Casdoor集成市场

Vaultwarden | 应用集成

Vaultwarden 单点登录

Since version 1.35.0, Vaultwarden can sign users in through an OpenID Connect provider. With Casdoor, your team signs in to the password manager with the same account and MFA they use everywhere else.

Casdoor 官方核验OIDCPKCE
你需要一个正在运行的 Casdoor,自己部署或用 Casdoor 云都可以。示例中的 https://auth.example.com 请换成你的 Casdoor 地址(Casdoor 云上类似 https://acme.casdoor.com),其他 example.com 地址也换成你自己的。

用 Casdoor 配置 Vaultwarden

  1. 1

    在 Casdoor 中注册 Vaultwarden

    在 Casdoor 控制台打开 应用,为 Vaultwarden 添加一个应用,在它的 OIDC/OAuth 标签页复制 客户端ID 和 客户端密钥。把下面的地址加到 重定向URLs:

    • https://vault.example.com/identity/connect/oidc-signin
  2. 2

    Configure Vaultwarden

    Set these environment variables on Vaultwarden 1.35.0 or later, for example in Docker Compose, and restart it. Vaultwarden builds the redirect URI from DOMAIN.

    services:
      vaultwarden:
        image: vaultwarden/server:latest
        environment:
          DOMAIN: "https://vault.example.com"
          SSO_ENABLED: "true"
          SSO_AUTHORITY: "https://auth.example.com"
          SSO_CLIENT_ID: "<client ID>"
          SSO_CLIENT_SECRET: "<client secret>"
          SSO_SCOPES: "email profile"
          SSO_PKCE: "true"
  3. 3

    Sign in

    Users can now choose single sign-on on the Vaultwarden login page, sign in at Casdoor, and then unlock their vault. Add SSO_ONLY: "true" once everyone has switched, to turn off email-and-password login.

注意事项

  • SSO_AUTHORITY must equal the issuer in https://auth.example.com/.well-known/openid-configuration exactly, without a trailing slash.
  • Vaultwarden refuses to sign up a user whose ID token says email_verified: false. Casdoor marks an email as verified once the user confirms it with a code or a magic link, for example at sign-up.
  • The Bitwarden mobile apps support Vaultwarden SSO from version 2026.1.0.

Vaultwarden 的设置取自它的官方文档(核对于 2026年10月:Vaultwarden SSO wiki、Vaultwarden releases);另见Casdoor 文档。Vaultwarden 是其所有者的商标。

常见问题

Do users still need a master password?

Yes. Single sign-on replaces the email-and-password login, but the vault is still encrypted with the user's master password, which they enter after signing in with Casdoor.

I don't see the single sign-on option. Why?

Check that the server runs Vaultwarden 1.35.0 or later and that SSO_ENABLED is true, then restart it. If sign-in fails afterwards, compare SSO_AUTHORITY with Casdoor's issuer and check the redirect URI in the Casdoor application.