></h2>
|
||
<p>Once group membership is in the id_token, you can use it to hide or show pages, sections and items in Dashy. The property name is <code>hideForKeycloakUsers</code> / <code>showForKeycloakUsers</code> (the name is historical; it works for any OIDC provider, including Authentik).</p>
|
||
<p>To make an Admin section visible only to members of <code>dashy-admins</code>:</p>
|
||
<div class="language-yaml codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#F8F8F2;--prism-background-color:#282A36"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-yaml codeBlock_bY9V thin-scrollbar" style="color:#F8F8F2;background-color:#282A36"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#F8F8F2"><span class="token key atrule">displayData</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">showForKeycloakUsers</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">groups</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token punctuation" style="color:rgb(248, 248, 242)">-</span><span class="token plain"> dashy</span><span class="token punctuation" style="color:rgb(248, 248, 242)">-</span><span class="token plain">admins</span><br></div></code></pre></div></div>
|
||
<p>Both <code>showForKeycloakUsers</code> and <code>hideForKeycloakUsers</code> accept lists of <code>groups</code> and <code>roles</code>. If a user matches an entry they're allowed or excluded as defined.</p>
|
||
<div class="language-yaml codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#F8F8F2;--prism-background-color:#282A36"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-yaml codeBlock_bY9V thin-scrollbar" style="color:#F8F8F2;background-color:#282A36"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#F8F8F2"><span class="token key atrule">sections</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token punctuation" style="color:rgb(248, 248, 242)">-</span><span class="token plain"> </span><span class="token key atrule">name</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> Internal Tools</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">displayData</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">showForKeycloakUsers</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">groups</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> </span><span class="token punctuation" style="color:rgb(248, 248, 242)">[</span><span class="token string" style="color:rgb(255, 121, 198)">'dashy-admins'</span><span class="token punctuation" style="color:rgb(248, 248, 242)">]</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">hideForKeycloakUsers</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">groups</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> </span><span class="token punctuation" style="color:rgb(248, 248, 242)">[</span><span class="token string" style="color:rgb(255, 121, 198)">'guests'</span><span class="token punctuation" style="color:rgb(248, 248, 242)">]</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">items</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token punctuation" style="color:rgb(248, 248, 242)">-</span><span class="token plain"> </span><span class="token key atrule">title</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> Hidden from interns</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">displayData</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">hideForKeycloakUsers</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">groups</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> </span><span class="token punctuation" style="color:rgb(248, 248, 242)">[</span><span class="token string" style="color:rgb(255, 121, 198)">'interns'</span><span class="token punctuation" style="color:rgb(248, 248, 242)">]</span><br></div></code></pre></div></div>
|
||
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="5-silent-token-renewal-optional">5. Silent token renewal (optional)<a href="#5-silent-token-renewal-optional" class="hash-link" aria-label="Direct link to 5. Silent token renewal (optional)" title="Direct link to 5. Silent token renewal (optional)" translate="no"></a></h2>
|
||
<p>By default, when your token expires Dashy sends you back through Authentik's login to get a new one. Set <code>enableSilentRenew: true</code> to have Dashy refresh the session quietly in the background instead, using a refresh token:</p>
|
||
