OIDC IdP Setup
OIDC / IdP setup (Okta, Auth0, Entra, Keycloak)
Section titled “OIDC / IdP setup (Okta, Auth0, Entra, Keycloak)”Kazma uses standard OpenID Connect (authorization code + PKCE).
Fail-closed: the callback verifies the id_token (JWKS for RS/ES/PS,
client secret for HS*). A JWKS miss, alg: none, wrong audience, or bad
signature is a 400 — Kazma never mints a session from an unverified JWT.
UserInfo is used only when the IdP omitted id_token.
Kazma env
Section titled “Kazma env”KAZMA_PUBLIC_URL=https://kazma.example.comKAZMA_OIDC_ISSUER=https://YOUR_TENANT.okta.com # or Auth0/Entra issuerKAZMA_OIDC_CLIENT_ID=...KAZMA_OIDC_CLIENT_SECRET=...# optional overridesKAZMA_OIDC_REDIRECT_URI=https://kazma.example.com/api/auth/oidc/callbackKAZMA_OIDC_SCOPES=openid profile emailKAZMA_OIDC_ROLE_CLAIM=role # or groups / custom claimKAZMA_OIDC_DEFAULT_ROLE=operator # viewer | operator | adminKAZMA_OIDC_TENANT_CLAIM=org # optional: claim naming the user's Kazma tenantKAZMA_OIDC_TENANT_CLAIM is off by default, and then every OIDC user shares the
default tenant. When set, the named claim (a slug of letters, digits, ., _,
-; a one-element list is accepted) is stored in the user’s session and every
request runs under that tenant: its secrets, memory, sessions and threads. A
malformed value is ignored and logged. Local users get the same binding from
tenant_id on POST /api/saas/users.
IdP app registration
Section titled “IdP app registration”| Setting | Value |
|---|---|
| Application type | Web / Confidential |
| Grant | Authorization Code |
| Sign-in redirect URI | {KAZMA_PUBLIC_URL}/api/auth/oidc/callback |
| Sign-out (optional) | {KAZMA_PUBLIC_URL}/login |
| PKCE | Enabled (S256) |
- Applications → Create App Integration → OIDC → Web Application
- Sign-in redirect:
https://your.host/api/auth/oidc/callback - Assign users/groups
- Optional: add claim
role=admin/operator/viewerin Authorization Server
- Applications → Regular Web Application
- Allowed Callback URLs:
https://your.host/api/auth/oidc/callback - Issuer:
https://YOUR_DOMAIN.auth0.com/ - Optional Actions: add
roleto ID token
Azure Entra ID
Section titled “Azure Entra ID”- App registration → Web redirect URI
- Issuer:
https://login.microsoftonline.com/{tenant}/v2.0 - Expose roles or use App roles mapped into token
Kazma login UX
Section titled “Kazma login UX”/loginshows Continue with SSO when OIDC is configured (/api/auth/status→oidc: true)- After callback, Kazma mints an opaque
kazma-sessionwith username + role - Branding (logo, colors) is configured on the IdP login page — Kazma shows a neutral SSO button
Role mapping
Section titled “Role mapping”| IdP claim value | Kazma role |
|---|---|
| admin, owner, administrator | admin |
| operator, user, member, write | operator |
| viewer, read, guest | viewer |
| (missing) | KAZMA_OIDC_DEFAULT_ROLE |
- Open
/login→ Continue with SSO - Complete IdP login
- Land on
/with cookie set GET /api/auth/mereturnsusername+role