Sign-in and single sign-on
Passwords with two-factor authentication, plus sign-in with Google, GitHub or any OpenID Connect provider such as Entra ID, Okta or Keycloak.
Self-hosted
Passwords and two-factor authentication
Passwords are hashed with scrypt; accounts lock after repeated failures, and sign-in timing does not reveal whether an email exists. Users can turn on authenticator-app codes (TOTP) with ten one-time recovery codes. For a lost device, an administrator can turn two-factor off with a reason; the person is signed out everywhere, emailed, and the action is audited.
Sign-in providers
Each provider is off until its client id and secret are set (environment or Server settings). Register this redirect URI with the provider:
<PUBLIC_URL>/api/v1/auth/oauth/<google | github | oidc>/callback| Provider | Variables |
|---|---|
GOOGLE_CLIENT_ID, GOOGLE_CLIENT_SECRET | |
| GitHub | GITHUB_CLIENT_ID, GITHUB_CLIENT_SECRET (GITHUB_URL, GITHUB_API_URL for Enterprise Server) |
| OpenID Connect | OIDC_ISSUER, OIDC_CLIENT_ID, OIDC_CLIENT_SECRET; OIDC_DISPLAY_NAME for the button; OIDC_SCOPES defaults to openid email profile |
How identities map to accounts
- An identity signs in to the account it is connected to.
- Otherwise, if the provider confirms the email is verified and an account with that email exists, the identity is connected to it.
- Otherwise a new account is created, subject to
ALLOW_REGISTRATION. Invitation links also offer the providers.
Two-factor authentication still applies. Users connect and disconnect providers under Settings → Your account. An account created through a provider has no password until the user sets one with "Forgot password".
CLI and mobile
agentctl login --server <url> and the mobile app's Sign in with your browser use a device code approved
in the web app, so they work with every sign-in method.
Verification status
The OIDC provider type is tested against a local stand-in provider. Google, GitHub and specific OIDC vendors have not yet been tried with real accounts. Two-factor uses authenticator apps only: no SMS or security keys.