<div class="language-yaml codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#F8F8F2;--prism-background-color:#282A36"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-yaml codeBlock_bY9V thin-scrollbar" style="color:#F8F8F2;background-color:#282A36"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">oidc</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">clientId</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> dashy</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">endpoint</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> https</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain">//auth.example.com/application/o/dashy/</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">adminGroup</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> dashy</span><span class="token punctuation" style="color:rgb(248, 248, 242)">-</span><span class="token plain">admins</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">scope</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> openid profile email groups</span><br></div><div class="token-line" style="color:#F8F8F2"><span class="token plain"> </span><span class="token key atrule">enableSilentRenew</span><span class="token punctuation" style="color:rgb(248, 248, 242)">:</span><span class="token plain"> </span><span class="token boolean important">true</span><br></div></code></pre></div></div>
|
||
<p>Dashy adds the <code>offline_access</code> scope to its request automatically. Authentik ships an <code>offline_access</code> scope mapping by default, so just make sure it's listed under the provider's <strong>Advanced protocol settings > Selected Scopes</strong>. It's off by default, and if a refresh ever fails Dashy falls back to the normal sign-in. See <a class="" href="/docs/oidc#silent-token-renewal">silent token renewal</a> for the full notes and caveats.</p>
|
||
<p>How often renewal fires is set by the provider's <strong>Access Token validity</strong> (and <strong>Refresh Token validity</strong>) under <strong>Advanced protocol settings</strong> in Authentik; the defaults suit most people.</p>
|
||
<hr>
|
||
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="troubleshooting-common-authentik-issues">Troubleshooting common Authentik Issues<a href="#troubleshooting-common-authentik-issues" class="hash-link" aria-label="Direct link to Troubleshooting common Authentik Issues" title="Direct link to Troubleshooting common Authentik Issues" translate="no"></a></h2>
|
||
<p>Two places will tell you what went wrong. Client-side problems, like a token Dashy can't use or a renewal that didn't take, are logged to the browser console tagged <code>SSO</code> or <code>OIDC</code>, so open your browser's DevTools and check the Console tab. Token verification failures show up in the Dashy server logs instead. Check whichever fits what you're seeing.</p>
|
||
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="migrations-still-running-on-first-boot">Migrations still running on first boot<a href="#migrations-still-running-on-first-boot" class="hash-link" aria-label="Direct link to Migrations still running on first boot" title="Direct link to Migrations still running on first boot" translate="no"></a></h4>
|
||
<p>Problem: Authentik returns 502 or never reaches the login page right after <code>docker compose up</code>.<br>
|
||
Solution: First boot runs database migrations and can take a minute or two. Tail the logs with <code>docker compose logs -f server</code> and wait for the <code>uvicorn</code> startup line before opening the UI.</p>
|
||
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="redirect-loop-after-login">Redirect loop after login<a href="#redirect-loop-after-login" class="hash-link" aria-label="Direct link to Redirect loop after login" title="Direct link to Redirect loop after login" translate="no"></a></h4>
|
||
<p>Problem: Browser bounces between Dashy and Authentik repeatedly.<br>
|
||
Solution: <code>endpoint</code> in <code>conf.yml</code> probably includes <code>.well-known/openid-configuration</code>. Drop everything from <code>.well-known</code> onwards; Dashy appends it itself.</p>
|
||
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="invalid_redirect_uri">invalid_redirect_uri<a href="#invalid_redirect_uri" class="hash-link" aria-label="Direct link to invalid_redirect_uri" title="Direct link to invalid_redirect_uri" translate="no"></a></h4>
|
||
<p>Problem: Authentik shows "invalid redirect URI" after submitting credentials.<br>
