Skip to main content

Configure sign-in

Sign-in is optional. You can enable Google, GitHub, or a custom OpenID Connect provider.

Public origin and callbacks​

Set your public HTTPS origin in .env:

OAUTH_ORIGIN=https://regex101.example.com

Register the callback URL for each provider you enable:

ProviderCallback URL
Google<OAUTH_ORIGIN>/connect/google/callback
GitHub<OAUTH_ORIGIN>/connect/github/callback
Custom OpenID Connect<OAUTH_ORIGIN>/connect/custom/callback

Replace <OAUTH_ORIGIN> with the origin above.

Google or GitHub​

Register an application with your provider and add its credentials to .env:

OAUTH_GOOGLE_CLIENT_ID=
OAUTH_GOOGLE_CLIENT_SECRET=

OAUTH_GITHUB_CLIENT_ID=
OAUTH_GITHUB_CLIENT_SECRET=

Each provider requires OAUTH_ORIGIN, its client ID, and its client secret. Leave unused providers empty.

Custom OpenID Connect​

Register an application with your provider and set:

OAUTH_CUSTOM_LABEL="Company sign-in"
OAUTH_CUSTOM_ISSUER=https://login.microsoftonline.com/<tenant-id>/v2.0
OAUTH_CUSTOM_CLIENT_ID=
OAUTH_CUSTOM_CLIENT_SECRET=
OAUTH_CUSTOM_AUTH_METHOD=header

The issuer, client ID, client secret, and OAUTH_ORIGIN are required. The label is optional. Use the issuer from your provider's discovery configuration, including its path and trailing slash.

For Microsoft Entra ID, replace <tenant-id> with your tenant ID. Use a tenant-specific issuer. If your provider requires client_secret_post, set OAUTH_CUSTOM_AUTH_METHOD=body. The default header uses client_secret_basic.

Apply and verify​

  1. Save .env and recreate the services.
  2. Open your HTTPS URL in a new browser session.
  3. Sign in with the configured provider.
  4. Save a workspace, sign out, then sign in and reopen it.

An incomplete provider configuration leaves that provider disabled. Different providers or issuers can create separate accounts. Verify access to existing workspaces after a provider change.

If sign-in fails, see Troubleshooting.