Configure sign-in
Sign-in is optional. You can enable Google, GitHub, or a custom OpenID Connect provider.
Public origin and callbacks
Set your public HTTPS origin in .env:
OAUTH_ORIGIN=https://regex101.example.com
Register the callback URL for each provider you enable:
| Provider | Callback URL |
|---|---|
<OAUTH_ORIGIN>/connect/google/callback | |
| GitHub | <OAUTH_ORIGIN>/connect/github/callback |
| Custom OpenID Connect | <OAUTH_ORIGIN>/connect/custom/callback |
Replace <OAUTH_ORIGIN> with the origin above.
Google or GitHub
Register an application with your provider and add its credentials to .env:
OAUTH_GOOGLE_CLIENT_ID=
OAUTH_GOOGLE_CLIENT_SECRET=
OAUTH_GITHUB_CLIENT_ID=
OAUTH_GITHUB_CLIENT_SECRET=
Each provider requires OAUTH_ORIGIN, its client ID, and its client secret. Leave unused providers empty.
Custom OpenID Connect
Register an application with your provider and set:
OAUTH_CUSTOM_LABEL="Company sign-in"
OAUTH_CUSTOM_ISSUER=https://login.microsoftonline.com/<tenant-id>/v2.0
OAUTH_CUSTOM_CLIENT_ID=
OAUTH_CUSTOM_CLIENT_SECRET=
OAUTH_CUSTOM_AUTH_METHOD=header
The issuer, client ID, client secret, and OAUTH_ORIGIN are required. The label is optional.
Use the issuer from your provider's discovery configuration, including its path and trailing slash.
For Microsoft Entra ID, replace <tenant-id> with your tenant ID. Use a tenant-specific issuer.
If your provider requires client_secret_post, set OAUTH_CUSTOM_AUTH_METHOD=body. The default header uses client_secret_basic.
Apply and verify
- Save
.envand recreate the services. - Open your HTTPS URL in a new browser session.
- Sign in with the configured provider.
- Save a workspace, sign out, then sign in and reopen it.
An incomplete provider configuration leaves that provider disabled. Different providers or issuers can create separate accounts. Verify access to existing workspaces after a provider change.
If sign-in fails, see Troubleshooting.