|
||
Solution: The URL Dashy is being served from doesn't exactly match what's registered on the provider. Register both the bare URL and the trailing-slash variant (e.g. <code>https://dashy.example.com</code> and <code>https://dashy.example.com/</code>), keep matching mode on <code>Strict</code>, and make sure the scheme matches (<code>http</code> vs <code>https</code>).</p>
|
||
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="logged-in-but-config-saves-return-403">Logged in but config saves return 403<a href="#logged-in-but-config-saves-return-403" class="hash-link" aria-label="Direct link to Logged in but config saves return 403" title="Direct link to Logged in but config saves return 403" translate="no"></a></h4>
|
||
<p>Problem: User authenticates fine, but saving the dashboard returns 403.<br>
|
||
Solution: The id_token isn't carrying the group claim. Paste the token (from localStorage, key <code>idToken</code>) into <a href="https://jwt.io" target="_blank" rel="noopener noreferrer" class="">jwt.io</a> and look for <code>groups</code>. If it's missing, the <code>groups</code> scope mapping isn't attached to the provider's <strong>Selected Scopes</strong> or <strong>Include claims in id_token</strong> is off. If the claim is there but the user isn't in it, add them to the <code>dashy-admins</code> group.</p>
|
||
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="issuer-mismatch-behind-a-reverse-proxy">Issuer mismatch behind a reverse proxy<a href="#issuer-mismatch-behind-a-reverse-proxy" class="hash-link" aria-label="Direct link to Issuer mismatch behind a reverse proxy" title="Direct link to Issuer mismatch behind a reverse proxy" translate="no"></a></h4>
|
||
<p>Problem: Server logs show <code>unexpected "iss" claim value</code>. The browser reaches Authentik over HTTPS, but Authentik advertises an HTTP issuer in its discovery document.<br>
|
||
Solution: Set <code>AUTHENTIK_LISTEN__TRUSTED_PROXY_CIDRS</code> on the Authentik server and worker containers to include your proxy's IP range (e.g. <code>172.16.0.0/12</code> for default Docker bridges), and make sure the proxy forwards <code>X-Forwarded-Proto: https</code>. Once Authentik trusts the proxy, its discovery document will advertise the public HTTPS URL.</p>
|
||
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="audience-mismatch-on-token-verification">Audience mismatch on token verification<a href="#audience-mismatch-on-token-verification" class="hash-link" aria-label="Direct link to Audience mismatch on token verification" title="Direct link to Audience mismatch on token verification" translate="no"></a></h4>
|
||
<p>Problem: Server logs show <code>unexpected "aud" claim value</code>. Every auth'd API call returns 401.<br>
|
||
Solution: <code>clientId</code> in <code>conf.yml</code> must exactly match the provider's <strong>Client ID</strong> field. If you let Authentik auto-generate one, copy the exact value (including case) from the provider page.</p>
|
||
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="sso-token-is-encrypted">"SSO token is encrypted"<a href="#sso-token-is-encrypted" class="hash-link" aria-label="Direct link to "SSO token is encrypted"" title="Direct link to "SSO token is encrypted"" translate="no"></a></h4>
|
||
<p>Problem: The browser console shows <code>SSO token is encrypted. Dashy needs signed JWT tokens, not encrypted JWE tokens.</code> and sign-in doesn't stick.<br>
|
||
Solution: The provider has an <strong>Encryption Key</strong> set, so Authentik hands Dashy an encrypted (JWE) token it can't read. Open the Dashy provider, expand <strong>Advanced protocol settings</strong>, clear the <strong>Encryption Key</strong> field so only the <strong>Signing Key</strong> stays set, and save. Dashy needs a signed token, not an encrypted one.</p>
|
||
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="self-signed-authentik-certificate-rejected">Self-signed Authentik certificate rejected<a href="#self-signed-authentik-certificate-rejected" class="hash-link" aria-label="Direct link to Self-signed Authentik certificate rejected" title="Direct link to Self-signed Authentik certificate rejected" translate="no"></a></h4>
|
||
