https://auth.example.com 请换成你的 Casdoor 地址(Casdoor 云上类似 https://acme.casdoor.com),其他 example.com 地址也换成你自己的。用 Casdoor 配置 Vaultwarden
- 1
在 Casdoor 中注册 Vaultwarden
在 Casdoor 控制台打开 应用,为 Vaultwarden 添加一个应用,在它的 OIDC/OAuth 标签页复制 客户端ID 和 客户端密钥。把下面的地址加到 重定向URLs:
https://vault.example.com/identity/connect/oidc-signin
- 2
Configure Vaultwarden
Set these environment variables on Vaultwarden 1.35.0 or later, for example in Docker Compose, and restart it. Vaultwarden builds the redirect URI from
DOMAIN.services: vaultwarden: image: vaultwarden/server:latest environment: DOMAIN: "https://vault.example.com" SSO_ENABLED: "true" SSO_AUTHORITY: "https://auth.example.com" SSO_CLIENT_ID: "<client ID>" SSO_CLIENT_SECRET: "<client secret>" SSO_SCOPES: "email profile" SSO_PKCE: "true" - 3
Sign in
Users can now choose single sign-on on the Vaultwarden login page, sign in at Casdoor, and then unlock their vault. Add
SSO_ONLY: "true"once everyone has switched, to turn off email-and-password login.
注意事项
SSO_AUTHORITYmust equal theissuerinhttps://auth.example.com/.well-known/openid-configurationexactly, without a trailing slash.- Vaultwarden refuses to sign up a user whose ID token says
email_verified: false. Casdoor marks an email as verified once the user confirms it with a code or a magic link, for example at sign-up. - The Bitwarden mobile apps support Vaultwarden SSO from version 2026.1.0.
Vaultwarden 的设置取自它的官方文档(核对于 2026年10月:Vaultwarden SSO wiki、Vaultwarden releases);另见Casdoor 文档。Vaultwarden 是其所有者的商标。
常见问题
Do users still need a master password?
Yes. Single sign-on replaces the email-and-password login, but the vault is still encrypted with the user's master password, which they enter after signing in with Casdoor.
I don't see the single sign-on option. Why?
Check that the server runs Vaultwarden 1.35.0 or later and that SSO_ENABLED is true, then restart it. If sign-in fails afterwards, compare SSO_AUTHORITY with Casdoor's issuer and check the redirect URI in the Casdoor application.
更多应用集成
查看全部Argo CD
应用集成Connect Argo CD to Casdoor over OpenID Connect: oidc.config in argocd-cm, the client secret, PKCE, CLI login and RBAC from Casdoor groups.
Gitea
应用集成Add Casdoor to Gitea as an OpenID Connect authentication source: the add-oauth command, callback URL, and admins from a Casdoor group.
GitLab
应用集成Configure self-managed GitLab to sign users in with Casdoor over OpenID Connect: gitlab.rb provider settings, account creation and group-based admins.