<p>Problem: Fetching the discovery doc or JWKS fails and Dashy logs the generic <code>[auth-oidc] token verification failed: fetch failed</code>. Underneath that <code>fetch failed</code> is a TLS cert rejection (a self-signed or untrusted-CA cert on Authentik's HTTPS endpoint); the OpenSSL reason like <code>self-signed certificate</code> sits in the error cause, not the log line.<br>
|
||
Solution: Use a real certificate on the Authentik HTTPS endpoint (Let's Encrypt or your homelab CA), or mount your CA bundle into the Dashy container and set <code>NODE_EXTRA_CA_CERTS=/path/to/ca.pem</code>. Authentik's built-in <code>authentik Self-signed Certificate</code> is only used to sign tokens; the TLS cert is whatever's terminating HTTPS in front of Authentik.</p>
|
||
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="oidc-signincallback-returned-no-user">"OIDC signinCallback returned no user"<a href="#oidc-signincallback-returned-no-user" class="hash-link" aria-label="Direct link to "OIDC signinCallback returned no user"" title="Direct link to "OIDC signinCallback returned no user"" translate="no"></a></h4>
|
||
<p>Problem: Login submits, Authentik redirects back, then the browser console logs <code>OIDC signinCallback returned no user</code> and sign-in fails.<br>
|
||
Solution: The id_token came back without a usable username claim. Confirm <code>profile</code> and <code>email</code> are in the provider's <strong>Selected Scopes</strong>, that <strong>Include claims in id_token</strong> is on, and that the user has an email or username set in Authentik.</p>
|
||
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="logout-stuck-on-a-consent-screen">Logout stuck on a consent screen<a href="#logout-stuck-on-a-consent-screen" class="hash-link" aria-label="Direct link to Logout stuck on a consent screen" title="Direct link to Logout stuck on a consent screen" translate="no"></a></h4>
|
||
<p>Problem: Clicking Logout sends the user to Authentik's end-session endpoint, which prompts for confirmation and never returns.<br>
|
||
Solution: This is the default behaviour of <code>default-provider-invalidation-flow</code>. To skip the prompt, change the provider's <strong>Invalidation flow</strong> to one without a consent stage, or accept the extra click.</p>
|
||
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="token-expired--clock-skew">Token expired / clock skew<a href="#token-expired--clock-skew" class="hash-link" aria-label="Direct link to Token expired / clock skew" title="Direct link to Token expired / clock skew" translate="no"></a></h4>
|
||
<p>Problem: 401s with <code>"exp" claim timestamp check failed</code>, even just after login.<br>
|
||
Solution: Dashy allows 30 seconds of drift. Sync clocks on both hosts with NTP. Container clocks follow their host, so it's almost always the host that's drifted.</p>
|
||
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="silent-renewal-never-refreshes-the-session">Silent renewal never refreshes the session<a href="#silent-renewal-never-refreshes-the-session" class="hash-link" aria-label="Direct link to Silent renewal never refreshes the session" title="Direct link to Silent renewal never refreshes the session" translate="no"></a></h4>
|
||
<p>Problem: With <code>enableSilentRenew: true</code> the session still drops when the token expires, and the browser console mentions <code>ensure offline_access is granted</code>.<br>
|
||
Solution: Authentik isn't issuing a refresh token because the <code>offline_access</code> scope isn't granted. Open the Dashy provider, expand <strong>Advanced protocol settings</strong>, add the built-in <code>offline_access</code> scope to <strong>Selected Scopes</strong>, and save. Dashy requests <code>offline_access</code> on its own, so all Authentik has to do is allow it.</p>
|
||
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="numeric-client-id-truncated">Numeric Client ID truncated<a href="#numeric-client-id-truncated" class="hash-link" aria-label="Direct link to Numeric Client ID truncated" title="Direct link to Numeric Client ID truncated" translate="no"></a></h4>
|
||
<p>Problem: Audience mismatch when <code>clientId</code> in <code>conf.yml</code> is a long numeric string.<br>
|
||
Solution: Wrap numeric Client IDs in quotes (e.g. <code>clientId: "12345678901234567"</code>). Without quotes YAML parses the value as a JS number and loses precision past around 15 digits.</p>
|
||
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="dashy-server-cant-reach-authentik">Dashy server can't reach Authentik<a href="#dashy-server-cant-reach-authentik" class="hash-link" aria-label="Direct link to Dashy server can't reach Authentik" title="Direct link to Dashy server can't reach Authentik" translate="no"></a></h4>
|
||
<p>Problem: Auth'd API calls return 401 and Dashy logs show fetch errors for <code>.well-known/openid-configuration</code>.<br>
|
||
Solution: <code>endpoint</code> must be reachable from inside the Dashy container, not just from the browser. If both run in Docker, put them on the same network. Test with <code>docker exec <dashy-container> wget -qO- "$ENDPOINT/.well-known/openid-configuration"</code>.</p>
|
||
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="config-change-to-authoidc-not-picked-up">Config change to auth.oidc not picked up<a href="#config-change-to-authoidc-not-picked-up" class="hash-link" aria-label="Direct link to Config change to auth.oidc not picked up" title="Direct link to Config change to auth.oidc not picked up" translate="no"></a></h4>
|
||
<p>Problem: Updated <code>clientId</code>, <code>endpoint</code>, <code>adminGroup</code> or <code>scope</code> in <code>conf.yml</code>, but Dashy still uses the old values.<br>
|
||
Solution: The server reads the auth config only at boot. Restart the Dashy container after any change to fields under <code>auth.oidc</code>.</p>
|
||
<hr>
|
||
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="config-example">Config Example<a href="#config-example" class="hash-link" aria-label="Direct link to Config Example" title="Direct link to Config Example" translate="no"></a></h2>
|
||
<p>Below is an example of a configured local dashy instance (port 4000) for Authentik.</p>
|
||
<details class="details_lb9f alert alert--info details_b_Ee" data-collapsed="true"><summary>Screenshots of Dashy config in Authentik</summary><div><div class="collapsibleContent_i85q">
|
||
<!-- -->
|
||
<p><img decoding="async" loading="lazy" src="https://pixelflare.cc/alicia/screenshots/authentik-settings-1/w1024" alt="" class="img_ev3q">
|
||
<img decoding="async" loading="lazy" src="https://pixelflare.cc/alicia/screenshots/authentik-settings-2/w1024" alt="" class="img_ev3q">
|
||
<img decoding="async" loading="lazy" src="https://pixelflare.cc/alicia/screenshots/authentik-settings-3/w1024" alt="" class="img_ev3q">
|
||
<img decoding="async" loading="lazy" src="https://pixelflare.cc/alicia/screenshots/authentik-settings-4/w1024" alt="" class="img_ev3q">
|
||
<img decoding="async" loading="lazy" src="https://pixelflare.cc/alicia/screenshots/authentik-settings-5/w1024" alt="" class="img_ev3q"></p>
|
||
</div></div></details>
|
||
<hr>
|
||
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="how-it-works">How it Works<a href="#how-it-works" class="hash-link" aria-label="Direct link to How it Works" title="Direct link to How it Works" translate="no"></a></h2>
|
||
<p>Nothing here is specific to Authentik. Dashy speaks standard OIDC, so the same flow works with Keycloak or any other provider; only the config differs.</p>
|
||
<p>Here's what happens when you open Dashy with OIDC enabled:</p>
|
||
<ol>
|
||
<li class="">Your browser asks the Dashy server for the config. You're not signed in yet, so the server only sends back the auth settings. Your sections, items and URLs stay on the server.</li>
|
||
<li class="">Dashy sees OIDC is enabled and redirects you to Authentik to sign in, using the standard authorization code flow with PKCE.</li>
|
||
<li class="">You enter your credentials (plus MFA if you've set it up). Authentik sends you back to Dashy with a one-time code, which the browser swaps for a signed token proving who you are and which groups you're in.</li>
|
||
<li class="">The browser stores that token and attaches it to every request it makes to the Dashy server.</li>
|
||
<li class="">The server checks each token against Authentik's published signing keys, and makes sure it was issued by your Authentik, for Dashy, and hasn't expired. A valid token gets the full config; no token or a bad one gets sent back to the login flow.</li>
|
||
<li class="">Your Authentik groups ride along inside the token. Being in the <code>adminGroup</code> lets you edit and save the config, and groups also power the show/hide visibility rules.</li>
|
||
</ol>
|
||
<p>When the token expires you're bounced back through Authentik for a new one, which is usually instant since you still have a session there. With <code>enableSilentRenew</code> on, Dashy refreshes it in the background and you won't notice at all.</p>
|
||
<p>To sign out, use Dashy's Logout control: it clears the stored token and sends you to Authentik's end-session endpoint (see <a href="#logout-stuck-on-a-consent-screen" class="">Logout stuck on a consent screen</a> if that asks for confirmation).</p>
|
||
<p>If you want the implementation details, the client side lives in <code>src/utils/auth/OidcAuth.js</code> and the server-side token verification in <code>services/auth-oidc.js</code>.</p></div><footer class="theme-doc-footer docusaurus-mt-lg"><div class="row margin-top--sm theme-doc-footer-edit-meta-row"><div class="col noPrint_WFHX"><a href="https://github.com/Lissy93/dashy/edit/master/docs/docs/authentication/authentik.md" target="_blank" rel="noopener noreferrer" class="theme-edit-this-page"><svg fill="currentColor" height="20" width="20" viewBox="0 0 40 40" class="iconEdit_Z9Sw" aria-hidden="true"><g><path d="m34.5 11.7l-3 3.1-6.3-6.3 3.1-3q0.5-0.5 1.2-0.5t1.1 0.5l3.9 3.9q0.5 0.4 0.5 1.1t-0.5 1.2z m-29.5 17.1l18.4-18.5 6.3 6.3-18.4 18.4h-6.3v-6.2z"></path></g></svg>Edit this page</a></div><div class="col lastUpdated_JAkA"><span class="theme-last-updated">Last updated<!-- --> on <b><time datetime="2026-07-04T17:12:29.000Z" itemprop="dateModified">Jul 4, 2026</time></b></span></div></div></footer></article><nav class="docusaurus-mt-lg pagination-nav" aria-label="Docs pages"><a class="pagination-nav__link pagination-nav__link--prev" href="/docs/authentication/authelia-oidc"><div class="pagination-nav__sublabel">Previous</div><div class="pagination-nav__label">Authelia OIDC</div></a><a class="pagination-nav__link pagination-nav__link--next" href="/docs/authentication/built-in"><div class="pagination-nav__sublabel">Next</div><div class="pagination-nav__label">Built-In Auth</div></a></nav></div></div><div class="col col--3"><div class="tableOfContents_bqdL thin-scrollbar theme-doc-toc-desktop"><ul class="table-of-contents table-of-contents__left-border"><li><a href="#contents" class="table-of-contents__link toc-highlight">Contents</a></li><li><a href="#1-deploy-authentik" class="table-of-contents__link toc-highlight">1. Deploy Authentik</a></li><li><a href="#2-configure-authentik" class="table-of-contents__link toc-highlight">2. Configure Authentik</a><ul><li><a href="#create-the-groups-scope" class="table-of-contents__link toc-highlight">Create the groups scope</a></li><li><a href="#create-the-oidc-provider" class="table-of-contents__link toc-highlight">Create the OIDC provider</a></li><li><a href="#create-the-application" class="table-of-contents__link toc-highlight">Create the application</a></li><li><a href="#create-the-admin-group" class="table-of-contents__link toc-highlight">Create the admin group</a></li><li><a href="#create-test-users" class="table-of-contents__link toc-highlight">Create test users</a></li><li><a href="#restrict-who-can-access-dashy-optional" class="table-of-contents__link toc-highlight">Restrict who can access Dashy (optional)</a></li></ul></li><li><a href="#3-enabling-authentik-in-dashy" class="table-of-contents__link toc-highlight">3. Enabling Authentik in Dashy</a></li><li><a href="#4-groups-and-visibility" class="table-of-contents__link toc-highlight">4. Groups and Visibility</a></li><li><a href="#5-silent-token-renewal-optional" class="table-of-contents__link toc-highlight">5. Silent token renewal (optional)</a></li><li><a href="#troubleshooting-common-authentik-issues" class="table-of-contents__link toc-highlight">Troubleshooting common Authentik Issues</a></li><li><a href="#config-example" class="table-of-contents__link toc-highlight">Config Example</a></li><li><a href="#how-it-works" class="table-of-contents__link toc-highlight">How it Works</a></li></ul></div></div></div></div></main></div></div></div><footer class="theme-layout-footer footer footer--dark"><div class="container container-fluid"><div class="row footer__links"><div class="theme-layout-footer-column col footer__col"><div class="footer__title">Intro</div><ul class="footer__items clean-list"><li class="footer__item"><a href="https://github.com/lissy93/dashy" target="_blank" rel="noopener noreferrer" class="footer__link-item">GitHub<svg width="13.5" height="13.5" aria-label="(opens in new tab)" class="iconExternalLink_nPIU"><use href="#theme-svg-external-link"></use></svg></a></li><li class="footer__item"><a href="https://demo.dashy.to" target="_blank" rel="noopener noreferrer" class="footer__link-item">Live Demo<svg width="13.5" height="13.5" aria-label="(opens in new tab)" class="iconExternalLink_nPIU"><use href="#theme-svg-external-link"></use></svg></a></li><li class="footer__item"><a class="footer__link-item" href="/docs/quick-start">Quick Start</a></li><li class="footer__item"><a class="footer__link-item" href="/docs">Documentation</a></li></ul></div><div class="theme-layout-footer-column col footer__col"><div class="footer__title">Setup Guide</div><ul class="footer__items clean-list"><li class="footer__item"><a class="footer__link-item" href="/docs/deployment">Deploying</a></li><li class="footer__item"><a class="footer__link-item" href="/docs/configuring">Configuring</a></li><li class="footer__item"><a class="footer__link-item" href="/docs/management">Management</a></li><li class="footer__item"><a class="footer__link-item" href="/docs/troubleshooting">Troubleshooting</a></li></ul></div><div class="theme-layout-footer-column col footer__col"><div class="footer__title">Feature Docs Pt 1</div><ul class="footer__items clean-list"><li class="footer__item"><a class="footer__link-item" href="/docs/authentication">Authentication</a></li><li class="footer__item"><a class="footer__link-item" href="/docs/alternate-views">Alternate Views</a></li><li class="footer__item"><a class="footer__link-item" href="/docs/backup-restore">Backup & Restore</a></li><li class="footer__item"><a class="footer__link-item" href="/docs/icons">Icons</a></li></ul></div><div class="theme-layout-footer-column col footer__col"><div class="footer__title">Feature Docs Pt 2</div><ul class="footer__items clean-list"><li class="footer__item"><a class="footer__link-item" href="/docs/multi-language-support">Language Switching</a></li><li class="footer__item"><a class="footer__link-item" href="/docs/status-indicators">Status Indicators</a></li><li class="footer__item"><a class="footer__link-item" href="/docs/searching">Searching & Shortcuts</a></li><li class="footer__item"><a class="footer__link-item" href="/docs/theming">Theming</a></li></ul></div><div class="theme-layout-footer-column col footer__col"><div class="footer__title">Community</div><ul class="footer__items clean-list"><li class="footer__item"><a class="footer__link-item" href="/docs/developing">Developing</a></li><li class="footer__item"><a class="footer__link-item" href="/docs/development-guides">Development Guides</a></li><li class="footer__item"><a class="footer__link-item" href="/docs/contributing">Contributing</a></li><li class="footer__item"><a class="footer__link-item" href="/docs/showcase">Showcase</a></li><li class="footer__item"><a class="footer__link-item" href="/docs/credits">Credits</a></li></ul></div><div class="theme-layout-footer-column col footer__col"><div class="footer__title">Misc</div><ul class="footer__items clean-list"><li class="footer__item"><a class="footer__link-item" href="/docs/privacy">Privacy & Security</a></li><li class="footer__item"><a class="footer__link-item" href="/docs/license">License</a></li><li class="footer__item"><a href="https://github.com/Lissy93/dashy/blob/master/.github/LEGAL.md" target="_blank" rel="noopener noreferrer" class="footer__link-item">Legal<svg width="13.5" height="13.5" aria-label="(opens in new tab)" class="iconExternalLink_nPIU"><use href="#theme-svg-external-link"></use></svg></a></li><li class="footer__item"><a href="https://github.com/Lissy93/dashy/blob/master/.github/CODE_OF_CONDUCT.md" target="_blank" rel="noopener noreferrer" class="footer__link-item">Code of Conduct<svg width="13.5" height="13.5" aria-label="(opens in new tab)" class="iconExternalLink_nPIU"><use href="#theme-svg-external-link"></use></svg></a></li><li class="footer__item"><a href="https://github.com/Lissy93/dashy/blob/master/.github/CHANGELOG.md" target="_blank" rel="noopener noreferrer" class="footer__link-item">Changelog<svg width="13.5" height="13.5" aria-label="(opens in new tab)" class="iconExternalLink_nPIU"><use href="#theme-svg-external-link"></use></svg></a></li></ul></div></div><div class="footer__bottom text--center"><div class="footer__copyright"><a href="https://dashy.to">Dashy</a> - The Self-Hosted Dashboard for your Homelab<br>License under <a href="https://github.com/Lissy93/dashy/blob/master/LICENSE">MIT</a>. Copyright © 2026 <a href="https://aliciasykes.com">Alicia Sykes</a></div></div></div></footer></div>
|
||
</body>
|
||
</html> |